Cookie Policy

Last Updated: 03/08/2026

This Cookie Policy explains how Pilotflows (operated by Tegi S.à r.l.-S.) uses cookies and similar technologies on pilotflows.com and app.pilotflows.com. It describes the three consent categories shown in our cookie banner and preference dialogs — Necessary, Analytics, and Marketing — and lists what each category actually stores. For broader data practices, see our Privacy Policy.

1. Consent categories

  • Necessary — always on. Required for security, authentication, consent recording, and core site features.
  • Analytics — optional. Controls Google Analytics 4.
  • Marketing — optional. Controls Meta Pixel, Google Ads tags, Calendly embeds, and related attribution storage.

2. Necessary

These technologies are required for the product to work. They cannot be switched off in the preference dialog.

NamePurposeDurationPartyStorage
pilotflows_cookie_consentStores your cookie category choices and mirrors them across Pilotflows subdomains so app.pilotflows.com can honor a choice made on the marketing site.1 yearFirst-partyCookie
cookieConsentSame consent preferences as above, kept in browser storage on the marketing site origin for the banner and preference dialogs.Until cleared by you or the browserFirst-partylocalStorage
tokenSigned-in session for the Pilotflows dashboard (app.pilotflows.com). Used so middleware and the app can keep you authenticated.10 hoursFirst-partyCookie
metar-taf-usageLimits free METAR/TAF tool usage per browser day (UTC). HttpOnly functional cookie on the marketing site.48 hoursFirst-partyCookie
preferredCommunityRoleRemembers whether you last used the pilot or skydiver community experience in the dashboard.1 yearFirst-partyCookie
sidebar_stateRemembers whether the dashboard sidebar is expanded or collapsed.7 daysFirst-partyCookie

3. Analytics

When you enable Analytics, we load Google Analytics 4 (gtag) to understand aggregate traffic and product usage. Exact cookie names are set by Google’s tag (commonly _ga and _ga_*).

NamePurposeDurationPartyStorage
_ga / _ga_* (Google Analytics 4)Google Analytics 4 identifiers used for website and product usage analytics when Analytics consent is granted. Exact names are set by Google’s gtag.Set by Google (typically up to 2 years)Third-partyCookie

4. Marketing

When you enable Marketing, we may load Meta Pixel and Google Ads (gtag), show consent-gated Calendly embeds, and persist ad click / campaign attribution. Disabling Marketing stops those scripts from running and clears Meta Pixel cookies we can remove from this site.

NamePurposeDurationPartyStorage
_fbpMeta Pixel browser identifier used to measure ads and site events when marketing consent is granted.Set by Meta (typically up to 3 months)Third-partyCookie
_fbcMeta click identifier when you arrive from a Meta ad. Used with Conversions API when marketing consent is granted.Set by Meta (typically up to 3 months)Third-partyCookie
_gcl_au / _gcl_aw (and related Google Ads cookies)Google Ads / gtag conversion and click identifiers used for ad measurement when marketing consent is granted (ad_storage). Exact names are set by Google’s tag.Set by Google (typically up to 90 days)Third-partyCookie
pilotflows_click_attribution_v1 (gclid / gbraid / wbraid)Stores Google Ads click IDs from the landing URL so conversions can be attributed after you move between pages or into the dashboard.90 days (then discarded)First-partylocalStorage
pilotflows_click_attribution_v1 (session copy)Session-scoped copy of the same gclid / gbraid / wbraid attribution values.Browser sessionFirst-partysessionStorage
pilotflows_utm_attributionCross-subdomain UTM campaign parameters so attribution survives navigation from pilotflows.com to app.pilotflows.com when marketing consent is granted.30 daysFirst-partyCookie

5. How to change your preferences

On the marketing site, open Cookie Preferences from the footer (Resources), or use the cookie banner the first time you visit. Toggle Analytics and Marketing, then save. Necessary cookies remain enabled.

You can also clear cookies and site data in your browser settings, which removes consent and other stored values until you choose again.

6. Cross-subdomain consent (pilotflows.com ↔ app.pilotflows.com)

Consent chosen on the marketing site is saved in localStorage under cookieConsent and mirrored to a first-party cookie named pilotflows_cookie_consent on the shared .pilotflows.com domain (1 year, SameSite=Lax).

That shared cookie lets the dashboard at app.pilotflows.com read the same marketing/analytics choice you made on pilotflows.com. People are often surprised that changing preferences on one subdomain affects scripts on the other — this is intentional so ad and analytics tags stay aligned across the product.

7. Contact

Questions about cookies or this policy: [email protected]
Tegi S.à r.l.-S., Luxembourg