Loading…
Loading…
Every cookie and browser-storage key Coloseos sets, what it's for, and how long it stays.
Coloseos uses a small number of first-party cookies for the parts of the site that require signing in, plus — only if you accept analytics — pseudonymous first-party product analytics and Google Analytics loaded through Google Tag Manager. Separately, embedded videos, social posts, and externally hosted images load only if you allow embedded content. We don't run advertising cookies, we don't use Google's advertising integrations, and we don't sell your data.
You can change your preferences any time from Cookie preferences or the link in the site footer. Rejecting or revoking stops our first-party analytics beacons and immediately deletes thecoloseos_vid cookie, Google Analytics cookies, and analytics-only tab storage. We also send Google Consent Mode a denial, disable the GA property, and remove injected Google scripts and frames, so an already-loaded tag cannot continue collecting as you navigate the site. Turning embedded content off removes provider iframes and external images immediately. Cookies or storage already set on a provider's own domain remain under that provider's controls and browser settings.
Set even if you reject analytics. Without these the site can't run.
| Name | Category | Purpose | Retention |
|---|---|---|---|
| coloseos_session | Necessary | Keeps you signed in after log-in. HttpOnly, SameSite=Lax, Secure in production. | 30 days |
| coloseos_consent | Necessary | Stores your cookie preferences so we don't ask again on every page. Required for the consent system itself to work. | 13 months |
| coloseos_currency | Necessary | Remembers the USD or EUR display currency you explicitly chose. SameSite=Lax and Secure over HTTPS. | 1 year |
| coloseos_impersonate, coloseos_impersonate_return | Necessary | Lets authorised staff inspect a coach account in read-only support mode and return safely to the staff area. HttpOnly, SameSite=Lax, Secure in production. | 1 hour |
| oauth_state, oauth_verifier | Necessary | Protects a Google sign-in attempt against request forgery and proves the browser that started it is completing it. HttpOnly and deleted after the callback. | 10 minutes |
| oauth_draft, oauth_return_to | Necessary | Carries an in-progress signup reference and a safe same-site return path through Google sign-in. HttpOnly and deleted after the callback. | 10 minutes |
| calendar_oauth_state, calendar_oauth_verifier, calendar_oauth_provider | Necessary | Protects and completes a coach-requested calendar connection, including which provider was selected. HttpOnly and deleted after the callback. | 10 minutes |
An expired or revoked sign-in session cannot authorize access. We may keep its hashed server-side record and device context for up to 90 more days so an unfamiliar later sign-in can trigger a security alert; older retired records are removed by a daily retention job.
Small bits of state kept in your browser's localStorage or sessionStorage. Analytics rows are used only after you accept analytics; the campaign values are then sent with first-party events.
| Name | Category | Purpose | Retention |
|---|---|---|---|
| theme | Necessary | next-themes stores your light/dark preference so the UI doesn't flash on next load. | Until you clear it |
| coloseos-tour-minimized | Necessary | Remembers whether the landing-page tour annotations are minimised in the current tab. | Until you close the tab |
| coloseos:consent-sync | Necessary | Brief cross-tab signal that applies a cookie-preference change to other open Coloseos tabs. Removed immediately after it is sent. | Immediate deletion |
| coloseos:utm | Analytics | Keeps campaign source, medium, and campaign tags consistent while you navigate in one tab. Written only after analytics consent and sent with consented first-party events. | Until you close the tab or turn analytics off |
| coloseos:seen:<coach>:<section> | Analytics | Prevents a coach-site section-view event being counted twice after a refresh. Read and written only after analytics consent. | Until you close the tab or turn analytics off |
| colos:active-context | Necessary | Keeps the current admin page and in-progress context available to Colos-AI within the current tab. | Until you close the tab |
| coloseos:sidebar:always-show-subtabs | Necessary | Remembers a coach's sidebar display preference. | Until you clear it |
| coloseos.build.draft.v1 | Necessary | Saves an unsubmitted website-builder draft in this browser so entered content survives a refresh. | Until submitted or cleared |
| coloseos:site-dashboard:dismissed-suggestions:<coach> | Necessary | Remembers which site-dashboard suggestions a coach dismissed. | Until you clear it |
| event-template-draft | Necessary | Carries a coach-requested event template into the editor in the current tab. | Until consumed or the tab closes |
| flyers:<coach> | Necessary | Keeps local fallback edits for a coach's flyer; the saved server copy remains authoritative. | Until you clear it |
Everything below is gated on you accepting analytics in the cookie banner or preferences page. The first three rows are first-party — our own `/api/e` endpoint stores the events. The last two rows describe Google Tag Manager and the Google Analytics tag loaded through it; these are third-party and only fire when analytics is granted.
