Cookie Policy
Last updated: 18/08/2026
This Cookie Policy explains what cookies AnnualVault uses, why we use them, and how you can change your choice at any time. It should be read alongside our Privacy Policy.
1. How consent works
On your first visit we ask you to Accept all, Reject non-essential, or Manage preferences. Analytics and advertising cookies are off by default and are only set after you actively grant consent. Necessary cookies always run because the site cannot function without them.
No Google Analytics or Meta Pixel request is sent, and no advertising identifier is read or stored, before you grant the relevant consent.
2. Cookies we use
| Category | Examples | Purpose | Provider | Data categories | Retention |
|---|---|---|---|---|---|
| Necessary | __session, __client (Clerk sign-in), av_consent (your cookie preference) | Keeps you signed in, protects the site, and remembers your cookie choice. | AnnualVault, Clerk | Session identifiers, consent choice | Session or up to 365 days (av_consent) |
| Analytics | _ga, _ga_*, _gid | Google Analytics (GA4): understand traffic and non-advertising campaign measurement. | Pseudonymous identifiers, pages viewed, device/browser type | Up to 13 months (Google default) | |
| Attribution | av_attribution | Remembers which campaign (utm_source/medium/campaign) first and last brought you here. | AnnualVault (first-party) | UTM parameters, landing page, referrer host - never a full URL or raw personal data | 90 days |
| Advertising | _fbp, _fbc | Meta Pixel: measure and improve our Meta (Facebook/Instagram) ad campaigns. | Meta | Pseudonymous identifiers, pages viewed, ad click identifiers (fbclid) | Up to 90 days (Meta default) |
3. Meta Conversions API
When advertising consent is granted, some events measured by the Meta Pixel in your browser are also sent directly from our servers to Meta's Conversions API, using the same event so it isn't counted twice. This uses your Meta browser identifiers (_fbp, _fbc) and non-identifying event data (such as which page you were on) - never your name, email address, or account details.
4. Changing or withdrawing your consent
You can change your preferences at any time using the link in the footer of every page. Withdrawing consent stops future analytics/advertising cookies from being set, and we make a best-effort attempt to remove known first-party analytics and advertising cookies (such as _ga, _ga_*, _fbp and _fbc) from your browser.
Rejecting or withdrawing consent never blocks your access to AnnualVault - it only stops non-essential tracking.
5. Contact
Questions about this policy can be sent to support@annualvault.io.