🔥 Lite Plan for just €19.00/month! 🔥

Cookie Policy and tracking tools

Which cookies and similar tools we use on the supportfast.ai and app.supportfast.ai websites, what they are for, how to manage them and how to withdraw consent at any time.

Version: 2.3 | Effective from: 19/05/2026 | References: Regulation (EU) 2016/679 · Legislative Decree 196/2003 · Italian DPA Order of 10/06/2021
 
Managing your preferences. You may modify or withdraw your consent to non-technical cookies at any time, without affecting the lawfulness of the processing already carried out. Use the “Modify cookie preferences” link at the bottom of each page of the website.

This Cookie Policy describes the cookies and similar tracking tools (web beacons, pixels, device identifiers, local storage) used by Stepcode SRL on the supportfast.ai and app.supportfast.ai websites. It is drafted pursuant to Article 122 of Legislative Decree 196/2003 (Italian Privacy Code) and the Order of the Italian Data Protection Authority of 10 June 2021 on cookies.

This document supplements the Privacy Policy and should be read together with it for the complete picture of processing activities.

1.What cookies and similar tools are

Cookies are small text files that visited websites save on the user’s device to store information useful for their operation, preferences, or for statistical and marketing purposes. They may be set by the website visited (first-party cookies) or by third-party domains through integrated content (third-party cookies).

Tools similar to cookies

In addition to traditional cookies, technologically different tools that perform similar functions may be used on our websites. The rules on consent also apply to such tools.

  • Local Storage and Session Storage: browser storage spaces used to save preferences and session state.
  • Pixels and web beacons: transparent images used to record the opening of a page or an e-mail.
  • Device identifiers: unique strings associated with the browser or device.
  • Fingerprinting: recognition technique based on the combination of device characteristics. Stepcode does not use fingerprinting.

When this document refers generically to “cookies”, the term shall be understood as also referring to the similar tools listed above, unless otherwise specified.

2.Data Controller

The Data Controller for data collected through cookies is Stepcode SRL, with registered office at Via Valpolicella 238, 37015 Sant’Ambrogio di Valpolicella (VR), Italy, VAT IT05205700239.

For any request relating to cookies or to exercise the rights provided by the GDPR, you may write to [email protected].

3.Categories of cookies used

According to the Italian DPA Guidelines of 10 June 2021, cookies are divided into three categories that require different treatment in terms of consent.

  • Strictly necessary cookies (Cat. 1): necessary for the operation of the website or for the provision of a service explicitly requested by the user. No prior consent required.
  • Analytics cookies (Cat. 2): used to collect statistics on the use of the website. Require prior consent, except in cases of anonymisation and exclusive control by the data controller.
  • Profiling and marketing cookies (Cat. 3): used to track the user in order to build profiles and display targeted advertising. Always require prior, free, specific and informed consent.
On our websites, Category 2 and 3 cookies are activated only after the user’s explicit consent, expressed through the consent banner (CMP) that appears on first access. Until consent is given, only the strictly necessary cookies of Category 1 are activated.

4.Strictly necessary cookies

Strictly necessary cookies are required for the correct operation of the website and the console and for the provision of the service requested by the user. Pursuant to Article 122 of Legislative Decree 196/2003, the use of these cookies does not require prior consent.

On the supportfast.ai and app.supportfast.ai websites there are strictly necessary cookies for the operation of the service (user session management, authentication in the console, protection against CSRF attacks, storage of language and theme preferences, storage of the choices expressed by the user on the consent banner). These cookies are first-party, have a duration limited to the session or to strictly necessary periods, and are not used for profiling or marketing purposes.

5.Analytics cookies

Analytics cookies are used to collect aggregated information on the number of visitors, the most viewed pages and browsing behaviour, in order to improve the website and content. They require the user’s prior consent and are activated only after such consent has been obtained through the banner.

5.1 Google Analytics 4 and Google Tag Manager

Third party: Google Ireland Ltd. privacy policy.

