Legal
Cookie policy
Everything this site stores in your browser, what each item does, how long it lasts, and who it belongs to. Generated from the same list the site itself reads, so it cannot quietly fall out of date.
Updated 4 Oct 2026about 5 minutes
On this page
1.What is stored, in full
Everything, in one table, and nothing kept back for a paragraph further down. A cookie goes to our server with every request; local storage never leaves your browser at all, and session storage is the same but is gone when the tab closes.
The rows set by Outrouted are exempt from asking under Article 5(3) of the ePrivacy Directive, either because they are strictly necessary to deliver what you asked for or because they record a preference you set yourself. So is the one row set by Cloudflare Turnstile, which is the check on four of this site's forms and is described in its own section below. Exempt from asking is not exempt from telling, which is what this page is. Every other row in the table waits for a yes.
| Name | Set by | Kind | What it does | How long |
|---|---|---|---|---|
| outrouted_session | Outrouted | cookie | Keeps you signed in. Signed, http-only, and readable only by the server. | 30 days, or until the browser closes if you did not tick “keep me signed in” |
| outrouted_display | Outrouted | cookie | The units, currency, temperature scale and date format you chose. A cookie rather than storage because prices and distances are formatted on the server. | Until the browser closes |
| outrouted_theme | Outrouted | local storage | Whether you chose the day theme, the night theme or your device's setting. Read before the page draws so it does not flash the wrong colours. | Until you clear it or choose again |
| outrouted_pending_checkout | Outrouted | local storage | The reference of a payment page you were sent to, so a payment that never brought you back here is still found and put on your account. It goes to our own server and nowhere else. | Until the payment is confirmed, or for a day |
| outrouted_oauth | Outrouted | cookie | Only set if you press Continue with Google. It is the signed note that the sign-in coming back from Google is the one you started here: a one-time code, where to go afterwards and, if you arrived by a campaign link, that link as a few fixed words. Readable only by the server, and deleted when the sign-in finishes. | 10 minutes |
| or_consent | Outrouted | local storage | Your answer to the cookie question, with the date and the version of the question. Nothing else, and it never leaves your browser. | Until you clear it, or until the question materially changes |
| outrouted:human-pass | Outrouted | session storage | The pass our server hands out after the human check on a search, so the next question or search in this tab does not ask again. A random value and the time it ends. It goes back to our own server and nowhere else. | Until the tab closes, or until it runs out, which is never more than two hours |
| outrouted:plan-* | Outrouted | session storage | Five small records of a search in progress: what you asked for, why nothing fitted, the search being waited on, the answers you gave to its questions, and the human check handed from one screen to the next. They let a reload, or a sign-up in between, carry on rather than start over, and they are cleared once a trip is saved. They never leave your browser except as the request you sent. | Until the tab closes, or until a trip is saved |
| outrouted_paid_intent:* | Outrouted | session storage | What you pressed on a trip when an offer opened, so that coming back from the payment page can remind you and offer to do it. The star is the trip's own id. It is never done for you without another press. | Until the tab closes |
| outrouted.context | Outrouted | session storage | The country, currency, units and exchange rates our server worked out for this tab, so the next page is written in your own money from its first paint. | Until the tab closes |
| outrouted_tab:* | Outrouted | session storage | The tab of a trip you last had open, so going back to it opens the same one. The star is the trip's own id. | Until the tab closes |
| outrouted_day:* | Outrouted | session storage | The day of a trip you last picked, for the same reason. The star is the trip's own id. | Until the tab closes |
| or_funnel | Outrouted | local storage | When you last opened each of your trips on this device (up to thirty), and which plan a purchase was last counted for. It lets the measurement tell a return to a trip from a first look, and count one purchase once. Only written if you accepted measurement, never sent anywhere, and removed when you withdraw. | Until you withdraw measurement or clear it |
| or_attr | Outrouted | local storage | Which link brought you here, kept as a few fixed words that everyone who followed the same link shares, such as a channel and a campaign name. Never a click id, an address or the page you came from. The first one is kept for 90 days and the latest for 7, so a later visit or a sign-up can be counted as coming from the same place. Only written if you accepted measurement, and removed when you withdraw. The copy in your browser is not sent anywhere by itself. | 90 days for the first, 7 days for the latest, or until you withdraw measurement or clear it |
| cf_chl_rc_* | Cloudflare Turnstile | cookie | Cloudflare documents these as internal, for spotting problems with the challenge itself on real browsers. Nothing here reads them and nothing here is told what is in them. The star is a one or two letter suffix; they are printed the way Cloudflare writes them rather than guessed at, and only the challenge's own origin ever sees them. | The visit. Cloudflare publishes no lifetime for them, and this list would rather say that than invent one |
| _ga | Google Analytics | cookie | Tells this browser apart from another one, as a random number. It is not linked to your account and it is not a name. | 13 months, shortened from Google's own default of two years |
| _ga_* | Google Analytics | cookie | Holds the state of the current visit: when it started, and how many pages in you are. The star is the measurement property's own id, which is configuration rather than something committed here, so the name is printed the way it is written rather than guessed at. | 13 months |
| _clck | Microsoft Clarity | cookie | A random id for this browser, so two visits can be told apart from two people. | 1 year |
| _clsk | Microsoft Clarity | cookie | Joins the pages of one visit into one recording rather than five. | 1 day |
2.The one third party that does not wait to be asked
Five forms on this site are checked to see whether a browser with a person in front of it is what submitted them: signing up, signing in, asking for a password reset link, planning a route (the questions before a search included), and asking to be emailed when your routes are ready. The check is Cloudflare Turnstile, and it runs before you have answered anything, because a script does not answer cookie notices and a script is the entire thing it is there to stop.
