Legal
Cookie policy
Winglark sets only the cookies it needs to work. Visits to the public pages are measured only if you say yes — and even then without cookies and without identifying anybody.
Your choice
The first time you open the public site, a panel asks one question: may Winglark measure this visit? “Accept all” turns measurement on, “Necessary only” leaves it off, and “Manage preferences” shows the same choice with the details written out. Until you answer, nothing optional runs.
Your answer is kept in a cookie, winglark_consent, for six months; after that the question is asked again. It holds the version of the question, your answer and the day you gave it — no identifier.
You can change your answer at any time with “Cookie preferences” in the footer of every public page. Switching measurement off stops it immediately and removes the two session-storage notes described below.
If your browser sends Global Privacy Control or Do Not Track, the question is not asked, because the browser has already answered: nothing is measured, whatever is selected in the preferences.
Necessary: what Winglark always stores
winglark_session keeps you signed in. It holds an identifier for your session and nothing else — no name, no email, no tracking value. It is removed when you sign out.
winglark_locale remembers the language you chose, for one year, so the site does not switch back on your next visit. When the site suggests your browser’s language and you answer, local storage (winglark_locale_pref, winglark_language_prompt) notes that you answered so the suggestion is not repeated; closing the suggestion without answering is remembered for the tab only (winglark_language_prompt_closed).
winglark_consent records the answer described above.
While you sign in with Google, two short-lived cookies (winglark_oauth and winglark_access_hint) carry the sign-in from Google back to Winglark; they expire within fifteen minutes. Inside the product, winglark_client and winglark_profile_notice remember which client workspace you are working in and whether you dismissed a notice.
These are needed for the site and the product to work, or record a choice you made yourself, which is why they are not switched off by the consent panel.
Analytics: measuring visits to the public pages
Only if you have said yes. Winglark then counts how its public pages are used — which pages are read, where visitors came from, which buttons are used — with PostHog, hosted in the United States. Until you say yes the PostHog script is not loaded and nothing is sent.
It runs without cookies and without storing anything of its own in your browser. Visitors are counted with a hash PostHog computes on its servers from the request and a random value that changes every day, so the same visitor on two different days is not recognised as the same person. No profile is built, nothing is linked to an account, and your IP address is not kept.
The country and region of a visit are taken from what the network already knows about the request, before anything is sent; the address itself is never stored, and no city is recorded.
There is no session recording and no heatmap. Signed-in pages, and invitation, activation and reply pages, are never measured.
Not decidedLegal review: the transfer of visit data to PostHog in the United States (EU–US Data Privacy Framework, KVKK cross-border rules), the PostHog data processing agreement, and whether the consent wording meets the explicit-consent standard of every market Winglark serves.
Analytics: where your visit started
Also only if you have said yes. Your browser’s session storage then keeps where the visit started — the campaign, the referring site and the first page (winglark_attribution) — and the page you came from (winglark_trail). If you ask for access, the form sends them with your request, so the team can see how you found Winglark.
They hold no identifier, are deleted when you close the tab or switch analytics off, and are sent nowhere else. Without them, a request for access records only what the request page itself knows: the address it was opened with and the page that linked to it.
What Winglark does not use
No advertising or marketing cookies. No third-party pixels, tag managers or session recorders. No heatmaps. No cross-site tracking of any kind. The preferences therefore have no “marketing” switch: there is nothing for it to control.
Anything added later that needs your permission will be added to the preferences, and you will be asked again.
Two flags exist for the Winglark team’s own browsers: visiting a public page with ?wl_analytics=exclude stores winglark_analytics_exclude in local storage and keeps that browser out of the measurement for good, and ?wl_analytics=qa marks a tab’s visits as test traffic. Neither is set for anybody who does not type that address.
Fonts and assets
The two typefaces are served from Winglark’s own domain rather than from a font CDN, so loading a page does not tell a third party that you visited.
Questions about any of this go to the contact page.