Cookie Policy

Effective date: July 14, 2026

The short version

SailSync uses first-party cookies to keep you signed in, protect shared sailing data, remember your choices, and understand which Event or campaign led to a signup. Google Analytics is optional and runs only after you allow it.

Google Analytics does not load and makes no request to Google until you select Allow analytics.

Necessary cookies

These first-party cookies support features you request or preserve security and privacy choices.

Name Purpose Typical duration
_vmg_soft_session Delivers authenticated pages and protects form submissions. Session-dependent
_sailsync_cookie_preferences_v1 Stores your encrypted cookie choice and, only after analytics consent, a server-only anonymous analytics identifier. Up to 1 year
_sailsync_event_access_* Remembers access to a code-protected Event. The Event code itself is not stored in the cookie. Up to 7 days
_sailsync_event_human_v1 Remembers a successful human-verification check before opening a shared Session. Up to 30 minutes
_sailsync_event_auth_intent Finishes an Event Save after you sign in or create an account. It contains no Event access code or Session viewer credential. Up to 30 minutes
auth and other login cookies Keeps you signed in and authorizes requests you make. Session or remembered-login duration

First-party signup attribution

The signed, HttpOnly ss_signup_attribution cookie connects a future signup with the Event, Session, or campaign that introduced SailSync. It keeps only allowlisted UTM fields, a sanitized path/referrer, and non-secret record identifiers. Event access codes and Session share-code values are never stored in it.

The cookie expires after at most one year and is deleted when signup attribution is recorded. Any identifiable account copy is automatically cleared no later than one year after the original landing was recorded. This first-party attribution does not load Google scripts and is not controlled by the Google Analytics preference.

Google Analytics (optional)

When production analytics is enabled and you select Allow analytics, SailSync may use Google Tag Manager to load Google Analytics on ordinary site pages. Public Event measurement is sent server-to-server so Google code does not run in Event pages that contain protected handoff links.

Analytics may process the page or Event viewed, broad device/browser information, campaign parameters, and an anonymous client identifier. SailSync does not intentionally send Event access codes, Session viewer links, handoff tokens, GPS tracks, or account passwords to Google Analytics.

Code-protected Event pages, access-code screens, Session handoff/verification pages, and downstream private viewer links are excluded from Google Analytics measurement.

Google may set cookies such as _ga and _ga_* after consent. Their duration depends on the production Google Analytics configuration and may be up to two years.

Withdrawing consent

Choose Keep analytics off in Cookie settings to stop future Google Analytics loading. SailSync also expires recognized Google analytics cookies presented by your browser. You can additionally clear site data through your browser controls.

Security and payment providers

Cloudflare Turnstile loads only when you ask to open a Session from an Event and need a human-verification check. Stripe may load where payment functionality is shown. Neither provider loads on an ordinary public Event page.

Questions

For privacy or cookie questions, email contact@sailsync.ai.