Cookie & Tracker Policy
Last updated: 20 July 2026
Short version. Inside the authenticated Olyteck consoles we set only the strictly necessary cookies that keep you signed in and protect against CSRF — no advertising cookies, no third-party analytics. On our public marketing pages we use one optional audience-measurement cookie (Google Analytics 4), and it is off until you click Accept on the consent banner. Reject is given the same prominence as Accept and your choice is remembered for 6 months (CNIL recommendation 2020-091). In our marketing emails, open/click tracking is a tracker under the same rules — we include it only if you opted in to engagement measurement, and you can withdraw at any time. Our service, security and alert emails carry no marketing tracking.
1. What cookies are
Cookies are small text files a website asks your browser to keep so it can recognise you on a
later request — for example, to keep you signed in. Similar client-side storage like
localStorage is treated as a cookie equivalent under EU/UK ePrivacy law; we treat
it the same way here.
2. Cookies we set
Strictly necessary — always on (console)
Required for the app to work; they cannot be disabled without breaking sign-in. No consent required under ePrivacy Directive Art. 5(3) / French LCEN Art. 82.
- Session cookie — identifies your browser to the server while you are
signed in.
HttpOnly,Secure,SameSite=Lax. - CSRF token — protects against forged state-changing requests.
- OIDC state & nonce — short-lived values used during the Microsoft Entra sign-in handshake.
Optional — audience measurement (marketing pages only, consent-gated)
| Cookie | Set by | Purpose | Lifetime |
|---|---|---|---|
oly_consent_v1 |
Olyteck (first-party) | Remembers your Accept / Reject choice so we don't ask again. Set regardless of choice to honour your decision. | 6 months |
_ga, _ga_* |
Google Analytics 4 | Audience measurement on marketing pages. Only set after you click Accept. IP anonymisation enabled. | Up to 13 months (Google default) |
Local storage (treated like cookies for consent purposes)
The consoles use localStorage to remember interface preferences (current tab,
table filters, sidebar state). These keys never contain personal data and exist only on your
device.
Third-party (payment)
At the billing step, Stripe's hosted Checkout may set its own cookies inside the Stripe iframe to detect fraud. Those cookies are controlled by Stripe and governed by Stripe's privacy policy. We do not place them and cannot read them.
3. Tracking pixels in our emails
Some emails can contain a tiny, invisible image (a "tracking pixel") and links that pass through a redirect. When your mail app loads them, they can tell us whether and when an email was opened, and which links were clicked. Under EU/French ePrivacy law (Article 82) these are trackers, subject to the same consent rules as cookies, and independently of whether the email itself needed your consent to be sent. This follows the CNIL Recommendation on tracking pixels in emails (14 April 2026).
Marketing emails (sent via Amazon SES) — consent-gated
Open- and click-tracking is included only for recipients who opted in to engagement measurement — the optional marketing consent you give on one of our forms or in-app. If you did not opt in, our marketing emails contain no tracking pixel and their links are not rewritten for tracking. For consenting recipients we use it to measure open/click rates, gauge and improve our emails, and adapt sending frequency. We do not use email opens to build cross-site advertising profiles.
Service, security & alert emails (sent via Microsoft 365) — no marketing tracking
Functional messages — sign-in and security alerts, product notifications, receipts and the like — carry no marketing analytics pixel. Any strictly-necessary use (for security or basic deliverability) stays within the narrow exemptions Article 82 allows and never requires your consent.
Your control
- Withdraw any time. Every marketing email has a one-click unsubscribe, which stops all marketing email and therefore all associated tracking. You can also change your marketing preferences at any time — withdrawal is as easy as opting in and applies to future emails.
- Proof & records. We keep an individual record of when and how you gave (or withdrew) consent, as required by the GDPR.
- Details. The specific purposes are presented to you at the point you opt in; questions can go to the contact address below.
4. What we do not use
- No advertising or retargeting cookies.
- No cross-site tracking pixels.
- No social-plugin cookies (no Facebook/Twitter pixels, no LinkedIn Insight Tag).
- No fingerprinting libraries.
- No analytics of any kind inside the authenticated consoles — GA4 runs only on public marketing pages, and only with consent.
5. How consent works (ePrivacy / CNIL)
- Prior consent. No Google request is made and no analytics cookie is set until you click Accept.
- Equal prominence. Reject is the same size and weight as Accept; declining is one click, no dark patterns.
- Persistence. Your choice is stored for 6 months, within CNIL guidance, then re-prompted.
- Revocation. You can withdraw consent at any time; revoking reloads the page analytics-free.
6. Manage cookies in your browser
- Chrome: Settings → Privacy & security → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Settings → Privacy → Manage Website Data
- Edge: Settings → Cookies and site permissions
If you clear or block the session cookie you will be signed out and will have to log in again.
7. Changes
If we add a new cookie or analytics provider we update this page, bump the consent-cookie version (so every browser is re-prompted), and where the law requires we ask for fresh consent before any new cookie is set.
8. Contact
Questions about cookies? Email [email protected].