1. What cookies are, in plain English
A cookie is a tiny text file that a website drops into your browser so it can recognise the same device on the next click or the next visit. That is the whole trick. Cookies do not run code, cannot install software and cannot read the rest of your hard drive. Some are set by the site you are looking at, called first-party, and others by a service embedded on that site, called third-party. On overlog.gg we treat the word "cookie" as shorthand for the wider family of storage devices covered by the ePrivacy Directive, including browser local storage, session storage and tracking pixels. If any of them touch your device, they get listed on this page.
2. The legal basis we rely on
We publish out of the UK and serve visitors across the EU, so we work to the UK GDPR, the EU General Data Protection Regulation and the Privacy and Electronic Communications Regulations (PECR). The rule that matters most is straightforward: strictly necessary cookies can be set without asking, but every other category needs your prior, informed, freely given consent before it loads. Rejecting the optional buckets has to be as easy as accepting them, and you have to be able to change your mind at any time. That is exactly how our banner is built, and section five explains how to reopen it whenever you like.
The consent tool in one line. Click the "Cookie settings" link in the footer, or clear the overlog_consent cookie in your browser, and the preference banner returns on your next page load, letting you switch analytics or affiliate tracking on or off without having to email anyone.
3. The three categories we use
Rather than sneaking dozens of cookies onto the page and burying them in jargon, we keep the count small and sort what is left into three buckets. The label a cookie carries decides whether it needs your consent before it can load, and it is the same label the consent tool exposes on its sliders.
3.1 Strictly necessary
These keep the site usable. They remember your consent choice so the banner stops nagging, protect the forms from automated abuse and let our CDN serve pages from the nearest edge. Without them you would see the banner on every click, the search box would misbehave and load balancing would fall over. Because they are essential for a service you actively asked for, PECR lets us set them without a consent prompt. You can still block them in your browser, but the site will feel broken.
3.2 Analytics and performance
These tell us which guides are being read, which pages crash on which phone models and where readers scroll off before finishing. We use Google Analytics 4 with IP anonymisation, plus Microsoft Clarity for pooled heatmaps and Matomo for a self-hosted second opinion. None of them see your name, email or payment details, and we never join analytics data to identifiable profiles. Nothing in this bucket loads until you tap "Accept" or move the analytics slider on our consent banner.
3.3 Marketing and affiliate tracking
We do not run display ads, retargeting pixels or social-media conversion trackers on overlog.gg. The only marketing-adjacent thing we do is drop a first-party click ID when you follow an outbound link to a casino, so the operator can credit the referral to us if you sign up. The plain-English version lives in our affiliate disclosure. This category is off by default and only wakes up once you have given consent.
4. Every cookie, at a glance
The table below is the full, unabridged list of what we set on this domain today. If we ever add or remove one, this table is the first thing we update, and the "Last updated" date at the top of the page moves with it.
| Category | Cookie / storage key | Purpose | Retention | Opt-out |
|---|---|---|---|---|
| Strictly necessary | overlog_session |
Anonymous session ID for security, rate limiting and CDN routing. | Session (deleted on browser close) | Clear browser cookies |
| Strictly necessary | overlog_consent |
Stores your banner choice per category so the banner does not reappear. | 12 months | Delete cookie to reopen banner |
| Analytics | _ga, _ga_<ID> |
Google Analytics 4, anonymised traffic and session counts. | 13 months | Banner slider, or Google opt-out add-on |
| Analytics | _clck, _clsk |
Microsoft Clarity heatmaps and scroll data, pooled and anonymous. | 12 months / session | Banner slider |
| Analytics | _pk_id, _pk_ses |
Matomo self-hosted analytics with IP anonymisation switched on. | 13 months / 30 minutes | Banner slider |
| Marketing / affiliate | overlog_cid |
First-party click ID appended when you follow an outbound casino link, used for referral attribution. | 90 days | Banner slider |
| Marketing / affiliate | Operator-side (e.g. btag, affid) |
Set by the casino or its network after you land on their site; governed by their cookie policy, not ours. | Typically 30-90 days | Manage on operator's site |
That really is the entire list. No advertising exchanges, no browser fingerprinting scripts, no data brokers. If you spot anything on the wire that is not covered here, please tell us via the contact page and we will investigate the same day.
5. Our consent tool, and changing your mind
The first time you land on overlog.gg from a fresh browser, a banner appears at the bottom of the screen with three equally weighted buttons: Accept all, Reject all, and Manage preferences. Nothing in the analytics or marketing categories fires until you choose. If you tap Reject all, we log the "no" in the overlog_consent cookie so you are not asked again on the next click.
