Cookie Policy
Last updated: 25 September 2026 · Policy version 2026-09-05
This page explains the cookies and similar technologies stravax.ai uses, why we use them, and how you control them. A cookie is a small file this site stores on your device. localStorage and sessionStorage do the same job in a different technical form, usually to remember something for longer or only for your current visit. A pixel (also called a tracking pixel or a web beacon) is a small, often invisible image or script request that reports back that a page loaded, without necessarily storing anything on your device at all. This page covers all three, because a page that only mentioned cookies would leave the other two undisclosed.
The four categories
The cookies and storage keys we use
The cookies, storage keys and pixels our own consent banner and Google's and Meta's tags actually read or write, checked directly against the live site. "Live" means we observed it ourselves on a real page load; "Not live" means it is built into our code but not currently loaded by any page, disclosed here so this page is not written after the fact. "Party" shows whether the row is set by us directly or by Google, Meta or Cloudflare under their own policies, linked below.
Swipe sideways to see the full table →
| Name | Provider | Purpose | Category | Duration | Party | Status |
|---|---|---|---|---|---|---|
_ga | Google (GA4) | Distinguishes visitors for analytics measurement | Analytics | About 2 years | First | Live |
_ga_* | Google (GA4) | Session state for our GA4 measurement ID | Analytics | About 2 years | First | Live |
_gcl_au | Google (Ads conversion linking) | Stores click information for conversion attribution | Marketing | About 90 days | First | Live |
_gcl_aw (also _gcl_dc, _gcl_gb, _gcl_gs when the matching click ID is present) | Google (Conversion Linker) | Stores the ad click ID for conversion attribution | Marketing | About 90 days | First | Only when you arrive with a gclid in the URL |
localStorage._gcl_ls | Companion storage to the _gcl_* cookies | Marketing | Until you clear it | First | Live | |
GCL_AW_P | Google (googleadservices.com) | Google Ads conversion measurement | Marketing | About 90 days | Third | Live |
_fbp | Meta | Browser identifier for ad measurement | Marketing | About 90 days | First | Live |
_fbc | Meta | Stores the ad click ID when you arrive from a Meta ad | Marketing | About 90 days | First | Only when you arrive from a Meta ad |
localStorage.lastExternalReferrer, lastExternalReferrerTime | Meta | Referrer capture for the pixel | Marketing | Until you clear it | First | Live |
sessionStorage.stravaxAiGeoCountry | Stravax | Caches your country, for this browser session only, so we show prices in the right currency | Strictly necessary | Session | First | Live |
Manual currency choice (localStorage.stravaxAiCurrencyManual) | Stravax | Remembers a currency you picked by hand, for currency display | Strictly necessary | Until you clear it | First | Only after you pick a currency yourself |
sessionStorage.stravax_lp | Stravax | Landing-page variant flag | Strictly necessary | Session | First | Not live. Built into our code but not currently loaded by any page on this site |
sx_attr cookie, and its localStorage.stravax_first_touch copy | Stravax | Would store which ad or link brought you here (click IDs, campaign tags, landing URL, referrer) | Marketing | 90 days | First | Not live. Built into our code but not currently loaded by any page on this site |
__cf_bm, cf_clearance, _cfuvid, __cfruid, __cflb, cf_ob_info, cf_use_ob, __cfseq, cf_chl_rc_* | Cloudflare | Bot management, challenge clearance, rate limiting, load balancing | Strictly necessary | __cf_bm about 30 minutes; others vary | First | Set only as the matching Cloudflare feature engages; not all appear on every visit |
| Google Tag Manager loader script | Loads our tag container | Strictly necessary (loader) | Not a cookie | Third | Live | |
<noscript> Google Tag Manager fallback | Loads the container when JavaScript is off | Analytics | Not a cookie | Third | Live. No consent control can reach this; it loads regardless | |
| Cloudflare Web Analytics beacon | Cloudflare | Page performance and traffic measurement | Analytics, cookieless | Not a cookie | Third | Not currently loaded. If enabled, Cloudflare states this beacon uses no client-side state and does not fingerprint visitors |
| Google Fonts requests | Loads our Archivo, Geist and Geist Mono typefaces | Not a cookie; discloses your IP address to Google | Not a cookie | Third | Live on every page. A pre-consent data transfer, not a cookie | |
