Politique en matière de cookies
Comme OrbitPage, il utilise le stockage facultatif du navigateur, des outils de sécurité et des analyses.
En vigueur et mis à jour à : 31 août 2026Cette traduction est fournie à titre pratique. La version anglaise reste la version de référence.
1. Scope
This policy covers orbitpage.com, including the website, login and dashboard, and explains OrbitPage's consent controls on hosted user pages at orbitpage.net. OrbitPage does not load its own Google Analytics property on hosted user pages. A page owner may enable their own analytics or external services and remains responsible for any additional notice and consent required for those choices.
2. What these technologies are
Cookies are small values stored by a browser and sent with later requests. Local storage and IndexedDB keep values in the browser until they are cleared, while session storage normally lasts for the current tab. Software development kits can use comparable identifiers to maintain a session or assess abuse.
3. Necessary storage
Necessary technologies operate because they are required to provide a requested login, security, dashboard, preference or consent-management function. Blocking them can prevent the relevant feature from working.
4. Optional platform analytics and returning-customer recognition
After Allow analytics is selected on an OrbitPage-owned platform page, the open-source FingerprintJS library reads browser and device characteristics and computes a pseudonymous visitor identifier locally. OrbitPage disables the library's optional usage monitoring, sends the identifier only to its own same-origin API and stores only a purpose-bound server-side hash. When the visitor is signed in, up to ten recent hashes can be associated with the account; a signed-out lookup returns only whether that browser hash was already associated with an OrbitPage customer. The raw identifier, Firebase UID and stored hash are not sent to Google Analytics.
This signal is approximate and can change or be spoofed. OrbitPage uses it to measure returning customers, not as authentication, proof of identity or a current free-trial entitlement decision.
OrbitPage uses Google Analytics 4 only on explicitly listed platform pages on orbitpage.com, and only after the visitor selects Allow analytics. Advertising storage, Google signals, advertising user data and ad personalisation are disabled. Email addresses, usernames, Firebase UIDs, tenant IDs and page content are not intentionally sent as analytics event parameters.
5. Provider flows you choose to open
Selecting Google sign-in opens Google's authentication flow. Selecting a paid plan or billing management opens Stripe Checkout or the Stripe Customer Portal. A Shop seller is redirected to Stripe-hosted connected-account onboarding and management, and a Shop buyer is redirected to Stripe Checkout. Opening a seller's Cal.com booking link or adding a Google or Apple Wallet pass opens the selected provider or device flow. Those providers may use their own necessary, security and fraud-prevention technologies on their domains. Their policies apply while you use those provider pages.
6. Partner blocks and external content on user pages
A page owner can add public content from independent services. OrbitPage supports social and video services such as Instagram, Facebook, YouTube, Vimeo, Loom, TikTok and Giphy; audio services such as Spotify, Apple Music, Deezer, SoundCloud and Mixcloud; and utility services such as Google Maps, Google Calendar, Calendly, Typeform and Google Forms.
Ordinary external links do not load the destination service until a visitor chooses to open them. Embedded partner content is initially replaced with a consent notice and no request is sent to the provider. The embed loads only after the visitor grants the category configured for that block, normally Preferences for maps, booking, forms and audio players or Marketing for social and video content. The page owner can change the category and is responsible for using an appropriate lawful setting.
After an embed is allowed, the external provider can receive the visitor's IP address, browser information, referring page and provider-specific cookies or identifiers. Existing sign-in state with that provider can also affect what it displays. OrbitPage does not control those technologies. The provider's own privacy and cookie terms apply.
A page owner may replace the built-in banner with iubenda, Cookiebot, CookieYes, OneTrust or an approved custom consent manager. The selected script can set its own cookies or browser values and receive consent, page and device information. The page owner is responsible for the provider contract, configuration, cookie list, legal basis and ensuring that optional content remains blocked until a valid choice.
7. Owner analytics on hosted pages
An eligible page owner may configure their own Google Analytics tag. It is separate from OrbitPage's platform property and remains blocked until the public-page visitor grants analytics consent. The page owner is responsible for the property configuration, data retention, notices, legal basis and responses to visitor rights requests.
8. Manage or withdraw consent
The first consent prompt presents optional analytics separately from essential storage. You can change or withdraw your choice at any time. Withdrawal updates Google Consent Mode, removes accessible OrbitPage-domain _ga* cookies, removes the current browser hash from the signed-in account when available and reloads the page without analytics or fingerprinting. Account deletion removes every hash stored with that account. Provider or browser storage outside OrbitPage's domain may need to be cleared in browser settings.
9. Browser controls and Global Privacy Control
You can delete or block storage through browser settings. Because necessary storage supports security and requested account functions, blocking it can stop sign-in or dashboard features. OrbitPage does not use advertising cookies, sell personal data or share it for cross-context behavioural advertising. On OrbitPage-owned platform pages, an enabled Global Privacy Control signal overrides a prior analytics grant and keeps Google Analytics and returning-customer fingerprinting denied; it does not affect necessary security or a provider page that you deliberately open. Page owners remain responsible for GPC handling by their own analytics, CMP and external services.
10. Updates and contact
This policy is updated when browser storage, providers or purposes materially change. Questions can be sent to contact@orbitpage.com.