Cookie and Storage Policy
Last revised: 4 August 2026
This policy covers cookies, browser local storage, session storage and third-party technologies used by Garcia Builder Fitness. Browser storage is not always a traditional cookie, but it can remember information in a similar way.
1. Your choices
Essential security and core functionality storage is active because the requested site or account cannot operate reliably without it. Analytics and advertising technologies are optional. On the assessment and these legal pages, Google Tag Manager is not downloaded until at least one matching optional category is granted. You can accept, reject, choose categories separately, and change or withdraw the choice at any time.
2. Audited storage inventory
| Name / technology | Provider | Category | Purpose | Duration | Party | Activation |
|---|---|---|---|---|---|---|
gb_consent_v1 | Garcia Builder Fitness | Essential / preference | Stores analytics and advertising choices, version and update time so the site can respect and evidence the selection. | Until cleared or replaced by a later choice/version. | First party, localStorage | When a cookie choice is saved. |
gb_attrib_v1 | Garcia Builder Fitness | Functional attribution | Stores the available UTM and click-attribution context used with forms and the assessment. | 7 days from the latest captured campaign touch in the current code. | First party, localStorage | When attribution capture runs; populated/updated when campaign parameters are present. |
gb_utm_*, gb_gclid, gb_fbclid | Garcia Builder Fitness | Functional attribution | Legacy first-party copies of individual campaign parameters used by existing forms. | Until browser storage is cleared; final cleanup/migration decision required. | First party, localStorage | When the corresponding parameter is present or attribution is injected. |
gb_lang, gb_language, selectedLanguage, preferred-currency | Garcia Builder Fitness | Functionality | Remembers language or display preferences. | Until changed or browser storage is cleared. | First party, localStorage | When a visitor selects or the interface saves a preference. |
gb_starter_assessment_answers, gb_starter_assessment_meta | Garcia Builder Fitness | Strictly necessary session state | Preserves assessment answers and attribution while moving through the funnel or opening the Privacy Notice in another tab. | Current browser-tab session. | First party, sessionStorage | When the assessment begins or changes. |
gb_starter_delivery_<token>, gb_assessment_submitted_event_ids_v1 | Garcia Builder Fitness | Strictly necessary / conversion safety | Shows the correct delivery notice and prevents the browser from firing the same successful lead event twice. | Current browser-tab session. | First party, sessionStorage | After a successful assessment submission/result. |
gb_last_submit | Garcia Builder Fitness | Security / reliability | Provides a short client-side form submission cooldown. | Until overwritten or browser storage is cleared. | First party, localStorage | After supported forms are submitted. |
Supabase auth token (normally sb-<project>-auth-token) and account caches such as gb_current_user | Supabase / Garcia Builder Fitness | Strictly necessary authentication | Maintains a signed-in session and the account interface. Exact token lifetime is controlled by the authentication configuration. | Session/token lifetime or until sign-out/clear; verify configured expiry before publication. | First party storage using a third-party processor | When a user creates an account or signs in. |
| Client portal state, including profile, metric, progress and selected-plan storage keys | Garcia Builder Fitness | Functionality / service delivery | Maintains client-entered interface state and local caches for account, profile, plan and coaching tools. | Until synchronised, deleted, signed out or browser storage is cleared; exact key-by-key retention requires the final portal audit. | First party, localStorage | Only when the relevant account/coaching feature is used. |
| Google Tag Manager container | Tag management | Loads approved analytics or advertising tags. The container itself is a loader; tags inside it may set storage listed below. | Script request for the page; any tag storage has its own duration. | Third party | Assessment/legal flow: only after analytics or advertising consent. Other site pages require final production verification. | |
Google Analytics, including possible _ga and container-specific analytics cookies | Analytics | Measures visits, engagement and funnel events without assessment contact PII in event parameters. | Provider/configuration controlled; verify actual names and expiry in the final browser audit. | Third party | Only after analytics consent and only if the approved GTM configuration activates Analytics. | |
| Google Ads, including possible advertising/click cookies | Advertising | Campaign attribution, conversion measurement and, only where separately permitted, advertising personalisation. | Provider/configuration controlled; verify actual names and expiry in the final browser audit. | Third party | Only after the relevant advertising choices are granted and an approved tag is configured. | |
| Meta Pixel | Meta | Advertising | Measures approved campaign and conversion events and may support advertising optimisation. | Provider/configuration controlled; verify the live pixel and storage in the final browser audit. | Third party | Only after the relevant advertising choices are granted and an approved tag is configured. |
_fbp | Meta | Advertising | Browser identifier used by Meta advertising measurement when the Pixel is active. | Provider controlled; verify the live expiry before publication. | Third party cookie | Only after advertising consent and Pixel activation. |
_fbc | Meta | Advertising | Stores Meta click context when an eligible fbclid visit is processed by the active Meta integration. | Provider controlled; verify the live expiry before publication. | Third party cookie | Only after advertising consent, an eligible click and Pixel activation. |
| Calendly storage | Calendly | Booking / third-party functionality | Operates appointment booking on Calendly's service. | Controlled by Calendly; verify if an embed is introduced. | Third party | Current site: when the visitor follows a Calendly link. An embed would require a separate consent review. |
| Stripe storage | Stripe | Payment / fraud prevention | Operates checkout, payment security, subscription administration and fraud prevention. | Controlled by Stripe and the checkout context. | Third party | When a visitor deliberately enters Stripe checkout or another Stripe surface. |
| My PT Hub storage | My PT Hub | Coaching / third-party functionality | Operates coaching or client functionality on the provider's service. | Controlled by My PT Hub. | Third party | Current public pages: when the user follows a My PT Hub link; re-audit before embedding it. |
3. Consent signals
The preference panel controls analytics_storage, ad_storage, ad_user_data and ad_personalization separately. Functional and security storage remains granted. Rejecting optional storage does not prevent completion of the assessment.
4. Changing or deleting storage
Use “Open Cookie Preferences” to change future optional processing. You can also delete cookies and browser storage in browser settings. Deleting essential/session storage may sign you out, reset preferences or clear unfinished assessment progress. Withdrawing consent does not make earlier consented processing unlawful; it updates the choice for future processing.
5. Third-party information
Third-party services maintain their own policies and may change technology names or durations. The launch owner must inspect the final production network and storage panels after each consent state and update this inventory when the implementation changes.
6. Contact
For questions or a data-rights request, email andre@garciabuilder.fitness. See also the Privacy Notice and Terms.