Cookie policy

Last updated 24 July 2026

This policy covers both yellowdesk.ai (the website) and app.yellowdesk.ai (the application), operated by Taliro Global Talent, S.L.

We use no advertising cookies, no tracking pixels and no cross-site profiling. Most of what is listed below is either required to make the service work or is a preference you set yourself, and under Article 22.2 of Spanish Law 34/2002 (LSSI-CE) and the Article 5(3) ePrivacy rule it implements, those do not require consent. Analytics is the exception, it is described in full in section 2, and it is the only thing on this page we ask about.

1. What a cookie is

A cookie is a small file a website stores in your browser. Some are essential to sign you in and keep you signed in. Others remember a choice you made. Others track you, and we do not use those.

The same rules apply to anything else stored on your device, such as local storage.

2. The website: yellowdesk.ai

The website sets no cookies of its own. It stores two things on your device: a local storage entry named yellowdesk.lang, holding the language you chose from the switcher, so the site opens in that language next time; and yd_consent, holding your answer to the analytics question below, so we stop asking. Both hold a single short value, neither is sent to any server, and clearing your browser storage removes them.

Analytics

Analytics is provided by Google Analytics 4, a service of Google Ireland Limited. Unlike the cookieless tool we used previously, Google Analytics does set cookies and does assign your browser an identifier. We therefore ask before it is allowed to do so.

Nothing is stored on your device until you accept. The tag is loaded on every page, but it starts with storage consent denied: until you press Accept it sets no cookie, assigns no identifier, and sends only a cookieless signal that a page was viewed. If you decline, it stays that way, and no part of the site is withheld from you.

If you accept, these are set:

NamePurposeLifetime
_gaDistinguishes one browser from another, so a returning visit is not counted as a new one2 years
_ga_236H0BXHE0Holds the state of the current visit2 years

What we look at is which pages are read, which buttons are pressed, which language the site is being read in, and how many people book a demo or start a sign-up. We do not use Google Analytics for advertising: advertising storage, ad personalisation and ad user data are all set to denied and are never turned on.

You can change your mind at any time by clearing this site's storage in your browser, which removes your recorded answer and brings the question back.

Google is established in the United States, so accepting means data may be transferred there. Google relies on the European Commission's standard contractual clauses for those transfers. Google's own privacy policy governs what it does with the data as a controller.

The demo booking page

The /demo page embeds a scheduling widget provided by Zeeg. The widget loads a script from Zeeg and draws the booking calendar inside a frame served by zeeg.me.

It sets no cookie on `yellowdesk.ai`. We checked the page as a visitor sees it: no cookie is stored for this site and nothing in the page asks your browser to store one. Anything Zeeg stores to run the calendar is stored against zeeg.me, not against us, and we cannot read it.

Zeeg's own privacy policy governs what it does with a booking you make.

3. The application: app.yellowdesk.ai

3.1 Strictly necessary

NamePurposeLifetimeAttributes
yellowdesk_sessionKeeps you signed in. Contains a random token, not your identity. The server holds the record it points at, which is why we can revoke a session and you can sign out everywhere.30 days, absoluteHttpOnly, Secure, SameSite=Lax

Without this cookie you cannot sign in. It carries no personal data itself: the token is meaningless to anyone who does not hold the corresponding database row, and we store only a hash of it.

3.2 Preferences you set

These are set when you save your preferences in Settings, and they exist so the pages you load before we have read your account render in the right language and format.

NamePurposeLifetime
localeThe language you chose1 year
countryThe country you chose, which seeds the formats below1 year
dateFormatHow dates are shown to you1 year
timeFormat12 or 24 hour clock1 year

The same values are stored on your user record, because e-mails have no browser to read a cookie from.

The language cookie is also set when you arrive with a ?lang= parameter, for example app.yellowdesk.ai/signup?lang=es. That is a preference you expressed by following that link.

3.3 Payments

The billing payment page loads Stripe.js, which is required to take a card securely and to keep card details away from our servers. Stripe sets its own cookies for fraud prevention:

NameSet byPurposeLifetime
__stripe_midStripeFraud prevention. Identifies the browser across payment attemptsAbout 1 year
__stripe_sidStripeFraud prevention, within a single payment sessionAbout 30 minutes

These load only on the payment page, and only when you go there. They are necessary to process a payment and to prevent fraud. Stripe's own privacy policy and cookie policy govern them.

3.4 What we do not use

No advertising cookies. No social media pixels. No cross-site tracking. No fingerprinting. No session recording or replay. No third-party analytics cookie of any kind.

4. Product analytics, and the commitment that goes with it

The application records product usage events in our own database: which features are used, how often, and whether a flow was completed. This is how we find out where the product fails the people paying for it. It sets no cookie and it is not third-party. It is tied to your account, not to a browser identifier, and it is described in Part B of the Privacy Policy.

The application also contains an unused integration with PostHog, a third-party product analytics service. It is switched off. No data is sent to PostHog and no PostHog cookie is set.

The commitment, and it is binding on us internally:

Neither PostHog, nor any other non-essential analytics or marketing technology, will be enabled on either property until a compliant consent mechanism is live: consent obtained before the technology loads, refusal as easy as acceptance, a record of what was consented to, and a way to withdraw it. Until then it stays off.

This is written here rather than only in an internal policy because it is a promise to the reader, and because switching it on is a single configuration change that someone could otherwise make without realising it puts us in breach of Article 22.2 LSSI-CE.

5. Controlling cookies yourself

Your browser can block or delete cookies. Every major browser has this in its privacy settings, and they all offer a way to see exactly what a site has stored.

If you block the session cookie you cannot sign in. If you block the preference cookies, the application will fall back to the language and formats on your account, or to the defaults, on each page load.

We do not respond to Do Not Track signals, because we do not track you to begin with.

6. Changes

We update this policy when what we store changes. The date at the top is the date of the version you are reading. Where a change means we start using a technology that requires consent, we will ask for it before we start, not afterwards.

7. Contact

privacy@taliro.net

Language

This document is published in English, German, French, Dutch and Spanish. The translations are provided for convenience. Where a translation and the English version differ, the English version governs.