1. Our principle
A cookie is a small file placed on your device by the website you visit. The Belgian Act of 13 June 2005 on electronic communications and the GDPR require your prior consent, except for cookies strictly necessary to provide the service you have asked for.
We use two categories, and only one is put to you. Necessary cookies make the site work: they keep your session open and remember your language and theme. They are set without your agreement, as the law allows, and the site does not work without them.
Advertising measurement cookies exist so we can tell which ads bring in customers. They remember where your visit came from, and that information is passed to Meta, TikTok and Google so we know what our campaigns produce. None of this is stored or sent until you have clicked “Accept”.
Declining takes nothing away: the site, the free tools and your account work exactly the same. You can change your mind at any time by deleting the `wobelio-consentement` cookie from your browser settings, and the banner will come back.
2. Cookies set
- authjs.session-token
- Keeps your session open after sign-in, so a code is not asked for on every page. Lifetime: 30 days. Necessary.
- authjs.csrf-token
- Protects forms against requests forged from another website. Lifetime: the browser session. Necessary.
- authjs.callback-url
- Remembers the page to reopen after signing in. Lifetime: the browser session. Necessary.
- wobelio-langue
- Remembers the language you chose, so it is not asked for on every visit. Lifetime: 1 year. Necessary for the service requested.
- wobelio-theme
- Remembers the light or dark theme and lets the server apply it from the very first paint. Lifetime: 1 year. Necessary for the service requested.
- wobelio-consentement
- Remembers your answer to the banner, so the question is not asked again on every page. Set whether you accept or decline. Lifetime: 6 months. Necessary.
- wobelio-origine
- Remembers which advertising campaign your visit came from, so we can measure what our ads produce. Signed, and unreadable from page scripts. Lifetime: 30 days. Set ONLY after your agreement.
- _fbp, _fbc
- Set by the Meta pixel (Facebook, Instagram) to tie your visit to the ad that brought you. Lifetime: 3 months. Set ONLY after your agreement.
- _ttp
- Set by the TikTok pixel, for the same purpose. Lifetime: 13 months. Set ONLY after your agreement.
- _ga, _gcl_au
- Set by the Google Ads tag, for the same purpose. Lifetime: 3 months to 2 years. Set ONLY after your agreement.
Session cookies are issued with the `HttpOnly`, `Secure` and `SameSite` attributes, which make them unreachable from page scripts and prevent them from being sent from another website.
3. What is sent to the ad networks
If you accept measurement, we tell Meta, TikTok and Google which steps you complete with us: creating an account, publishing a site, taking out a subscription. That is what lets them tell us which ads bring in customers rather than mere visitors.
Your email address is NEVER sent to them in the clear. It leaves as a SHA-256 fingerprint, which they can only match against an account they already know. We send neither your name, nor your address, nor the contents of your site.
These three companies are established in the United States. The transfer relies on the European Commission’s standard contractual clauses and on their certification under the EU–US Data Privacy Framework. If you decline measurement, nothing is sent to them, neither about you nor about your visit.
4. Local storage
Your browser also keeps, in its local storage, the theme you chose (key `wobelio-theme`) and the draft of the website being created as long as you have no account. That information never leaves your device and is never sent to us.
It is removed by clearing your browsing data, with no consequence other than losing an unsaved draft.
5. Cookies on published websites
This policy covers the platform itself. A website built with Wobelio may set other cookies, in particular where its owner enables audience measurement such as Google Analytics.
In that case, the website owner is answerable for them: it is for that owner to obtain visitors' prior consent, to leave them a way of withdrawing it, and to describe it in their own legal notice. The legal page templates provided by the platform set out that obligation.
6. Managing cookies
You may at any time inspect, block or delete cookies already set, from your browser settings, usually under "Privacy and security".
As the cookies described above are necessary, blocking them has direct consequences: sign-in can no longer be maintained, forms are rejected by the protection against forged requests, and language and theme fall back to their default on every visit. Public pages remain readable.
7. Questions and updates
This policy is updated whenever a cookie is added or removed. Should a non-necessary cookie ever be used, a prior consent mechanism would be put in place before anything is set.
For any question: info@espero-soft.com. The processing of personal data is described in the privacy policy.