Cookie Policy
Last updated: July 2026
This policy explains what saastro.io stores on your device — cookies and similar browser storage — and how you control it. It describes what this site actually does today, not what it might do in the future: where a feature is present in the code but inactive, this policy says so.
What are cookies?
Cookies are small text files a website asks your browser to store on your device. “Local storage” is a related browser mechanism that keeps data on your device without sending it back to the server with every request. Both are covered here.
Cookies this site sets
One. Only one cookie is set by this site, and only after you interact with the cookie banner:
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
cookie_consent |
Stores your own cookie choices (essential / analytics / personalization) plus the timestamp of the choice, so the banner stops asking. | 1 year | First-party, essential |
It is a first-party cookie, flagged SameSite=Lax and Secure. It contains only
your preferences and a timestamp — no identifier, no tracking value, nothing about
who you are. If you never answer the banner, this cookie is never written.
Essential cookies do not require consent, because without them the choice you made could not be remembered.
Analytics cookies
None are set at the moment. This site ships with support for Google Analytics, Google Tag Manager and Cloudflare Web Analytics, but all three are unconfigured (no measurement IDs and no beacon token are set), so none of these scripts are loaded and no analytics cookies are written.
If analytics are ever enabled, the loader is consent-gated: the script is injected only after you accept the “Analytics” category, and turning the toggle off stops it from loading. This policy will be updated with the specific provider, cookies and retention before any of that goes live.
Personalization cookies
The banner offers a “Personalization” toggle. Today, no code reads that
setting — it is recorded inside cookie_consent and currently controls nothing.
It is kept in place for planned features. Nothing is stored or shared on the basis
of this toggle at present.
Local storage (not a cookie)
If you use the light/dark theme switch, your choice is saved in your browser’s
local storage under the key theme, so the site does not flash the wrong theme on
your next visit. This is set only when you actively change the theme, it stays on
your device, and it is never transmitted to us or to anyone else.
Cookies set by our hosting provider
None. This site is served by Cloudflare, and Cloudflare’s features that would
set infrastructure cookies are switched off on this domain: Bot Fight Mode
(which sets __cf_bm) and the WAF’s security challenges (which set
cf_clearance) are both disabled. Those cookies are only ever written when the
corresponding feature is active, so none of them reaches your device here.
If any of those protections is enabled in the future, this policy will be updated to list the cookie it sets and its duration before that happens.
Third parties that receive data when a page loads
No cookie is involved here, but you should know about it: opening any page on
this site makes your browser fetch the site’s typefaces from Google Fonts
(fonts.googleapis.com and fonts.gstatic.com). This is a deliberate decision
by the site owner — the site does not self-host its typefaces and will keep
loading them from Google.
Because your browser has to ask Google’s servers for those files, this discloses your IP address to Google, along with the technical data inherent to any request (user agent and the page making it). It happens automatically on every visit and before you interact with the cookie banner, because the typeface is needed to render the page. That is its only purpose: to download and render the site’s typeface. Google sets no cookies through this, and it is not used to measure you or build a profile — but it is a disclosure of data to a third party. Google processes that data under its Privacy Policy.
The legal basis for this disclosure is our legitimate interest in serving the site’s typefaces from Google’s network (Art. 6(1)(f) GDPR). Because Google is established in the United States, it also involves an international transfer: Google is certified under the EU-U.S. Data Privacy Framework, covered by the European Commission’s adequacy decision of July 2023. See the Privacy Policy.
Managing your preferences
You can change your choice at any time using the Manage cookies button in the
site footer, which reopens the banner. You can also delete cookies and local
storage directly in your browser settings — every major browser lets you block or
remove them per site. Removing cookie_consent simply makes the banner ask again.
Because the only cookie this site sets is the one that remembers your choice, rejecting everything leaves the site fully functional.
Changes to this policy
If this site starts using cookies beyond the one described above, this policy will be updated before that happens, and the banner will ask for consent where consent is required.
Contact
For questions about this policy, see the contact details in our Privacy Policy.