Cookie policy
Last updated 2026-07-24
This policy covers both yellowdesk.ai (the website) and app.yellowdesk.ai (the application), operated by Taliro Global Talent, S.L.
There is no cookie banner on this site, and that is because of what we do not do rather than an oversight. We use no advertising cookies, no tracking pixels and no cross-site profiling. Every cookie listed below is either required to make the service work or is a preference you set yourself. Under Article 22.2 of Spanish Law 34/2002 (LSSI-CE) and the Article 5(3) ePrivacy rule it implements, those do not require consent. A banner asking for permission to do something we are not doing would be theatre.
1. What a cookie is
A cookie is a small file a website stores in your browser. Some are essential to sign you in and keep you signed in. Others remember a choice you made. Others track you, and we do not use those.
The same rules apply to anything else stored on your device, such as local storage.
2. The website: `yellowdesk.ai`
The website sets no cookies of its own. It stores one thing on your device: a local storage entry named yellowdesk.lang, holding the language you chose from the switcher, so the site opens in that language next time. It holds a two-letter language code and nothing else, it is not sent to any server, and clearing your browser storage removes it.
Analytics is provided by Plausible Analytics, which is cookieless by design. It stores nothing on your device, sets no identifier, does not follow you to other websites and does not build a profile of you. It counts page views and button presses in aggregate. Plausible processes in the European Union.
The demo booking page
The /demo page embeds a scheduling widget provided by Zeeg. The widget loads a script from Zeeg and draws the booking calendar inside a frame served by zeeg.me.
It sets no cookie on `yellowdesk.ai`. We checked the page as a visitor sees it: no cookie is stored for this site and nothing in the page asks your browser to store one. Anything Zeeg stores to run the calendar is stored against zeeg.me, not against us, and we cannot read it.
Zeeg's own privacy policy governs what it does with a booking you make.
3. The application: `app.yellowdesk.ai`
3.1 Strictly necessary
| Name | Purpose | Lifetime | Attributes |
|---|---|---|---|
yellowdesk_session | Keeps you signed in. Contains a random token, not your identity. The server holds the record it points at, which is why we can revoke a session and you can sign out everywhere. | 30 days, absolute | HttpOnly, Secure, SameSite=Lax |
Without this cookie you cannot sign in. It carries no personal data itself: the token is meaningless to anyone who does not hold the corresponding database row, and we store only a hash of it.
3.2 Preferences you set
These are set when you save your preferences in Settings, and they exist so the pages you load before we have read your account render in the right language and format.
| Name | Purpose | Lifetime |
|---|---|---|
locale | The language you chose | 1 year |
country | The country you chose, which seeds the formats below | 1 year |
dateFormat | How dates are shown to you | 1 year |
timeFormat | 12 or 24 hour clock | 1 year |
The same values are stored on your user record, because e-mails have no browser to read a cookie from.
The language cookie is also set when you arrive with a ?lang= parameter, for example app.yellowdesk.ai/signup?lang=es. That is a preference you expressed by following that link.
3.3 Payments
The billing payment page loads Stripe.js, which is required to take a card securely and to keep card details away from our servers. Stripe sets its own cookies for fraud prevention:
| Name | Set by | Purpose | Lifetime |
|---|---|---|---|
__stripe_mid | Stripe | Fraud prevention. Identifies the browser across payment attempts | About 1 year |
__stripe_sid | Stripe | Fraud prevention, within a single payment session | About 30 minutes |
These load only on the payment page, and only when you go there. They are necessary to process a payment and to prevent fraud. Stripe's own privacy policy and cookie policy govern them.
3.4 What we do not use
No advertising cookies. No social media pixels. No cross-site tracking. No fingerprinting. No session recording or replay. No third-party analytics cookie of any kind.
4. Product analytics, and the commitment that goes with it
The application records product usage events in our own database: which features are used, how often, and whether a flow was completed. This is how we find out where the product fails the people paying for it. It sets no cookie and it is not third-party. It is tied to your account, not to a browser identifier, and it is described in Part B of the Privacy Policy.
The application also contains an unused integration with PostHog, a third-party product analytics service. It is switched off. No data is sent to PostHog and no PostHog cookie is set.
The commitment, and it is binding on us internally:
Neither PostHog, nor any other non-essential analytics or marketing technology, will be enabled on either property until a compliant consent mechanism is live: consent obtained before the technology loads, refusal as easy as acceptance, a record of what was consented to, and a way to withdraw it. Until then it stays off.
This is written here rather than only in an internal policy because it is a promise to the reader, and because switching it on is a single configuration change that someone could otherwise make without realising it puts us in breach of Article 22.2 LSSI-CE.
5. Controlling cookies yourself
Your browser can block or delete cookies. Every major browser has this in its privacy settings, and they all offer a way to see exactly what a site has stored.
If you block the session cookie you cannot sign in. If you block the preference cookies, the application will fall back to the language and formats on your account, or to the defaults, on each page load.
We do not respond to Do Not Track signals, because we do not track you to begin with.
6. Changes
We update this policy when what we store changes. The date at the top is the date of the version you are reading. Where a change means we start using a technology that requires consent, we will ask for it before we start, not afterwards.
7. Contact
privacy@taliro.net