Cookie Policy
This website shows no banner asking you to accept cookies. That is not an oversight: it follows from how the site is built. This page explains which cookies are actually installed, who sets them, what they are for and how long they last, so that you can check for yourself that the missing banner is a legitimate choice and not a shortcut.
The list below is not theoretical: it is the result of a check carried out by browsing the site with the browser's developer tools open on the cookie list, page by page. Two groups of entries are an exception, and the table says so row by row: the payment service's cookies and the route map's cookies, which appear only once a payment has been started and once you have clicked, and the cookie that keeps your session open after you sign in. Those we could not observe one by one, which is why they are declared by provider and purpose rather than by name. The date of the last check is the one shown at the top of this page, next to the version number.
1. What cookies are
A cookie is a small text file that a website stores in your browser and that the browser sends back on later visits. Its job is to remember something: that you have already signed in, which language you want to read in, that you are in the middle of a payment. The same rules apply to other forms of browser storage that serve similar purposes, such as so-called local storage: what matters is not the name of the technology, but whether it is there to run a service you asked for or to observe your behaviour.
Italian and European law distinguishes two families, and treats them very differently.
Technical cookies are the ones that are indispensable for the website and the services you ask of it: keeping a sign-in session open, completing a payment, protecting a service from automated requests. For these your consent is not required, because without them the site simply cannot do what you asked it to do. They must, however, be declared, and that is what this page does.
Profiling, non-anonymous analytics and advertising cookies do something else: they track who you are and what you do, on the site and sometimes beyond it, in order to build a profile of your interests. For these, consent is mandatory: it must be obtained in advance, that is, before they are installed, and it must be freely given, specific and revocable. Banners exist in order to collect that consent. This website uses no cookie of this family.
2. Why there is no banner on this website
A banner makes sense when there is something to consent to. Here there is not, for three verifiable reasons.
Traffic statistics are collected without cookies. We want to know how many times a page has been viewed and where visitors arrive from, and an aggregate count is enough for that. The tool we use is Vercel Web Analytics, from Vercel, the provider that hosts the site: it installs no cookies, assigns you no persistent identifier and builds no profile whatsoever, and it cannot tell us who visited a page, nor recognise you on your next visit. We do not use Google Analytics or any advertising tool, there is no social network pixel, and none of these figures is cross-referenced with the data of people who request a quote.
The only cookies present are necessary to make the site work. They belong to the service that manages access to your account and, at the moment of payment only, to the service that collects the card payment. They are listed one by one in the table under point 3.
Third-party content that is not needed to make the site work does not load by itself. The route map hosted by Strava, the only external component the site could do without, stays a placeholder until you decide to load it: the click is the consent, and it comes first by design. Point 4 lists all five third-party components and separates the necessary ones from this one.
The result is that there is nothing we need to ask you about before installing it. We prefer a website that does not put a window in front of you to close, over a website that asks permission to do something it could avoid doing.
3. Cookies used
This is the situation observed while browsing the home page, the quote request form, the public pages in Italian and English, and the sign-in page.
| Name or family | Who sets it | What it is for | Duration |
|---|---|---|---|
__client | Clerk, the service that manages account access | Identifies the browser to the authentication service: it is the cookie that access to the members' area relies on | About 13 months (400 days) |
__client_uat, plus a variant with a suffix (__client_uat_…) | Clerk | Signals whether a sign-in session is active in this browser, so the site knows whether to show you the members' area or the login page | About 13 months (400 days) |
__cf_bm | Cloudflare, an infrastructure provider used by Clerk | Purpose as declared by the provider: telling requests coming from a person apart from automated ones, protecting the authentication service | 30 minutes |
_cfuvid | Cloudflare, an infrastructure provider used by Clerk | Purpose as declared by the provider: applying its own rate limits to incoming requests | Until you close the browser |
| Cookies set by SumUp | SumUp, the service that collects card payments | Making the card payment form work | Decided by SumUp, only from the moment you start the payment |
Cookies set by Strava, currently from the strava-embeds.com domain | Strava | Making the interactive route map work | Decided by Strava, only from the moment you click the placeholder |
Three clarifications, because a table on its own would be inaccurate.
