1. Analytics is off until you choose
Until you explicitly allow analytics, browsing useobelo.com creates no analytics identifier, sets no analytics cookie, and makes no analytics request to Obelo or Google. The site does not use advertising cookies.
If you allow analytics, this public site uses both Obelo's consent-gated first-party measurement and Google Analytics 4, which may set the cookies described below. The signed-in application at app.useobelo.com is a separate service with a separate storage model; section 5 covers it.
2. Analytics on this site is opt-in
Before you make a choice, this site creates no analytics identifier, sets no analytics cookie, and makes no analytics request. If you decline, the site stores only your refusal and this policy version in local browser storage so it does not ask again; that refusal is never sent anywhere. The banner is the only control that can turn analytics on.
Declining changes nothing about how the site works. Every page, form, the scorecard, the waitlist, and the transfer of your scorecard result into Obelo all function identically with analytics off. Your decision is recorded against the version of this policy it was made under, so if we ever change what analytics does, a decision made under the old version does not silently carry over.
A refusal never leaves your browser. We do not record, transmit or count the fact that you declined.
3. What is stored after your choice
If you decline, only the decision record below is stored. If you allow analytics, the remaining browser storage and cookies may also be created:
- →Your decision (
obelo_analytics_consentand its policy version) — written whether you allow or decline, so the banner stops asking. - →Google Analytics cookies (
_gaand a property-specific_ga_*cookie) — pseudonymous client and session identifiers used to distinguish visits. Google normally keeps these for up to two years and may refresh their expiry when you return. - →A random visitor identifier (
obelo_visitor_id) — 128 random bits. It is not derived from anything about you, contains no timestamp, and is replaced automatically after 180 days. - →A random session identifier (
obelo_session_id) — held only for the browser session and expiring after 30 minutes of inactivity. - →Campaign tags from the link you arrived on (first and last touch, and the page you entered on) — only the standard
utm_*and referral values, never the rest of the address. These are kept so that if you later start using Obelo we know which campaign brought you; they are not attached to the events described in section 4.
4. What is sent, and what is never sent
Obelo's governed events go to /api/events on this domain. Each event is one of a fixed, published list of thirteen: a page view, a consent grant, a CTA click, a pricing view, a change of billing period, starting and finishing the scorecard, and starting, sending or failing to send either the contact form or the waitlist form.
Each event carries only values drawn from a fixed vocabulary — which page you were on, as one of fourteen names from a published list rather than an address; which governed button you used and roughly where on the page it was; which plan and billing period you were looking at; what you told us a contact request was about; whether a form succeeded or failed and in what category; and how you arrived, as one of seven categories. Anything outside that list is rejected rather than trimmed, both in your browser and again on our server.
After the same opt-in, this site loads Google Analytics 4 for measurement ID G-QM165BVYP4. On each page navigation, Google receives one page-view event containing a broad page category from the same fourteen-name list, pseudonymous cookie identifiers, and standard browser and network information that accompanies a web request, such as browser/device characteristics and IP address. Google may use the IP address to derive approximate location, but GA4 does not expose the individual address to Obelo. Advertising storage, advertising personalization, Google Signals, Enhanced Measurement, granular location and device collection, and user-provided data collection are disabled by Obelo. Obelo manually sends the broad page views described here. GA4 may also generate standard session and engagement events after that page view, using the same sanitized broad page context; Google still processes standard browser, device, and network metadata as the analytics processor. Google processes this information under its privacy policy.
Obelo configures this standard GA4 property to retain user-level and event-level data for two months, with user-data retention set not to reset on new activity. Google's retention setting does not apply to standard aggregated reports, which may remain for longer. Google may process analytics data on servers outside your country; where required, international transfers rely on adequacy decisions or contractual safeguards such as Standard Contractual Clauses. Google describes those safeguards in its data-transfer frameworks.
The following are never sent by either analytics path:
- →Your name, email address, company, or message
- →Any scorecard answer you typed, and not your score either — only which of four bands your result fell into, how many questions the scorecard asked, and how long you spent on it
- →A full URL or page address, query string, fragment, dynamic blog slug, or dynamic path segment. A page is reduced to a broad name from a fixed list before it reaches either system, so your waitlist referral code cannot be expressed.
- →The address of the site you arrived from — only its category
- →Your waitlist position, exactly or approximately, and your referral code
- →The campaign-tag values from section 3. They are kept for attribution if you sign up; the values are not sent with your activity.
- →Transfer tokens, or any account, organisation or user identifier
Your IP address reaches Obelo's server and Google when a request is made to each service. Obelo does not attach it to the governed first-party event record.
5. Changing your mind, and the Obelo application
Use the Analytics control in the footer of any page. The label tells you the decision currently in force. Choosing to withdraw stops future Obelo and Google Analytics events, disables the Google property in this browser, and erases the identifiers, campaign tags, and accessible _ga cookies listed in section 3. The record that you declined remains so the banner does not ask again. Withdrawal cannot remove information already processed into aggregated analytics reports.
You can also clear this site's storage in your browser settings at any time, which returns the site to the state it is in before any decision has been made.
The signed-in application at app.useobelo.com is a separate service with a separate storage model. It uses cookies that are strictly necessary to keep you signed in and to secure your session, and it may use cookies set by the providers named in our privacy policy — including our authentication provider and payment processor. Those essential application cookies cannot be disabled without preventing the application from working; they are not the analytics cookies controlled by this website's footer.
6. Updates to this policy
We may update this Cookie Policy from time to time. Any change is published on this page with a new revision date and a new consent policy version, and a new version means we ask again rather than assuming your previous answer applies to something you did not agree to.
Contact Us
If you have questions about this policy or about what we store, contact us atsales@useobelo.com.