Cookie Policy
Last updated: 11 May 2026
Aikairo handles cookies in two clearly separated contexts: the cookies we set on this site, and the first-party cookies the Aikairo tracker sets on your domain when you install it.
1. Cookies on aikairo.app
We only use cookies that are strictly necessary to authenticate you and remember your preferences. No advertising or cross-site-tracking cookies are set.
sb-*— Supabase Auth session and refresh tokens. Session-scoped or up to 14 days. Without these you cannot stay signed in.trail_hubspot_state— short-lived (5 min) CSRF token used during HubSpot OAuth handshake.aikairo_prefs(optional) — UI preferences such as last-viewed report range. 1 year.
Because these cookies are strictly necessary for the Service to function, no prior consent is required under Art. 82 of the French Data Protection Act / Art. 5 (3) of the ePrivacy Directive. We use Plausible (cookieless) for product analytics on this site; no third-party tracking cookies are set.
2. Cookies the Aikairo tracker sets on your domain
When you install the Aikairo tracker (tracker.js) on your site, it sets a single first-party cookie on your domain to identify a returning browser.
_trail_vid— a random UUID, 1-year expiry,SameSite=Lax,Secure. Used to link a new pageview to past pageviews from the same browser so we can build the conversion path.- If cookies are blocked, the tracker falls back to
localStoragewith the same key; if that is also blocked, the session is treated as a fresh visit.
The tracker exposes a JavaScript API (window.trail) gated by your consent banner. We integrate with Axeptio, Didomi, and OneTrust out of the box, and you can wire any other CMP by calling trail.enable() / trail.disable().
3. Your obligations as a tracker customer
- You must surface the Aikairo tracker in your own cookie banner / preference centre under a clear category (we recommend Analytics / Statistics).
- You must obtain prior consent from your visitors before enabling the tracker where required by the ePrivacy Directive (in practice: most EU/EEA traffic).
- The
window.trail.identify()call must only be made when the visitor has provided a basis for processing their email (e.g. they submitted a form).
4. Updates
Material changes to the cookie list are published on this page and announced via the dashboard. See the Privacy Policy for retention and your data-subject rights.