Cookie and Storage Policy
Last revised: 5 August 2026
This policy covers cookies, browser local storage, session storage and third-party technologies used by Garcia Builder Fitness. Browser storage is not always a traditional cookie, but it can remember information in a similar way.
1. Your choices
Essential security and core functionality storage is active because the requested site or account cannot operate reliably without it. Analytics and advertising technologies are optional. Across the public site, Google Analytics is downloaded only after analytics consent; Google Tag Manager and Meta Pixel are downloaded only after advertising consent. You can accept all, reject all, choose analytics and advertising separately, and change or withdraw the choice at any time.
2. Audited storage inventory
| Name / technology | Provider | Category | Purpose | Duration | Party | Activation |
|---|---|---|---|---|---|---|
gb_consent_v1 | Garcia Builder Fitness | Essential / preference | Stores analytics and advertising choices, version and update time so the site can respect and evidence the selection. | Up to 180 days; an expired or incompatible record is removed and a new choice is requested. | First party, localStorage | When a cookie choice is saved. |
gb_attrib_v1 | Garcia Builder Fitness | Analytics / advertising attribution | Stores available UTM and click-attribution context used with consented measurement and forms. | 7 days, or earlier if consent is withdrawn or browser storage is cleared. | First party, localStorage | Only after analytics or advertising consent and when campaign parameters are present. |
gb_utm_*, gb_gclid, gb_gbraid, gb_wbraid, gb_fbclid | Garcia Builder Fitness | Analytics / advertising attribution | First-party copies of individual campaign parameters used by supported forms. | 7 days, or earlier if consent is withdrawn or browser storage is cleared. | First party, localStorage | Only after analytics or advertising consent; removed when optional consent is withdrawn. |
gb_lang, gb_language, selectedLanguage, preferred-currency | Garcia Builder Fitness | Functionality | Remembers language or display preferences. | Until changed or browser storage is cleared. | First party, localStorage | When a visitor selects or the interface saves a preference. |
gb_starter_assessment_answers, gb_starter_assessment_meta | Garcia Builder Fitness | Strictly necessary session state | Preserves assessment answers and attribution while moving through the funnel or opening the Privacy Notice in another tab. | Current browser-tab session. | First party, sessionStorage | When the assessment begins or changes. |
gb_starter_delivery_<token>, gb_assessment_submitted_event_ids_v1 | Garcia Builder Fitness | Strictly necessary / conversion safety | Shows the correct delivery notice and prevents the browser from firing the same successful lead event twice. | Current browser-tab session. | First party, sessionStorage | After a successful assessment submission/result. |
gb_last_submit | Garcia Builder Fitness | Security / reliability | Provides a short client-side form submission cooldown. | Until overwritten or browser storage is cleared. | First party, localStorage | After supported forms are submitted. |
Supabase auth token (normally sb-<project>-auth-token) and account caches such as gb_current_user | Supabase / Garcia Builder Fitness | Strictly necessary authentication | Maintains a signed-in session and the account interface. Exact token lifetime is controlled by the authentication configuration. | Session/token lifetime or until sign-out/clear; verify configured expiry before publication. | First party storage using a third-party processor | When a user creates an account or signs in. |
| Client portal state, including profile, metric, progress and selected-plan storage keys | Garcia Builder Fitness | Functionality / service delivery | Maintains client-entered interface state and local caches for account, profile, plan and coaching tools. | Until synchronised, deleted, signed out or browser storage is cleared; exact key-by-key retention requires the final portal audit. | First party, localStorage | Only when the relevant account/coaching feature is used. |
| Interface libraries and styles | jsDelivr / cdnjs | Essential content delivery | Delivers pinned Bootstrap, Font Awesome and related interface assets. No site cookie is intentionally set for this purpose; the providers receive ordinary HTTP connection data. | Request and provider security logs; no first-party browser storage is created by the website for this purpose. | Third-party content delivery | When a page that uses the relevant interface asset loads. |
| Google Tag Manager container | Advertising tag management | Loads the approved advertising container. The container itself is a loader; tags inside it may set storage listed below. | Script request for the page; any tag storage has its own duration. | Third party | Only after advertising consent. | |
Google Analytics, including possible _ga and container-specific analytics cookies | Analytics | Measures visits, engagement and funnel events without assessment contact PII in event parameters. | Provider/configuration controlled; see Google's current cookie information and the browser controls for observed expiry. | Third party | Only after analytics consent. The site can load Analytics directly when advertising consent is not granted. | |
| Google Ads, including possible advertising/click cookies | Advertising | Campaign attribution, conversion measurement and, only where separately permitted, advertising personalisation. | Provider/configuration controlled; verify actual names and expiry in the final browser audit. | Third party | Only after the relevant advertising choices are granted and an approved tag is configured. | |
| Meta Pixel | Meta | Advertising | Measures approved campaign and conversion events and may support advertising optimisation. | Provider/configuration controlled; verify the live pixel and storage in the final browser audit. | Third party | Only after the relevant advertising choices are granted and an approved tag is configured. |
_fbp | Meta | Advertising | Browser identifier used by Meta advertising measurement when the Pixel is active. | Provider controlled; verify the live expiry before publication. | Third party cookie | Only after advertising consent and Pixel activation. |
_fbc | Meta | Advertising | Stores Meta click context when an eligible fbclid visit is processed by the active Meta integration. | Provider controlled; verify the live expiry before publication. | Third party cookie | Only after advertising consent, an eligible click and Pixel activation. |
| Calendly storage | Calendly | Booking / third-party functionality | Operates appointment booking on Calendly's service. | Controlled by Calendly; verify if an embed is introduced. | Third party | Current site: when the visitor follows a Calendly link. An embed would require a separate consent review. |
| Stripe storage | Stripe | Payment / fraud prevention | Operates checkout, payment security, subscription administration and fraud prevention. | Controlled by Stripe and the checkout context. | Third party | When a visitor deliberately enters Stripe checkout or another Stripe surface. |
| My PT Hub storage | My PT Hub | Coaching / third-party functionality | Operates coaching or client functionality on the provider's service. | Controlled by My PT Hub. | Third party | Current public pages: when the user follows a My PT Hub link; re-audit before embedding it. |
3. Consent signals
The preference panel offers separate Analytics and Advertising choices. Advertising maps together to ad_storage, ad_user_data and ad_personalization; Analytics maps to analytics_storage. Functional and security storage remains granted. Rejecting optional storage does not prevent completion of the assessment.
4. Changing or deleting storage
Use “Open Cookie Preferences” to change future optional processing. You can also delete cookies and browser storage in browser settings. Deleting essential/session storage may sign you out, reset preferences or clear unfinished assessment progress. Withdrawing consent does not make earlier consented processing unlawful; it updates the choice for future processing.
5. Third-party information
Third-party services maintain their own policies and may change technology names or durations. The launch owner must inspect the final production network and storage panels after each consent state and update this inventory when the implementation changes.
6. Contact
For questions or a data-rights request, email andre@garciabuilder.fitness. See also the Privacy Notice and Terms.