A short allowlist of completed operational actions — such as a submitted contact form or sign-in — may be counted without optional analytics. Those rows contain only the event name and one fixed, non-identifying marker: no IP-derived hash, browser, location, path, referrer, campaign, visitor, account, coach, or form details.
| Name | Category | Purpose | Retention |
|---|---|---|---|
| coloseos_vid | Analytics | Random first-party visitor identifier used to connect consented analytics events across visits. Set only after you accept analytics and deleted if you reject, revoke, or turn analytics off. Not used for advertising. | Up to 1 year, or until analytics is rejected |
| /api/e — pageviews and product usage | Analytics | Pseudonymous first-party events covering pageviews and how visitors use coach sites and content. Records the path, referrer, campaign tags, event details, browser user-agent, device class, approximate country/city/region, a daily salted hash derived from IP+user-agent, and the coloseos_vid identifier. If you're signed in, the row also carries your internal account id; coach-site paths identify the site owner. We don't store the raw IP address. | Rolling 13 months |
| /api/e — Core Web Vitals | Analytics | Same pseudonymous record, carrying LCP / CLS / INP / FCP / TTFB so we can see what's fast or slow on your device. | Rolling 13 months |
| Google Tag Manager (GTM) | Analytics | Loads analytics tags our team has configured. The GTM container script itself sets no cookies; the services it loads do (see below). Only loaded after you accept analytics, and never on the private /client, /messages, or /account workspaces. Turning analytics off sends a Google Consent Mode denial, disables GA, and removes injected Google script and frame elements. | Loaded only while analytics is enabled on an eligible page |
| _ga, _ga_508NETDDES | Analytics | Google Analytics 4 identifiers, set by the G-508NETDDES tag loaded through GTM. _ga distinguishes visitors; _ga_508NETDDES persists session state. Aggregated traffic reporting only — we do not use Google's advertising integrations. Coloseos deletes accessible GA cookies when analytics is turned off. | Up to 2 years (Google default), or until analytics is turned off |
Coloseos replaces provider iframes with a labelled placeholder before consent; external images remain absent or use a first-party fallback. Neither makes a provider request. You can open the original provider page without granting this category, or choose Allow embedded content to load embeds across Coloseos. Turning the category off unmounts images, players, and posts without changing your analytics choice.
| Name | Category | Purpose | Retention |
|---|---|---|---|
| YouTube, Vimeo, and Loom players | Embedded content | Shows coach videos, video links, and provider-hosted preview artwork in public pages and client materials. The provider receives connection data such as your IP address, browser details, and the page referrer, and may set its own cookies or browser storage after you allow embedded content. | Provider-controlled; removed from the page when you turn embedded content off |
| Instagram, TikTok, and Facebook posts | Embedded content | Shows social posts selected by a coach. The provider receives connection data and may set its own cookies or browser storage only after you allow embedded content. | Provider-controlled; removed from the page when you turn embedded content off |
| Strava activities | Embedded content | Shows Strava activities selected by a coach. Strava receives connection data and may set its own cookies or browser storage only after you allow embedded content. | Provider-controlled; removed from the page when you turn embedded content off |
| Pexels covers and other externally hosted images | Embedded content | On Coloseos web pages, shows a blog, program, event, or client-material cover selected by a coach from Pexels, or an image linked from another host. Relative Coloseos images load normally; an external image host receives connection data only after you allow embedded content. | Host-controlled; removed from the page when you turn embedded content off |
| Google favicon service and other external identity marks | Embedded content | Shows a small organization or credential mark derived from a saved domain. The external image host receives connection data only after you allow embedded content; this is separate from Google Tag Manager and Analytics. | Host-controlled; removed from the page when you turn embedded content off |
This page-level choice does not rewrite cover URLs included in SEO metadata or blog emails. Link-preview and search crawlers, and your email client when you receive a subscribed post, may fetch those images under their own remote-image controls. Authenticated authoring pages may contact Pexels to display a cover the coach already selected, and opening or searching the Pexels picker makes the corresponding authoring request.
When you make a choice, we store an audit row with a daily- rotated salted hash of your IP (never the IP itself), your browser user-agent, the version of the consent prompt you saw, the categories you accepted or rejected, the page where you made the choice, and — if you're signed in — your internal account id. We keep those rows for 13 months so we can answer a data-subject request or a regulator's question.
If we add a new category or change what's collected under an existing one, we'll bump the consent version and ask again. Your previous choice stays on file in the audit log.