Cookie Policy
This Cookie Policy explains what cookies and browser storage A22 (“we”, “us”, or “our”) uses when you visit a22team.com, why we use them, and how you can manage them. We use only strictly necessary storage: no advertising cookies, no cross-site tracking, no third-party analytics.
2. What We Use
A22 uses a minimal set of strictly necessary storage. The following table lists everything we place in your browser:
| Name / Key | Type | Purpose | Expires |
|---|---|---|---|
| sb-*-auth-token | localStorage | Supabase session token. Keeps you signed in to the platform. The platform cannot function without it. | Sign-out or session expiry |
| a22_cookie_consent | localStorage | Records that you have acknowledged our cookie notice. Stores only the string “accepted”. Contains no personal data. | Until browser storage is cleared |
| Preference keys | localStorage | Your selected currency (EUR/USD) and interface preferences. Contains no personal data and is never transmitted to our servers. | Until browser storage is cleared |
| cf_clearance (Cloudflare) | Cookie (Cloudflare) | Set by Cloudflare Turnstile to verify you have passed a bot challenge. Set by Cloudflare, not A22. See section 4. | Cloudflare's policy |
3. Strictly Necessary Storage
All storage listed above is classified as strictly necessary. Under the EU ePrivacy Directive and GDPR, strictly necessary cookies and storage may be used without prior consent because they are essential for a service the user has explicitly requested. Specifically:
- Authentication storage is necessary to keep you signed in. Without it, you would be signed out on every page load and the platform would be unusable;
- Cookie consent record is necessary to avoid showing you the cookie notice on every subsequent visit;
- Preference storage is necessary to remember the display settings you have explicitly chosen;
- Cloudflare Turnstile is necessary to protect registration and password reset from automated bot abuse (see section 4).
A22 does not use any storage that requires prior consent under the ePrivacy Directive or GDPR.
4. Cloudflare Turnstile
A22 uses Cloudflare Turnstile on its account registration and password reset pages. Turnstile is a privacy-friendly CAPTCHA alternative that protects these pages from automated bot abuse without requiring you to solve visual puzzles.
When Turnstile runs, a script loaded from https://challenges.cloudflare.com analyses browser signals to determine whether the visitor is human. During this process, Cloudflare may set cookies or use other browser signals. These are:
- Operated and set by Cloudflare, not by A22;
- Governed by Cloudflare's Privacy Policy;
- Strictly necessary to protect the platform from abuse — without them, registration and password reset would be vulnerable to automated attacks;
- Not accessible to A22 and not used for advertising or cross-site tracking.
Cloudflare Turnstile is designed to have minimal privacy impact. Unlike traditional CAPTCHAs, it is built to avoid fingerprinting techniques that track you across websites. For further detail see Cloudflare's Privacy Policy.
5. Cookie Consent
When you first visit A22, a notice appears at the bottom of the page explaining our use of browser storage. When you click “Got it”, we store the key a22_cookie_consent = accepted in your browser's localStorage so the notice does not reappear on future visits.
Because A22 uses only strictly necessary storage, this notice is informational rather than a consent gate. Essential storage is already present whether or not you click the button. You are acknowledging that you have been informed, not granting consent for optional cookies.
If you clear your browser storage (for example, using your browser's “Clear browsing data” feature), the notice will reappear on your next visit.
6. What We Don't Use
A22 does not currently use any of the following:
- Advertising cookies or tracking pixels;
- Cross-site tracking that follows you between websites;
- Third-party analytics scripts (e.g. Google Analytics, Mixpanel, Hotjar);
- Session recording or heatmap tools;
- Social media tracking tags (e.g. Facebook Pixel, LinkedIn Insight Tag);
- Marketing retargeting cookies.
If any non-essential storage is introduced in a future update, we will revise this policy, notify you by email if material, and seek your consent where required by applicable law before any such storage takes effect.
7. Managing Cookies & Browser Storage
You can view, manage, and delete cookies and localStorage data at any time through your browser settings. Note that deleting your Supabase session storage (the sb-*-auth-token key) will sign you out of the platform.
How to clear cookies and storage in your browser
- Chrome: Settings → Privacy and security → Delete browsing data → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data → Clear Data
- Safari: Preferences → Privacy → Manage Website Data → Remove All
- Edge: Settings → Privacy, search, and services → Clear browsing data → Cookies and other site data
Inspecting individual localStorage keys
To view or delete individual localStorage entries, open your browser's developer tools (F12 in most browsers), navigate to Application → Local Storage → a22team.com, and delete any key you wish to remove.
For more general information about cookies and how to manage them, visit allaboutcookies.org.
8. Third-Party Cookies
The only third-party cookies that may appear in your browser while using A22 are:
- Cloudflare Turnstile: as described in section 4, set by Cloudflare only during account registration and password reset flows;
- PayPal: set within the PayPal checkout iframe when you initiate a payment. These are governed by PayPal's Privacy Statement. A22 does not access or control these cookies.
Neither of these third-party cookies is used by A22 for advertising, profiling, or cross-site tracking. Their use is strictly limited to the security and payment functions described above.
9. Changes to This Policy
We may update this Cookie Policy from time to time. We will notify you of material changes by email and by updating the effective date and version number at the top of this page. The most current version is always available at a22team.com/legal/cookies.
Your continued use of the platform after any change constitutes your acknowledgement of the updated policy.
10. Contact
For questions about this Cookie Policy or our use of browser storage, contact us at:
A22 (Data Controller)
info@a22team.com
a22team.com
For broader privacy questions, see our Privacy Policy. We aim to respond to all enquiries within 30 days.