Gestoa — Cookies Policy
1. About this policy
This Cookies Policy explains how Gestoa.com (“Gestoa”, “we”) uses cookies and similar technologies on the Gestoa website and platform (the “Service”). It supplements our Privacy Policy, which explains how we handle personal data more generally.
2. What are cookies and similar technologies?
Cookies are small text files placed on your device when you visit a website. Similar technologies include local storage, session storage, IndexedDB, pixels/tags and software development kits (SDKs) that store or read information on your device. In this policy we refer to all of these as “cookies”.
Cookies can be:
- First-party (set by Gestoa) or third-party (set by a provider such as Google).
- Session (deleted when you close your browser) or persistent (stored until they expire or you delete them).
3. How we ask for your consent
When you first visit, we show a cookie banner. Strictly necessary cookies (§4.1) are always active because the Service cannot work without them and they do not require consent. All other cookies load only if and when you consent. You can accept all, reject all, or choose by category, and you can change or withdraw your choice at any time via the “Cookie settings” link in our website footer.
For EU and UK visitors we obtain consent before any non-essential cookie is set. For US visitors, you can opt out of analytics/advertising cookies via the banner.
Global Privacy Control (GPC). If your browser or extension sends the GPC signal, we treat it as a valid opt-out and switch off every non-essential cookie — analytics as well as marketing/advertising. Only strictly necessary cookies (§4.1) keep running. Because the signal already answers the question, we do not show you a consent banner at all — there is nothing left to ask. If you open “Cookie settings” from our footer you will see both categories switched off and locked, with an explanation; they stay off even if you select “Accept all”. The signal legally covers the “sale” or “sharing” of personal information and targeted advertising; switching analytics off as well goes beyond what the law requires, and we do it for every visitor, not only where those laws apply. We declare that we honour GPC machine-readably at /.well-known/gpc.json. GPC is an opt-out signal, not consent — it never switches anything on.
4. Categories of cookies we use
4.1 Strictly necessary (always on)
Required for the Service to function — for example to keep you logged in, secure your session, remember your cookie choices, and balance server load. These do not require consent and cannot be switched off in our banner.
4.2 Analytics / performance (consent required)
Help us understand how the Service is used — which pages and features are popular, where users encounter problems — so we can improve it. We use Google Analytics 4 and Amplitude for this.
4.3 Error monitoring (consent required where non-essential)
Help us detect and diagnose crashes and errors. We use Sentry. Some of Sentry’s client storage supports core reliability and is treated as necessary; anything used for non-essential performance analytics is loaded only with consent.
4.4 Tag management
We use Google Tag Manager to load and manage the tags above according to your consent choices. Google Tag Manager itself does not set analytics cookies, but it governs which tags fire.
4.5 Marketing / advertising (consent required)
We do not currently run advertising cookies. If we add them in future (for example Google Ads conversion tags via Google Tag Manager), we will update this policy and load them only with your consent.
5. The specific cookies and technologies we use
| Name / pattern | Provider | Type | Purpose | Typical duration |
|---|---|---|---|---|
sb-*-auth-token (and related) | Gestoa / Supabase | Strictly necessary | Keeps you signed in; maintains your authenticated session | Session / until sign-out |
| Cookie-consent preference | Gestoa | Strictly necessary | Remembers your cookie choices | ~6–12 months |
| CSRF / security token | Gestoa | Strictly necessary | Protects forms and requests from cross-site attacks | Session |
_ga | Google Analytics | Analytics | Distinguishes users | ~2 years |
_ga_<container-id> | Google Analytics | Analytics | Persists session state | ~2 years |
_gid | Google Analytics | Analytics | Distinguishes users | ~24 hours |
Amplitude device/session IDs (amp_*, local storage) | Amplitude | Analytics | Identifies a device/session for product analytics | Persistent (local storage) |
| Sentry diagnostic storage | Sentry | Error monitoring | Correlates errors and performance traces | Session / short-lived |
| Google Tag Manager container | Tag management | Loads and controls tags per your consent | N/A (loads other tags) |
6. How to manage cookies
You can control cookies in several ways:
- Our cookie banner / “Cookie settings”: accept, reject or change categories at any time.
- Your browser: most browsers let you block or delete cookies and clear local storage. Blocking strictly necessary cookies may break parts of the Service. See your browser’s help pages (Chrome, Safari, Firefox, Edge).
- Google Analytics opt-out: the Google Analytics Opt-out Browser Add-on.
- Global Privacy Control (GPC): enable it in a supported browser (or via a privacy extension) to opt out of all non-essential cookies automatically, here and on every other site that honours the signal. See §3.
7. Third-party providers
Some cookies are set by third parties who act as our processors. Their handling of data is also governed by their own policies:
- Google (Analytics, Tag Manager) — policies.google.com/privacy
- Amplitude — amplitude.com/privacy
- Sentry — sentry.io/privacy
See §8 (International transfers) of our Privacy Policy for how we handle data sent to providers outside the EEA/UK.
8. Changes to this policy
We may update this Cookies Policy as our tools change. We will post the new version here with an updated “Last updated” date, and re-request consent where the law requires it.
9. Contact
Questions about cookies: info@gestoa.com