Changing your mind later is deliberately painless. Scroll to the footer, click "Cookie settings" and the banner returns pre-filled with your current choices. You can flip individual sliders, save and the change takes effect immediately. Withdrawing consent stops future collection; anything already gathered stays in our anonymised analytics logs unless you ask us to remove it via the routes set out in the privacy policy.
6. Managing cookies in your browser
If you would rather control cookies at the browser level for every site you visit, all of the mainstream browsers give you the same three tools: view a list of what has been stored, block by category or by domain, and delete on demand. The exact menu path drifts every few releases; the routes below were correct at the last update.
- Google Chrome (desktop): Settings → Privacy and security → Third-party cookies. Choose "Block third-party cookies" or use the "Sites allowed to use cookies" list to whitelist specific domains.
- Mozilla Firefox: Settings → Privacy & Security → Enhanced Tracking Protection. Selecting "Strict" blocks cross-site tracking cookies, fingerprinters and known trackers by default.
- Safari on macOS: Safari menu → Settings → Privacy. Tick "Block all cookies", or open "Manage Website Data" to remove entries site by site.
- Safari on iOS or iPadOS: Settings app → Safari → Advanced → Website Data, or toggle "Block All Cookies" on the main Safari settings page.
- Microsoft Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data.
- Brave: Settings → Shields → set "Trackers & ads blocking" to Aggressive; cross-site cookies are then blocked automatically.
- Samsung Internet on Android: hamburger menu → Settings → Sites and downloads → Block cookies.
- Private, incognito or InPrivate windows: any cookie set in a private window is discarded automatically the moment the last private tab is closed.
One warning before you scorch the earth: blocking the strictly-necessary bucket will stop the consent banner from remembering your choice, so it will pop up on every page load. Blocking analytics or affiliate cookies has zero effect on the reading experience and never locks any content away.
7. Third parties and affiliate click IDs
Some of the tracking you may notice while browsing does not originate on our servers at all. The most common case is affiliate attribution: when you click a "Visit casino" button, we append a short click ID to the destination URL and, in most cases, the operator or their affiliate network then sets its own cookie so any account you open in the following weeks is credited to overlog.gg. That commission is how we keep the lights on without paywalls or display ads, and the fee is paid by the operator, never by you.
From the second you land on the casino's domain, its cookie policy takes over from ours. We cannot switch off, shorten or read those cookies, and their behaviour will differ from operator to operator. Full plain-English detail on how the commercial relationship works, including which links are affiliated and how it does or does not influence our ratings, sits in the affiliate disclosure.
8. How long each cookie sticks around
Retention on this site follows a "shortest useful window" principle: session cookies die when you close the tab, consent choices last a year so we do not have to nag you every week, analytics cookies expire in line with the vendor default of thirteen months, and the affiliate click ID clears itself after ninety days. When a cookie hits its expiry the browser deletes it automatically; there is nothing you need to do. Our server-side analytics logs are separately trimmed on a rolling twenty-six-month schedule, matching the retention window disclosed in the privacy policy.
9. Frequently asked questions
Do I have to accept cookies to read the reviews?
No. Tap "Reject all" on the banner and every review, guide and comparison table stays fully readable. Only the strictly-necessary pair remains, and neither of them identifies you personally.
Will you sell my browsing data?
No. We do not sell, rent or share cookie data with data brokers, ad exchanges or social networks. The analytics vendors listed above are contractual data processors and act only on our written instructions.
What happens if I clear my cookies?
The consent banner will reappear on your next visit because the overlog_consent cookie is gone. Any affiliate attribution window from an older click will also end, which is worth knowing if you clicked one of our links a few days ago and were planning to sign up now.
Do you honour Do Not Track or Global Privacy Control?
We treat Global Privacy Control signals as a valid rejection: when your browser sends one, we skip the banner prompt and leave analytics and marketing off. The older Do Not Track header is not consistently implemented across browsers, so we do not rely on it on its own.
I am on a shared device. Can I wipe my history from your side?
Analytics data is stored in aggregate, so there is nothing personally linked to you to wipe. If you can identify approximate visit times, though, get in touch through the contact page and we will walk through the options with you.
10. Contact and policy updates
Questions, corrections and formal data-protection requests all go through the contact page. Anything to do with personal data more broadly, such as access, deletion or portability requests under UK GDPR or GDPR, is covered end-to-end in the privacy policy. We review this cookie page whenever we swap an analytics tool, retire a script or the regulator publishes fresh guidance; the last-updated date at the top of the page will always match the version you are reading.