Statistical analysis service provided by Google, integrated through Google Tag Manager. GTM does not directly set profiling cookies, but manages the loading of other tags. For Google Analytics 4, anonymisation of the IP address is configured.

NamePurposeDuration
_gaDistinguishes unique users by assigning a random identifier2 years
_ga_<ID>Persists the GA4 session state for the specific container2 years
_gidDistinguishes users for 24 hours (if active)24 hours
_gatLimits the frequency of requests to Google’s server1 minute

5.2 PostHog

PostHog Inc., EU region (Frankfurt). privacy policy.

Product analytics tool used both on the showcase website supportfast.ai and within the console app.supportfast.ai. It collects usage events (clicks, navigation, features used) to analyse the aggregated behaviour of users, improve the product and identify usability issues. Configured on the EU region: data remains within the European territory. Data is processed in pseudonymised form and the IP is truncated. For users authenticated in the console, PostHog acts as external Data Processor of Stepcode (see sub-processors page).

NamePurposeDuration
ph_<projectKey>_posthogPostHog device identifier for event tracking1 year
ph_current_project_tokenToken of the PostHog project in use1 year

5.3 Microsoft Clarity

Microsoft Ireland Operations Ltd. privacy policy.

Behavioural analysis tool provided by Microsoft, used both on the showcase website and within the console. It records heatmaps and anonymised sessions (with automatic masking of sensitive content) to improve usability. For users authenticated in the console, Microsoft acts as external Data Processor of Stepcode (see sub-processors page).

NamePurposeDuration
_clckPersists the user’s Clarity ID1 year
_clskLinks multiple page views into a single session1 day
CLIDClarity identifier1 year
MUIDIdentifies unique users across Microsoft1 year
SMMUID synchronisation between Microsoft domainsSession

6.Marketing and profiling cookies

Marketing cookies track the user’s activity on our website and other websites to build a profile and display relevant advertisements. They always require the user’s prior, free, specific and informed consent.

6.1 Meta Pixel (Facebook)

Meta Platforms Ireland Ltd. privacy policy.

Tracking pixel provided by Meta that allows measuring the effectiveness of advertising campaigns on Facebook and Instagram and building custom audiences for retargeting.

NamePurposeDuration
_fbpIdentifies the browser to deliver advertising on Facebook3 months
_fbcStores the last click that led to the website2 years
frFacebook’s main cookie for advertising (facebook.com domain)3 months
trConversion tracking pixelSession

7.Cookies from embedded third-party content

The supportfast.ai website integrates third-party content and functionalities which, once loaded, may set autonomous cookies on the user’s device. Activation is subject to user consent, where required.

7.1 Stripe (checkout and payments)

Stripe Payments Europe Ltd. privacy policy.

Stripe handles payments for the service. Cookies are used for fraud prevention and to ensure the security of transactions. As this is a security functionality essential for the provision of the service requested by the user, these cookies are considered technical when the user initiates a payment.

NamePurposeDuration
__stripe_midUniquely identifies the device for fraud prevention1 year
__stripe_sidIdentifies the current payment session30 minutes

7.2 Calendly (demo booking)

Calendly LLC. privacy policy.

Booking tool used to schedule demos and meetings with the sales team. When the user opens the booking widget, cookies may be set by the provider to maintain the state of the booking.

NamePurposeDuration
_calendly_sessionPersistence of the Calendly session during the booking21 days
__Host-_calendly_sessionSession security token (secure variant)21 days

7.3 Wistia (embedded videos)

Wistia, Inc. privacy policy.

Tutorial and demonstration videos are hosted on Wistia and embedded via an embedded player. When the user starts video playback, Wistia sets cookies to store playback preferences, video quality and to generate aggregated viewing statistics.

