מדיניות זו מפרטת את העוגיות ואת טכנולוגיות האחסון האחרות בדפדפן שבהן נעשה שימוש באתרי *.zak.co.il: מה הן עושות, מי מציב אותן, וכמה זמן הן נשמרות. התייחסות אל www.zak.co.il חלה גם על הדומיין החשוף zak.co.il — אותו אתר עצמו (דומיין השורש מפנה אל www.zak.co.il), והשניים נחשבים זהים לצורך מדיניות זו. היא משלימה את מדיניות הפרטיות שלנו.
מהי עוגייה / אחסון בדפדפן?
עוגייה היא קובץ טקסט קטן שאתר שומר בדפדפן שלכם ואשר נשלח חזרה לאותו אתר בביקורים הבאים. localStorage הוא מנגנון אחסון קרוב בדפדפן, השומר נתונים בדפדפן אך אינו נשלח בבקשות רשת. מדיניות זו מכסה את שניהם.
הסכמה
אתרי *.zak.co.il מציבים רק עוגיות הכרחיות (הדרושות לתפקוד האתר) ובנוסף את עוגיות האבטחה של Cloudflare. על פי הנחיית ePrivacy והדין הישראלי אלו פטורות מדרישת ההסכמה, ולכן אין צורך בהודעת הסכמה (opt-in). כשירות, מוצגת לכל המבקרים הודעת עוגיות אינפורמטיבית קצרה הניתנת לסגירה. איננו מציבים עוגיות שאינן חיוניות או עוגיות מעקב של צד שלישי; אם יתווספו כאלה בעתיד, מדיניות זו תעודכן והסכמתכם תתקבל בטרם יוצבו.
העוגיות והאחסון שבשימושנו
א. אתרים סטטיים — www.zak.co.il, deaf-info.zak.co.il
שם
סוג
צד
מטרה
משך
qn-transcriberserviceslocale
localStorage
צד‑ראשון
זוכר את בחירת שפת הממשק בדפי שירותי התמלול
עד שתנקו אותו
zak-legal-lang
localStorage
צד‑ראשון
זוכר את בחירת השפה (עברית/אנגלית) בדפים המשפטיים
עד שתנקו אותו
zak-cookie-notice-dismissed
localStorage
צד‑ראשון
זוכר שסגרתם את הודעת העוגיות
עד שתנקו אותו
__cf_bm
עוגייה
Cloudflare (צד ג')
ניהול בוטים / אבטחה
כ‑30 דקות
cf_clearance
עוגייה
Cloudflare (צד ג')
מתעד מעבר של אתגר אבטחה
עד כשנה
האתרים הסטטיים אינם מציבים עוגיות צד‑ראשון ואינם מפעילים אנליטיקה משלהם. שלושת פריטי ה‑localStorage שלעיל נשמרים בדפדפן שלכם ואינם נשלחים אלינו.
ב. הבלוג — tddpirate.zak.co.il (WordPress)
צד‑ראשון — הכרחיות (רק בעת התחברות או פרסום תגובה):
שם (תבנית)
מטרה
משך
wordpress_<hash>, wordpress_sec_<hash>
אימות (ניהול)
הפעלה
wordpress_logged_in_<hash>
מסמן אתכם כמחוברים
הפעלה / 14 יום
wordpress_test_cookie
בודק שהדפדפן מקבל עוגיות
הפעלה
wp-settings-<id>, wp-settings-time-<id>
העדפות ממשק הניהול
שנה
wp-postpass_<hash>
גישה לפוסטים מוגני סיסמה
10 ימים
wordpress_rec_<hash>
מצב שחזור משגיאה (ניהול)
הפעלה
צד‑ראשון — נוחות תגובה (רק אם סימנתם את תיבת ההסכמה):
שם (תבנית)
מטרה
משך
comment_author_<hash>
זוכר את שם המגיב
כשנה
comment_author_email_<hash>
זוכר את דוא"ל המגיב
כשנה
comment_author_url_<hash>
זוכר את אתר המגיב
כשנה
צד שלישי:
מקור
מטרה
הערות
Cloudflare (__cf_bm, cf_clearance)
שרת אבטחה
כמפורט בטבלה שלעיל
WordPress.com / Automattic (ללא עוגייה)
מרנדר נוסחאות מתמטיות
ראו הערה למטה — זהו טעינת תמונה מצד שלישי, לא עוגייה או פיקסל
מודולי המעקב של Jetpack בבלוג (Stats, Likes, Sharedaddy, Subscriptions, תמונות Gravatar) מושבתים, ולכן הבלוג אינו מציב עוגיות מעקב או פיקסלי מעקב של WordPress.com. גם Google Analytics / AdSense (בעבר דרך תוסף שהוסר) אינם עוד. אם יופעל מחדש אי‑פעם רכיב מעקב כלשהו של צד שלישי, יש לעדכן תחילה מדיניות זו ואת הטבלאות שלעיל, ולהתנות את העוגיות בהסכמה. נוסחאות מתמטיות (מודול "Beautiful Math" / LaTeX של Jetpack). פוסטים בבלוג המכילים מתמטיקה מרנדרים כל נוסחה כתמונה הנטענת משרתי WordPress.com (Automattic). זו אינה עוגייה ואינה פיקסל מעקב, אך — כמו כל משאב של צד שלישי — הבקשה חושפת ל‑WordPress.com את כתובת ה‑IP ואת פרטי הדפדפן שלכם בעת צפייה בפוסט כזה. אנו מגלים זאת כאן לשם שקיפות.