The last two rows are not a list of names. SumUp's and Strava's cookies are installed by those providers inside their own components, and they appear at two precise moments only: when you start a payment and when you load the map. Their names and durations are decided by them and may change without our being told: that is why we declare them by provider and purpose, rather than publishing a list that might already be out of date as you read it. If you want the detail, those two providers' own policies set it out.
The names of the sign-in cookies may change, their purpose does not. The authentication service updates its own software, and cookie names with it; in addition, once you sign in, a further cookie holding the reference to the open session is added to the ones listed above. What does not change is that they are all necessary to make sign-in work, that none of them profiles you, and that none of them is used for advertising purposes, either by us or by the provider.
No analytics cookies. The check turned up no traffic-analysis cookie, no advertising cookie and no social network cookie. That is the only way to make what point 2 states actually true.
Local browser storage
Besides cookies, the site saves some information in your browser's local storage. These are not cookies (they do not travel along with every request), but the rules are the same, so they must be declared too. None of these entries is there to profile you or to follow you from one site to another: almost all of them exist so that you do not have to type again what you have already typed. Two, however, deserve a further word: one contains the contact details you typed into the form, and another has your account identifier written into its own name.
- The draft of your quote request and the point in the form you have reached (
fastquote_data,fastquote_step,fastquote_v): if you close the page halfway through and come back later, you find what you had already filled in instead of starting over. The draft is rewritten on every change to the form and it holds everything you have typed up to that point, including your name, email address, telephone number and free-text notes. It is not a harmless entry and we do not present it as one: it stays in your browser and is not sent anywhere on its own, but it is data about you in every respect. It is deleted once you send your request, and you can delete it earlier from your browser settings. - The quote waiting to be linked to your account (
fastquote_pending): if you send your request choosing to create an account, we save here the identifier of the quote you have just sent, together with the email address you gave us. When you complete registration, only the quote identifier is read back and used, in order to write into our systems the link between that request and your new account, so that you do not have to send everything all over again; the email address written there never leaves your browser. Immediately afterwards the entry is deleted along with the draft. It is the only case in which part of the content of local storage leaves your device, and that part is the quote identifier. - A marker that your account has already been matched with our records (
user_initialized_…), so that the check is not repeated on every sign-in. The name of the entry contains your account identifier at the authentication service: it is therefore data about you, even though it never leaves your browser. - A marker that you have already opened the link to leave a Google review (
ce_review_google_…), so the invitation is not shown to you every time. The name of the entry contains the identifier of the quote it refers to. - The language you chose (
ce_lang), so that Italian is not offered back to you while you are reading in English. - Some configuration parameters of the authentication service (
__clerk_environment), which the provider keeps so it does not have to request them on every page.
You can delete all of this from your browser settings, just as you delete cookies. Two consequences to know about first: you lose the draft of the quote you were filling in, and, if you delete it before completing registration, the link described above is broken. In that case the request you had already sent remains valid and we still work on it, but it will not appear in your members' area: write to us and we will link it up ourselves.
4. Third-party content
The site loads five components provided by outside parties. They are not five equivalent cases, and the distinction is worth making: three are technically indispensable, one counts visits without installing anything, and only the fifth could install cookies of its own. It is also the only one that does not load by itself.
The authentication service
Account access is managed by Clerk, and its component is loaded on every page, public pages included. That is not a matter of convenience: the site is a single application which, in order to know whether to show you the «Sign in» button or your members' area, must be able to check at any moment whether you have an open session. Without this component authentication does not work at all: it is technically necessary, and the cookies it installs are technical cookies.
The data store
Quotes, proposals, orders and the catalogue of areas and experiences are held on Airtable, and the site reads and writes them straight from your browser: the request leaves your device and goes to the api.airtable.com domain, which you can recognise in the network panel. This also happens on the public pages and without your having signed in: when the quote request form loads the list of areas and experiences, when you open the detail page of an experience or of an area, and when you send your request. It is technically necessary: without it those pages have nothing to show and the request cannot be sent.