NamePurposeDuration
wistiaStores Wistia player preferences and settings1 year
wistia-video-progress-<id>Stores the playback point of individual videos1 year

8.Analytics in the app.supportfast.ai console

Within the authenticated console, in addition to the strictly necessary cookies for operation, Microsoft Clarity and PostHog are active to analyse the aggregated use of product features by users, identify usability issues and improve the experience. The basic technical cookies of these tools are the same as those described in Section 5.

As this is use within an authenticated product area, and based on the agreements signed, Microsoft and PostHog act as external Data Processors of Stepcode pursuant to Article 28 GDPR for the processing carried out in the console. The detail is available on the sub-processors page (Section 2, Core sub-processors) and in the DPA.

PostHog is configured on the EU region (Frankfurt) to ensure that analytics data relating to the console remains within European territory.

9.Consent management

On first access to the supportfast.ai and app.supportfast.ai websites, the user is shown a consent banner that allows to:

  • Accept all cookies (technical, analytics, marketing).
  • Reject non-technical cookies with a single click, immediately visible and of equal prominence with respect to the acceptance button.
  • Customise choices per cookie category.

The banner is managed through a Consent Management Platform (CMP) compliant with the Italian DPA Guidelines of 10 June 2021.

Features of consent collection

  • Consent is free, specific and informed: no “blanket” consent or consent through scrolling.
  • Until consent is given, only strictly necessary cookies are activated.
  • If the user closes the banner without expressing a choice, this is equivalent to a rejection of non-technical cookies. The banner is not shown again for at least 6 months, except for material changes to the conditions.
  • Consent may be withdrawn at any time with the same ease with which it was given, through the “Modify preferences” link at the bottom of each page and at the top of this Cookie Policy.
  • Consent is requested again every 6 months or on the occasion of material changes.

Rejection of non-technical cookies does not affect access to the website or the enjoyment of essential services. Some accessory functionalities (embedded videos, navigation statistics, advertising retargeting) may not be available or may be reduced.

10.How to disable cookies from your browser

Regardless of the choices expressed in the banner, the user may configure the browser to accept, reject or delete cookies. Links to the official instructions of the main browsers:

For advertising cookies, behavioural advertising preferences may also be managed via the YourOnlineChoices platform (EDAA) or, for US providers, via NAI and DAA.

11.Data transfers outside the European Union

Some third-party cookies are set by providers that may process data outside the European Economic Area (EEA), mainly in the United States. Such transfers take place on the basis of appropriate safeguards under Chapter V of the GDPR:

ProviderLegal basis for transfer
Google (GA4, GTM)EU-US Data Privacy Framework (DPF) + SCC
Meta (Pixel)EU-US Data Privacy Framework (DPF) + SCC
Microsoft (Clarity)EU-US Data Privacy Framework (DPF) + SCC
PostHogEU region (Frankfurt), intra-EU transfer
CalendlyStandard Contractual Clauses (SCC)
WistiaStandard Contractual Clauses (SCC)
StripeEU headquarters (Ireland) for European customers

The DPF certification status of individual US providers can be verified on the official register dataprivacyframework.gov.

12.Data subject rights

In relation to the processing carried out through cookies, the user may exercise at any time the rights provided by Articles 15-22 GDPR: access to the data collected, rectification and erasure, restriction of processing, objection to processing, withdrawal of consent, complaint to the Italian Data Protection Authority (www.garanteprivacy.it).

To exercise these rights, write to [email protected]. For full details, please refer to the Privacy Policy, Section 12.

13.Changes to the Cookie Policy

Stepcode SRL reserves the right to update this Cookie Policy to reflect changes in the cookies used, regulatory developments or updates to the providers. The current version is always available on this page, with date and version number highlighted in the header.

In case of material changes (e.g. introduction of new cookie categories or new third-party providers), the consent banner is shown again to the user to obtain new express consent.

14.Contacts

Language. This English version is provided for convenience. In case of conflict or inconsistency, the Italian version prevails as the binding legal text, given the Italian law governing this Cookie Policy.