ג. נקודות קצה proj* / tzstring
ללא עוגיות וללא אחסון בדפדפן.
ניהול עוגיות
ניתן לחסום או למחוק עוגיות דרך הגדרות הדפדפן, ולנקות את localStorage דרך בקרות נתוני‑האתר של הדפדפן. חסימת עוגיות הכרחיות עלולה למנוע מחלקים בבלוג (התחברות, תגובות) לפעול.
שינויים
נעדכן מדיניות זו בכל שינוי במערך העוגיות/האחסון.
Cookie & Storage Policy — the *.zak.co.il websites
This policy lists the cookies and other browser-storage technologies used on the *.zak.co.il websites, what they do, who sets them, and how long they last. References to www.zak.co.il also cover the bare domain zak.co.il — the same website (the apex domain redirects to www.zak.co.il), treated identically for the purposes of this policy. It complements our Privacy Policy.
What is a cookie / browser storage?
A cookie is a small text file a website stores in your browser and that is sent back to that website on later visits. localStorage is a related browser-storage mechanism that keeps data in your browser but is not sent in web requests. This policy covers both.
Consent
The *.zak.co.il sites set only strictly-necessary cookies (needed for the site to function) plus Cloudflare's security cookies. Under the ePrivacy Directive and Israeli law these are exempt from the consent requirement, so no opt-in consent banner is required. As a courtesy, all visitors are shown a brief informational cookie notice that can be dismissed. We set no non-essential or third-party tracking cookies; should any be introduced in the future, this policy will be updated and your consent obtained before they are set.
Cookies and storage we use
A. Static sites — www.zak.co.il, deaf-info.zak.co.il
Name
Type
Party
Purpose
Duration
qn-transcriberserviceslocale
localStorage
First-party
Remembers your UI-language choice on the Transcriber-Services pages
Until you clear it
zak-legal-lang
localStorage
First-party
Remembers your Hebrew/English choice on the legal pages
Until you clear it
zak-cookie-notice-dismissed
localStorage
First-party
Remembers that you dismissed the cookie notice
Until you clear it
__cf_bm
Cookie
Cloudflare (3rd)
Bot management / security
~30 minutes
cf_clearance
Cookie
Cloudflare (3rd)
Records that a security challenge was passed
Up to ~1 year
The static sites set no first-party cookies and run no first-party analytics. The three localStorage items above stay in your browser and are never sent to us.
B. Blog — tddpirate.zak.co.il (WordPress)
First-party — strictly necessary (only when you log in or comment):
Name (pattern)
Purpose
Duration
wordpress_<hash>, wordpress_sec_<hash>
Authentication (admin)
Session
wordpress_logged_in_<hash>
Marks you as logged in
Session / 14 days
wordpress_test_cookie
Checks the browser accepts cookies
Session
wp-settings-<id>, wp-settings-time-<id>
Admin interface preferences
1 year
wp-postpass_<hash>
Access to password-protected posts
10 days
wordpress_rec_<hash>
Error-recovery mode (admin)
Session
First-party — comment convenience (only if you tick the consent box):
Name (pattern)
Purpose
Duration
comment_author_<hash>
Remembers your comment name
~1 year
comment_author_email_<hash>
Remembers your comment email
~1 year
comment_author_url_<hash>
Remembers your comment website
~1 year
Third-party:
Source
Purpose
Notes
Cloudflare (__cf_bm, cf_clearance)
Security proxy
As in the table above
WordPress.com / Automattic (no cookie)
Renders mathematical formulas
See the note below — a third-party image load, not a cookie or pixel
The blog's Jetpack tracking modules (Stats, Likes, Sharedaddy, Subscriptions, Gravatar hovercards) are disabled, so the blog sets no WordPress.com tracking cookies or tracking pixels. Google Analytics / AdSense (previously via a now-removed plugin) are gone as well. If any third-party tracker is ever re-enabled, this policy and the tables above must be updated first and the cookies gated behind consent. Mathematical formulas (Jetpack "Beautiful Math" / LaTeX). Blog posts that contain mathematics render each formula as an image loaded from WordPress.com (Automattic) servers. This is not a cookie or a tracking pixel, but — like any third-party resource — the request tells WordPress.com your IP address and browser details when you view such a post. We disclose it here for transparency.
C. proj* / tzstring API endpoints
No cookies and no browser storage.
Managing cookies
You can block or delete cookies through your browser settings, and clear localStorage via the browser's site-data controls. Blocking strictly-necessary cookies may prevent parts of the blog (login, comments) from working.
Changes
We will update this policy whenever the set of cookies/storage changes.