Cookie and tracker policy
Our approach
In the current version, NoFlyer uses no third-party analytics, no advertising and no non-essential tracker. No advertising or analytics cookie is set. Public pages perform only first-party technical visit measurement, described below.
Strictly necessary storage
- Session refresh cookie (httpOnly, with the Secure attribute in production and SameSite=Lax): essential to authenticate and restore the owner and admin sessions.
- Access token: held temporarily in browser-tab memory and never written to localStorage; session recovery after a reload relies on the httpOnly refresh cookie.
- Local storage (localStorage): used only for functional owner-area preferences, such as onboarding progress and whether the QR code has already been seen.
- Language preference: carried by the URL (fr / en).
Guest public pages
A property public page sets no non-essential cookie and uses no advertising tracker or third-party analytics. First-party technical visit measurement is performed, from minimised and pseudonymised data (viewed route, referrer origin, locale, user-agent, a hashed IP-address value and a timestamp), without advertising profiling.
Third-party measurement trackers
Non-essential third-party analytics trackers are not active in the current version of the service. Enabling them in the future (for example an analytics tool) would require first putting in place a consent mechanism, offering a choice that allows refusal, before any setting or activation.
Consent
As no non-essential tracker is currently used, no consent banner is required. Should non-essential trackers be added in the future, a prior consent mechanism, allowing refusal, would be put in place before activation.