legal
Cookies and similar technologies
- effective
- 30 July 2026
pending legal review. this text is complete and ready for a Pakistani lawyer to review and approve. requirements vary by province, city and cantonment — see /docs/legal-checklist-pakistan.md.
Three things, all of them ours, none of them optional in any meaningful sense: a cookie that keeps you signed in, your cart, and a note that you closed the banner. No advertising cookies. No pixels. Nothing that follows you to another website.
The short version
This site sets one cookie and uses two browser-storage keys. All three are first-party — set by pastas.pk, readable only by pastas.pk — and all three exist so the site works: you stay signed in, your cart survives a page refresh, and a notice you dismissed stays dismissed. We measure how the site is used with our own analytics, recorded on our servers rather than through anyone else’s tag. There is currently no third-party, advertising or cross-site tracking technology on pastas.pk.
What we mean by “cookies and similar technologies”
A cookie is a small piece of text a website asks your browser to keep and send back on the next request. Browser storage (localStorage) is similar, with one important difference: it is not sent back automatically. It sits in your browser until code on the page reads it. We use both, and we list them together here because the distinction matters to engineers more than it matters to you — either way, something is being kept on your device, and you deserve to know what.
We do not use tracking pixels, web beacons, device fingerprinting, or any technique designed to recognise you across other websites.
Everything this site stores on your device
This is the complete list. If you find something on pastas.pk that is not on it, that is a bug, and we would like to hear about it at privacy@pastas.pk.
| Name | Type | Purpose | Lifetime | Category |
|---|---|---|---|---|
| pastas_session | First-party cookie | Keeps you signed in to your account. It holds a random token and nothing else — no name, no email, no order history. Your browser cannot read it (HttpOnly), it is not sent to other sites (SameSite=Lax), and in production it only travels over HTTPS. | 30 days from sign-in. Deleted when you sign out or delete your account. | Strictly necessary |
| pastas-cart-v1 | Browser storage (localStorage) | Your cart: the bowls in it, quantities and any modifiers, plus the kitchen you picked and whether you chose pickup or delivery. It stays in your browser — it is never sent to us as a cart, only as an order when you check out. | Until you clear it. Items empty automatically once an order is placed; your chosen kitchen is remembered for next time. | Strictly necessary |
| pastas-cookie-notice-v1 | Browser storage (localStorage) | Remembers that you dismissed the notice at the bottom of the screen, so it does not follow you from page to page. | Until you clear your browser storage for this site. | Strictly necessary |
The site we build sets nothing else. Our host, Vercel, may add an operational cookie of its own to route requests correctly — it carries no advertising or profiling function. We check this list against Vercel’s current documentation before each release, so if one appears it is named here rather than left for you to find.
Why there is nothing here to switch off
Cookie rules generally distinguish between storage that is strictly necessary to provide the service you asked for, and storage used for analytics, personalisation or advertising — the second kind is what consent banners are for. Everything in the table above is the first kind:
- Turn off pastas_session and you cannot stay signed in — no order history, no saved addresses, no rewards balance.
- Turn off pastas-cart-v1 and your cart empties every time you open a new page.
- Turn off pastas-cookie-notice-v1 and the notice you just dismissed comes back.
So we do not show you an accept-or-reject dialog. A choice that cannot be honoured is not a choice, and a banner that pretends otherwise is theatre. You get a plain statement of what is stored, and the browser controls below, which really do work.
Analytics: first-party, server-side, no pixel
We record what happens on the site — a menu viewed, a bowl added to a cart, an order placed — as rows in our own database, written by our own server. There is no analytics script in your browser, no tag manager, and no request to a third party. Nothing is stored on your device for analytics, which is why analytics does not appear in the table above.
Each event carries an event name, a timestamp, and a small set of properties that are checked against a strict schema before anything is written. The schema only accepts things like a menu-item slug, a quantity or a rupee amount; a stray name, phone number, email or address does not get quietly dropped — it fails the whole call. Today those rows do not carry any visitor identifier at all, so one person’s events cannot be strung together into a session or a profile.
How long we keep those rows is [counsel to confirm: analytics retention period, once counsel confirms tax and record-keeping needs]. We will state a fixed period here rather than keep them indefinitely.
No advertising, no cross-site tracking
To be unambiguous: pastas.pk currently runs no Google Analytics, no Google Ads, no Meta or Facebook pixel, no TikTok pixel, no retargeting tag and no social-embed tracker. We do not sell or share your data with advertising networks, because we do not send it to any.
Our code has room for those adapters, and one day the business may want one. If that day comes, this page and the notice at the bottom of the screen change before any such script is allowed to load, and the notice becomes a real consent mechanism where you can accept or decline each category. We will not switch on a tracker and update the policy afterwards.
The same applies to online payments. Today we accept cash on delivery, plus a test card that exists only in development and moves no money, so no payment provider sets anything in your browser. A licensed payment gateway would likely need its own cookies to work; that would be listed here first.
Managing and clearing what is stored
Your browser is in charge, and it can remove all of this at any time. Look for Settings → Privacy → Cookies and site data (Chrome and Edge), Settings → Privacy & Security → Cookies and Site Data (Firefox), or Settings → Privacy → Manage Website Data (Safari). Most browsers also let you clear one site at a time, block cookies entirely, or open a private window that forgets everything when you close it.
Clearing site data for pastas.pk empties your cart and signs you out. Nothing else is lost — orders, saved addresses, favourites and rewards live in your account on our servers, and come back when you sign in.
Blocking this site’s storage entirely is your right, and browsing the menu still works. Two things stop working while it is blocked: you cannot sign in, because the sign-in cookie is how we recognise that a request is yours, and your cart empties every time you move to another page, which makes ordering impractical. Checking out itself does not require an account — you can order as a guest — but it does need a cart that survives the walk to the checkout page.
Some browsers send a “Do Not Track” or Global Privacy Control signal. We have nothing to switch off in response to one, since we do not track you across sites; if we ever add technology that a signal like that should govern, we will say here exactly how we honour it.
How this fits with the privacy policy
This page covers what is stored on your device. What we collect when you order — your name, phone number, delivery address, order contents, and what we do with them — is in the privacy policy, along with how to request an export or deletion of your data. The two documents are meant to be read together.
Changes to this page
If what we store changes, this page changes on the same day and the effective date at the top moves with it. Adding anything that is not strictly necessary is a material change: it comes with a fresh notice on the site and, where consent is required, a request for it before the technology loads.
Questions about anything on this page go to privacy@pastas.pk or through the contact form. A person answers.
who you are dealing with
pastas is a sole proprietorship operating in Pakistan, operating a fresh pasta kitchen in Bahria Town Phase 4, Rawalpindi, and the ordering service at pastas.pk. the contracting party is pastas [legal name to be confirmed].
- address for notices:
- [counsel to confirm: registered address]
- legal and privacy contact:
- contact@pastas.pk — one inbox, read by a person. put “legal” or “privacy” in the subject and it reaches the right hands.