Three of those spend something real. A password reset and a ready message put mail in an inbox at an address whoever submitted the form typed, and planning a route calls a model we pay for. Counting requests per address does not protect either one, because the attack on both is one script and a thousand addresses.
It is exempt from asking under the same article as the session cookie, for the same reason: without it, the thing you asked for does not work safely. It is not exempt from being described, which is what this section is. If a content blocker stops it loading, those forms will say so instead of failing quietly.
- Cloudflare Turnstile: Checks that a browser with a person in front of it is what submitted the sign-up, sign-in, password reset, route planning and ready-message forms. It replaces a puzzle: most visitors are never shown anything at all, and the ones who are get a checkbox rather than a grid of traffic lights. Without it, those forms are open to any script, and the three that cost real money are the ones worth attacking. It receives the address of the page the form is on, your IP address, and signals about the browser itself. Cloudflare's own terms for Turnstile forbid using any of it to build an advertising profile, and nothing you type into the form is sent.
3.The optional ones, and who they belong to
Say yes and both of these load. Say no and neither does, and anything either of them had already stored is deleted from your browser on the spot. Refusing costs you nothing: every route, map, price and feature works identically either way.
There is one exception and it is worth being exact about. Before you have answered at all, Google's tag loads in what Google calls the denied state: it writes no cookie, sets no identifier, and sends signals saying a page was viewed or that a step such as a search or a booking link press happened, each as a fixed label with nothing you typed in it. That is there for a dull reason. Google verifies an installation by loading the page in a browser that never clicks a cookie notice, and with nothing loading before an answer it reports the tag as missing however much data is arriving. Answer either way and the exception ends. The session recorder never runs before a yes.
If you say yes, this site also remembers in your own browser when you last opened each of your trips, so that a return to one can be counted, and which campaign link brought you, as a few fixed words, so that a later visit or a sign-up can be counted as coming from the same place. Both are listed in the table above, the stored copies never leave your browser, and both are deleted when you withdraw. Before you have answered, the campaign words are kept in the page's memory only and go out with the same fixed-label signals; if you sign up or pay they are written on your account and on the payment, as the privacy policy sets out. If you say no, they are neither kept nor sent.
You can change the answer whenever you like from Cookie settings in the footer, and withdrawing is the same single click as giving it.
- Google Analytics: Counts which pages get opened and which ones a visit ends on. It is how a page nobody finishes gets found. Its tag is the one thing here that loads before you answer, in a state where it stores nothing and sets no identifier, because Google verifies an installation with a browser that never clicks a notice. It receives the page you are on (with the secret part of a share, invitation, reset, verification or mailed routes address replaced by a fixed word), which step of planning you reached (as a fixed label, never anything you typed), the page you arrived from, which campaign link brought you (as a fixed word, never a click id), a rough location worked out from your IP address, and your browser, language and screen size. Not your IP address itself, and nothing you type.
- Microsoft Clarity: Records what a page did under the cursor: where scrolling stops, what gets clicked twice because it did not look clickable, which control gets rage-clicked. A count says a page is abandoned; this says where. It receives the page you are on and what you did on it, as movements, clicks and scroll positions. It is not run on a share, invitation, reset, verification or mailed routes page. Text you type is masked in the browser before anything is sent. Its advertising storage is refused, so the cross-site cookies Microsoft would otherwise set are not set.
4.Third parties your browser talks to anyway
Map tiles, terrain and destination photography are fetched by your browser from the services that host them, so those services see your IP address and which tile or image you asked for, which is the same thing any image on any website discloses. They set no cookies here and receive nothing about who you are.
Stripe sets its own cookies on the payment step, for fraud checks on the card being used. That is part of taking a payment rather than something optional, it happens only when you are actually paying, and Stripe's own policy governs it.
The booking providers on the home page are deliberately not in that group, and it took a decision to keep them out. Every one of those affiliate programmes hands you a logo to load from its own network, and an image is enough to see an address and set a cookie, so those logos are files on this site instead. Nothing is requested from Booking.com, LOT Polish Airlines, Ferryhopper or EconomyBookings while you read the page, and none of them can put anything in your browser here. Press one of the links and that changes, because you are then on their site.
5.Turning them off
Your browser can block or clear all of them, and nothing here tries to work around that. Blocking the session cookie signs you out on every page load; clearing the preferences cookie resets you to what your country reads in. Neither breaks anything permanently.
We also honour Global Privacy Control. If your browser sends it, anything optional is treated as refused before you are asked. You would have to opt in deliberately to change that.
6.Changes
A new cookie or a new third party appears in the table above on the commit that adds it, because the table is generated from the list the code reads. If the change needs consent, the question is asked again, not answered by a click you made about something else.
Something unclear, or worded so it could be read two ways? Write to hello@outrouted.com and we will fix the wording rather than explain it privately once.