SiteCandor · Legal
Cookies and Tracking
This page lists everything SiteCandor sets in your browser, and it is the complete list. It is short because the footprint is short: two cookies of our own, Google's analytics cookies where you have allowed them, and the bot check's widget.
Cookies We Set Ourselves
sc_consent— lasts a year. Remembers your answer to the analytics question, yes or no, so we only ask once. It is set when you answer — including when the answer is no.__Host-sc_session— lasts 30 days. Keeps you signed in to your dashboard after you click a sign-in link. It holds a signed record of your email address, when it was issued and when it expires — nothing else — and scripts cannot read it. It is only set when you sign in.sc_google_connect— lasts ten minutes, and only during the few seconds it takes to connect a Google account from Settings in your dashboard. It holds two random values that let us check the answer coming back from Google is the one we asked for. It is deleted the moment you come back, whether you connected or changed your mind, and it is never set unless you start connecting.
That is all three. Browsing the site without signing in, without answering the analytics question and without connecting Google sets none of them.
Cookies Set by Others
- Google Analytics (
_gaand_ga_*) — only where analytics storage is allowed, which in the EU and UK means only after you said yes. They let Google count a returning visitor as one person rather than two. IP addresses are anonymised, Google’s advertising features are switched off, and none of it runs inside the dashboard or sign-in pages. - Cloudflare Turnstile — the bot check on our forms. Its widget may set its own state to tell a person from a script; it exists so the forms can work without making you solve puzzles.
Browser Storage That Is Not a Cookie
Two items, both in your browser’s local storage:
- Dismissing the small milestone ribbon that occasionally appears on the site is noted, so it stays dismissed. It never leaves your browser.
sc_first_touch— how your first visit reached us: the campaign tags in the link you followed (theutm_part), the website you came from (its name only, never the page), and the page you landed on. It is used for 90 days and removed on your next visit after that, sent with a free audit if you ask for one, and tells us which places bring people here. It follows your analytics choice: it is not kept if you said no, nor in the EU or the UK until you say yes.
What We Do Not Use
We use no advertising or remarketing pixels, from anyone. We do not record your session or build heat maps of it, and we do not fingerprint your device. We use no third-party font service that would watch your page loads — the fonts are served from our own site.
Your Analytics Choice
If you are in the EU or the UK, nothing analytics-related is stored until you say yes — and no is a full answer. Wherever you are, your current choice is below and you can change it at any time. Blocking or deleting cookies in your browser breaks nothing here except staying signed in — with one caveat: your saved analytics answer is itself a cookie, so deleting cookies forgets it, and outside the EU and UK analytics then runs by default again until you switch it off here.
Reading your saved choice…
What we store beyond your browser, and why, is in our privacy policy. Questions go through the contact form — a person reads it.