Last updated: July 24, 2026

Cookie Policy

This page describes the cookies and similar technologies used on this site, under Art. 122 of Italian Legislative Decree 196/2003 and the Garante's cookie guidelines (10 June 2021).

This is a courtesy translation. The Italian version of this notice prevails in case of any discrepancy.

1. In short

This site uses technical cookies, necessary for it to work, which do not require your consent under Art. 122 of Legislative Decree 196/2003 (transposing Art. 5(3) of the ePrivacy Directive 2002/58/EC). We also use one consent-based tool, Snitcher, which tells us which companies visit the site: it stays switched off until you turn it on through the banner, and you can withdraw at any time from section 6 of this page. We use no advertising cookies.

2. What cookies are

Cookies are small text files that sites store on a user's device to make the site work or to remember preferences. Some are strictly necessary for technical operation (technical cookies) and require no consent; others collect statistics, recognise who is visiting, or serve advertising, and require prior consent. The same applies to equivalent technologies that store or read information on your device, such as localStorage and sessionStorage, which this page describes alongside cookies.

3. Technical cookies we use

Cookie / storageSourcePurposeDuration
__Secure-next-auth.callback-urlCal.com booking widget (third party)Managing the booking widget sessionSession
__Secure-next-auth.csrf-tokenCal.com booking widget (third party)CSRF protection for the booking widget sessionSession
__cf_bmCloudflare, via the Cal.com widgetFiltering automated traffic to protect the booking widget30 minutes
cf_clearanceCloudflare, via the Snitcher partner badgeConfirming the badge request comes from a real browser and not from automated traffic. Set on the snitcher.com domain and partitioned to your visit to this site1 year
timeOption.is24hClock (localStorage)Cal.com booking widgetRemembering your 12/24h clock preferencePersistent (local)
novrith_newsletter_popup (localStorage)Novrith site (newsletter pop-up)Remembering the pop-up was already shown, subscribed or dismissed, so it is not shown again (frequency capping)Persistent (local)
novrith:blog-toc-open (localStorage)Novrith site (blog articles)Remembering whether the article's table of contents is open or closedPersistent (local)
cargo_anon_idCargo (GetCargo Inc.), first-party on novrith.comTying form submissions made from the same browser to a single visitor record. Set only at the moment you submit a form, never on page load12 months
These cookies and local-storage entries are set only when you interact with the relevant tools (the booking widget, the forms, the newsletter pop-up or the blog table of contents). They do not track your browsing and are not used for advertising.
cargo_anon_id deserves a note of its own because of how long it lasts (12 months). It is set by our provider Cargo, only at the moment you submit a form, and serves solely to tie submissions made from the same browser to a single record. It stays limited to this site, is never used to follow you elsewhere, and is neither read nor written if your browser sends a Global Privacy Control or Do Not Track signal. We have asked Cargo for the ability to switch it off entirely.

4. Visitor identification (consent-based)

We use Snitcher, a tool that works out which company or organisation you are visiting from, based on the IP address you visit from. We use it to understand which companies are interested in our services. Snitcher is provided by Snitcher B.V. (Netherlands), and the data it collects is stored primarily in the European Union (AWS, Frankfurt). A few of its technical sub-processors, used for error logging and content delivery, operate outside the EU under standard contractual clauses.

This tool is not loaded until you give consent through the banner. If you decline, or simply do not choose, the identification script is never added to the page and it learns nothing about your visit. You can withdraw your consent at any time from section 6.

Our footer also shows a Snitcher partner badge, which is served from Snitcher's own systems rather than ours. Because your browser loads it directly, your IP address, your browser details and the address of the page you are viewing are visible to Snitcher whenever a page loads, whatever you chose in the banner. The badge itself is a picture and a link: it carries no identification script and does not switch on the tool described above. Loading the badge also runs Cloudflare's automated-traffic check inside that frame. It reads characteristics of your browser, sends them to Cloudflare, and sets a cf_clearance cookie on the snitcher.com domain that lasts one year. That cookie is partitioned, which means it is tied to your visit to this site and cannot be used to recognise you elsewhere.

Cookie / storageSourcePurposeDuration
snitcher_device_id (cookie + localStorage, with a companion _expires entry)Snitcher B.V.Device identifier, used to link visits made from the same browser12 months
snitcher_session (localStorage, with a companion _expires entry)Snitcher B.V.The browsing session in progress60 minutes
radar_sn_* (sessionStorage)Snitcher B.V.Device fingerprint values and temporary working state for the toolSession

With consent active, Snitcher collects the pages you visit, how long you stay, the page you arrived from, campaign parameters, and a set of technical details about your device and browser that together form a device fingerprint (described in the next paragraph), along with the IP address the visit comes from.

That fingerprint is a set of measurements that together tell one browser or device apart from another. Once the script has loaded, it reads how your browser draws a hidden test image, the make and model of your graphics hardware, and the number of processor cores and the memory your device reports. It reads your screen resolution, colour depth, pixel ratio and the maximum number of simultaneous touches your screen recognises. It reads the timezone set on your device, your browser language, and the plugins and fonts you have installed. It reads how many audio and video devices are attached: the number only, never their names, and with no access to your camera or microphone. It reads which methods of storing data your browser supports, whether an ad blocker is present, and your Do Not Track setting. Finally, it reads the identifying line your browser sends about itself and the platform it runs on, and signals suggesting that the browser is being driven by software rather than by a person. These values are combined into a single code, sent with the rest of the visit data, and held in the radar_sn_* entries listed above. That code is a device-level identifier. It does not by itself attach a name to anyone, and we do not combine it with any tool that would. Snitcher provides no setting that turns it off: we searched the code the tool ships and found none.

Snitcher also offers features that would make it possible to identify an individual person, most directly the automatic reading of what you type into form fields. That feature is switched off in our configuration, as are the automatic capture of clicks, of downloads and of browser errors. The device fingerprint described above is the part we cannot switch off, so the only control we have over it is consent itself: decline, or make no choice, and the script never loads, so no fingerprint is taken. If you consented and later withdraw, the script is no longer loaded, and what it stored is deleted and stays deleted. We use the tool to see which companies visit us, not to build profiles of named individuals. The tool is additionally capable of reading cookies set by other analytics and advertising platforms that may be present on a site: we use none of those platforms, so there are no such cookies on our site for it to read.

5. Cookieless statistics

To understand how the site is used in aggregate, we use Vercel Web Analytics, a measurement solution that sets no cookies and no persistent identifiers and collects no identifying personal data. Because it sets no cookies, it requires no consent. Vercel Web Analytics uses a daily technical identifier, derived pseudonymously from IP address and user-agent, refreshed every day, which cannot recognise you across days or across sites.

6. Your preferences and how to manage cookies

From here you can check the choice you made about visitor identification and change it. Withdrawing consent is as easy as giving it: withdrawal takes effect immediately and deletes what the tool had stored on your device.

You can also block or delete cookies, including technical ones, through your browser settings. Note that disabling technical cookies may break some site features, such as the booking widget. Instructions are available in the support pages of the main browsers (Chrome, Firefox, Safari, Edge).

7. Data processing and rights

How we process personal data collected through the site, your rights as a data subject, and international data transfers are described in our Privacy Policy (/privacy).

8. Updates

If we introduce further analytics or profiling cookies in the future, this page will be updated and consent will be requested again before any such cookie is set.