It installs no cookies. But because the request leaves your browser, Airtable receives your IP address even if you are only looking at the catalogue and have given us no data at all. We declare it here because it is what you would see in the network panel, and it is right that you should know before you go looking for it. Which data is then stored, for how long and with what safeguards for transfers outside the European Union is described in the Privacy Policy.
The statistics tool
Visit counting is provided by Vercel, the company that hosts the site, and this too is loaded on every page. In the published version it does not come from an outside domain: the script is served from our own address, at the path /_vercel/insights/script.js, and it is from there that the counts reach Vercel. It installs no cookies (we checked, by loading the site and comparing the cookie list before and after) and it assigns you no identifier. It is a third-party component present on every page, and we declare it as such: there simply is nothing to consent to.
The payment service
Card payments are handled by SumUp. Its component is not loaded while you browse: it comes into play only when you start paying for a proposal, and that is the moment the payment form is added to the page. Here too the technical necessity is plain: without it, the payment you are asking to make cannot be collected.
The route map
In the detail view of a proposal, inside the members' area, we show the interactive route map, which is hosted by Strava. The maps we publish today are served from the strava-embeds.com domain: we name it so that you can recognise it in your browser's network panel, but it is not a perpetual guarantee: each proposal's map is inserted by hand by us, and the domain would change if we changed tools. This content is not technically necessary: it is something extra, and loading it gives the provider your IP address and the ability to install its own cookies.
For that reason it is not loaded automatically. In its place you find a placeholder telling you exactly this, with a button to load it. Until you press that button, your browser does not contact Strava in any way: no requests, no IP address, no cookies. The click is your consent, and it comes before the loading.
It is worth being precise about how long that consent lasts, because the answer is «not long», and that is a good thing: we do not store it anywhere. The site only keeps in mind the last proposal whose button you pressed: as long as you stay in the members' area and come back to that one, the map reappears without asking you anything. For any other proposal, including ones whose button you had pressed a moment earlier, the placeholder returns and a new click is needed. And if you reload the page, everything resets: no map is loaded until you ask for it again.
5. How to manage cookies from your browser
Cookies live in your browser, and the browser gives you full control over them. In all the most widely used browsers (Chrome, Safari, Firefox, Edge) the cookie settings sit in the section devoted to privacy or to website data, where you can:
- see which cookies have been installed by this and any other site, with their name, duration and who set them: it is the same list we consulted to compile the table under point 3, and you can check it yourself;
- delete them, all of them or only those belonging to one specific site;
- block them in advance, wholesale or distinguishing between the cookies of the site you are visiting and third-party ones;
- delete them automatically when you close the browser.
Menu entries differ from browser to browser and from version to version: your browser's own help page, under the cookie heading, is the most up-to-date source for the exact steps.
One important warning. The cookies listed under point 3 are technical, which means that some things depend on them. If you block or delete them:
- you will not be able to access your members' area. The authentication service needs its own cookies in order to open and maintain a session: if you block them, sign-in either fails or logs you straight back out. This is not a fault in the site, and it is a consequence we cannot work around;
- you will not be able to complete a payment, because the provider's payment form needs its own cookies to work;
- if you delete the sign-in cookies while you are using the members' area, you will be logged out and will have to sign in again.
The public pages (the home page, the experiences, the quote request form) keep working even with cookies blocked: you can browse the site and send a quote request without accepting anything.
6. References
How we handle personal data, on which legal bases, for how long we keep it, which providers we entrust it to and which rights you can exercise is described in the Privacy Policy.
For any question about this page, to report a cookie you have observed and that is not declared here, or to exercise your rights, write to info@cyclingexperience.it. Reports of inaccuracies are welcome: this page is worth exactly as much as its accuracy.
This Cookie Policy is updated whenever anything changes in what it describes. The version number and the date of the last update are shown at the top of the page.