Last updated 23 Sep 2026
Cookies this website actually sets
trinitycures_sessionid
A Django session cookie. It is needed for staff login and for the website to keep a server session. It is HttpOnly and lasts about 24 hours by default (or until the session expires).
trinitycures_csrftoken
Protects appointment, contact, and dashboard forms from cross-site request forgery. It is required for those POST forms to succeed.
cookieConsentAccepted
Set by the cookie banner in your browser when you choose Accept (value true) or Reject (value rejected). It lasts 365 days and uses SameSite=Lax. It is not HttpOnly.
What the banner does not do
Choosing Reject only stores cookieConsentAccepted=rejected and hides the banner. It does not currently switch off visitor IP/path tracking or block session/CSRF cookies, because those are used for site security and operations.
Analytics vs cookies
Visitor analytics (IP address, user-agent, page path) are stored on our server when you open a public page. That tracking is not controlled by the cookie banner in the current code.
How to control cookies
You can clear cookies in your browser settings. After clearing cookieConsentAccepted, the banner will show again.