| Cloudflare Turnstile | Cloudflare | Confirms you are not a bot before a form submits | Strictly necessary | Not individually published by Cloudflare | Third | Live on the homepage and /pricing/ |
| Email-address decoding script | Cloudflare | Displays our email addresses correctly without exposing them to scrapers | Strictly necessary | Not a cookie | First (site feature) | Live |
| Currency lookup request | Stravax | Looks up your country to show the right currency and pick the right banner variant, from a Stravax service on another host | Strictly necessary | Not a cookie | First party, different host | Live |
| Google Ads and remarketing requests | Ad conversion and remarketing measurement | Marketing | Not a cookie | Third | Live | |
| Cal.com booking widget | Cal.com (EU) | Loads the booking calendar when you reach that step | Functional, only on your action | Not a cookie | Third | Not live. No page this site deploys loads the widget today |
sx_consent | Stravax | Stores your cookie choice and a consent reference ID, so we can show consent was properly given if we are ever asked | Strictly necessary (consent record) | 12 months | First | Live |
localStorage.sx_consent_queue | Stravax | Queues your consent choice for a retry if saving it to our server failed the first time | Strictly necessary | Until it sends, or the oldest of 20 queued items | First | Live |
localStorage.sx_consent_notice | Stravax | Records that you dismissed the cookie notice outside the regions listed under How consent works, so it does not reappear | Strictly necessary | Until you clear it | First | Live |
sessionStorage.sxGeo | Stravax | Caches which banner variant applies to you for the rest of this browser session | Strictly necessary | Session | First | Live |
On cf_clearance: this is Cloudflare's own challenge-platform clearance cookie, not one set by the Turnstile widget itself.
On our GA4 tag: it is linked to a Google Ads account. Google signals (cross-device and demographic features) is switched off for our Google Analytics properties. That link is what produces several of the Google rows above alongside GA4's own analytics cookies, so GA4 here is a marketing surface as well as an analytics one, not analytics alone.
Before you make a choice, Google's own tags may still send a cookieless measurement ping (Google's "consent mode advanced" behaviour): it sets or reads no cookie, though like any web request it reaches Google with your IP address and the page address.
How these categories map to our consent settings
Behind the scenes, your choice above sets seven technical signals (Google's Consent Mode).
| Our category | Consent Mode signal(s) it controls |
|---|---|
| Strictly necessary | security_storage (always granted) |
| Functional | functionality_storage, personalization_storage |
| Analytics | analytics_storage |
| Marketing | ad_storage, ad_user_data, ad_personalization |
The record we keep of your choice
When you make a cookie choice, we store a record of it: which categories you accepted, the time, the policy version you accepted it under, your IP address (only as a salted one-way hash, never in a readable form), your browser's user-agent string, the country and region Cloudflare derives for your connection, which site you were on, and a random reference ID. We keep each record of a choice for 36 months from the day we record it (the 12 months it stays active, then 24 more), with your IP address stored only as a salted one-way hash.
Other companies that receive data through these technologies
Google, Meta, Cloudflare and Cal.com each process some of the data described above under their own privacy policies, not this one: Google's privacy policy, Meta's privacy policy, Cloudflare's privacy policy, Cal.com's privacy policy.
How consent works
- A cookie banner appears on your first visit. You can accept all, reject all, or manage your choices, and rejecting is exactly as easy as accepting.
- Strictly necessary cookies are not covered by this banner because they always run.
- Analytics and marketing cookies do not fire until you consent, for visitors in the EU, EEA, UK, Switzerland, Brazil, Quebec and Turkey. Elsewhere they are on by default and you can turn them off.
- You can change your choice at any time using the "Cookie settings" button above or in the site footer.
Browser controls
You can also block or delete cookies through your browser settings. Doing so may affect how parts of the site work.
Questions
Contact [email protected] with any questions about this Cookie Policy. See also our Privacy Policy and Terms of Service.