Version 1
Cookie & Tracking Technologies Policy
Effective date: the date shown in your member account, onboarding flow, or checkout confirmation.
Operator: Jaybird Sim Center (“Jaybird,” “we,” “us,” “our”), operating at 2550 N Thunderbird Cir #132, Mesa, Arizona 85215 and any successor or additional locations.
You (“Visitor,” “Member,” “you,” “your”): any person who visits jaybirdsims.com, the Jaybird member portal, or any other Jaybird web property.
This Policy explains the cookies and similar technologies Jaybird uses, what each one does, who sets it, how long it lasts, and how you can control it. It supplements the Privacy Policy, which governs everything we do with personal information, and it should be read alongside the Terms of Service and the Electronic Communications & E-Sign Consent. It describes only technologies that are actually in use on our properties, plus a forward-looking description of the categories we may add.
1. What these technologies are
Cookies are small text files a website stores in your browser and reads back on later requests. A first-party cookie is set by the domain you are visiting; a third-party cookie is set by another domain whose code the page loads.
Session cookies are erased when you close your browser. Persistent cookies survive until they expire or you delete them.
We also use, or may use, the following non-cookie technologies:
- Local storage and session storage — browser key-value stores that hold small amounts of data on your device and, unlike cookies, are not automatically sent to a server with every request.
- Pixels and web beacons — a tiny transparent image or a script whose loading tells a server that a page or email was opened.
- Software development kits (SDKs) loaded into the page, such as our error-monitoring library.
- Server-side event forwarding, where our server rather than your browser reports a conversion to an advertising platform.
Throughout this Policy, “cookies” is shorthand for all of these unless we say otherwise.
2. Cookie categories
| Category | What it does | Can you refuse it? | Who sets it |
|---|---|---|---|
| Strictly necessary | Signs you in, keeps you signed in, protects against cross-site request forgery, balances and routes traffic, remembers your cookie choices | No — the site cannot function without these, and we set them on the basis of legitimate interests rather than consent | Jaybird (first party) and Supabase and Vercel acting for us |
| Functional | Remembers preferences and interface state so you are not asked the same thing twice — a dismissed banner, a selected instructor filter, a saved café cart, a booking preference | Yes — blocking them degrades convenience but not access | Jaybird (first party) |
| Performance and error monitoring | Detects, records, and helps us reproduce crashes and broken pages | Yes | Sentry |
| Analytics | Counts page views, measures which pages and flows are used, and shows where people drop out | Yes | Google (where enabled) |
| Advertising and conversion measurement | Attributes a lead, checkout, or membership purchase back to the ad that produced it, and measures campaign performance | Yes | Google and Meta (where enabled) |
3. The cookies and storage we actually use
3.1 Strictly necessary — authentication and session
Authentication is operated by Supabase Auth on our behalf. When you sign in, Supabase sets first-party cookies on the Jaybird domain that carry your session and refresh tokens. These are typically named beginning sb- and ending -auth-token, and a long token may be split across several numbered cookies.
| Purpose | Set by | Type | Typical lifetime |
|---|---|---|---|
| Holds your signed-in session so every page load knows who you are | Supabase, first party on the Jaybird domain | Persistent | Until sign-out, session expiry, or token rotation; generally up to one year unless revoked earlier |
| Refreshes an expiring session without making you sign in again | Supabase, first party | Persistent | Same as above |
| Protects form submissions and server actions against cross-site request forgery | Jaybird and the application framework, first party | Session | Until the browser closes |
If you block these cookies you cannot sign in, cannot stay signed in, cannot book, and cannot complete onboarding or compliance. There is no version of the member portal that works without them.
3.2 Strictly necessary — hosting, routing, and protection
Our application is hosted by Vercel. Vercel may set first-party cookies on the Jaybird domain for request routing, load distribution, deployment protection on non-production preview environments, and platform security. These are operational, contain no marketing data, and are not used to profile you. Most are session-scoped or short-lived.
3.3 Functional — preferences and interface state
Jaybird stores a small amount of interface state in your browser’s local storage and session storage rather than in cookies. Examples of what is stored:
- Whether you have already dismissed a promotional dialog or a one-time prompt, so we do not show it again
- Booking preferences such as a previously chosen instructor, resource, or view
- The contents of an in-progress café cart before checkout
- Navigation and workspace layout state, such as an expanded or collapsed panel
- A per-session flag used to make sure a single conversion event is not reported twice
This data stays on your device, is not sent to us automatically with each request, and contains no identity documents, payment data, or compliance information. Clearing site data in your browser removes all of it.
3.4 Performance and error monitoring — Sentry
We use Sentry to detect and diagnose errors. The Sentry SDK runs in your browser and on our servers, and reports:
- The error, its stack trace, and the code path that produced it
- Breadcrumbs — a short trail of what happened immediately before the error, such as which page you were on and which control you activated
- Your browser, operating system, and IP address
- Console messages logged at error and warning level
- A session replay of the affected page, recorded only when an error occurs. Ordinary browsing is not recorded: the sample rate for error-free sessions is set to zero, so no replay is captured unless something breaks.
Sentry does not set advertising cookies. Its session-replay feature keeps a replay session identifier in your browser’s session storage. Replays capture page structure and interaction, and are used solely to reproduce and fix the defect. Data is retained per Sentry’s configured retention, typically 90 days.
3.5 Analytics and advertising — Google
Where a Google Ads identifier or Google Analytics 4 measurement identifier is configured for the site, we load Google’s global site tag (gtag.js) from googletagmanager.com. It sets third-party and first-party cookies commonly named _ga, _ga_ followed by a container identifier, and _gcl_au.
What we report through it:
- Page views, on navigation
- `generate_lead` when a contact form is successfully submitted
- `begin_checkout` when you start a Stripe checkout
- `purchase` when a purchase or membership subscription completes, with the transaction identifier, value, and currency
We do not send identity documents, compliance status, health disclosures, or photographs to Google. Where a lead conversion is reported and you supplied an email address, that address may be passed to Google’s user-data parameter for conversion matching. Google’s cookies typically last up to two years for _ga and up to 90 days for _gcl_au. Google’s own privacy terms govern what it does with the data as an independent controller for its own purposes.
If no Google identifier is configured for the deployment you are visiting, none of these tags load and none of these cookies are set.
3.6 Advertising, pixels, and lead ads — Meta / Instagram
Where a Meta Pixel identifier is configured, we load the Meta Pixel from connect.facebook.net. It sets cookies commonly named _fbp (first party) and, when you arrive from a Meta ad, records the click identifier fbclid which may be stored as _fbc. We also include a noscript fallback: a 1×1 transparent tracking pixel served from facebook.com/tr that fires when JavaScript is unavailable.
Events reported through the Pixel are limited to PageView, ViewContent, Lead, InitiateCheckout, and Purchase.
We additionally use the Meta Conversions API, which sends the same conversion events from our server rather than from your browser, with a shared event identifier so a single action is not counted twice. Where an email address or phone number is included for matching, it is hashed before transmission — Meta receives the hash, not the plain value.
Lead ads. If you complete a lead form inside Instagram or Facebook, Meta collects the information you typed into that form and passes it to us so we can follow up. That collection happens on Meta’s platform under Meta’s own privacy terms before it ever reaches us; once it reaches us, our Privacy Policy governs it. _fbp typically lasts 90 days.
If no Meta Pixel identifier is configured for the deployment you are visiting, the Pixel and its `noscript` image do not load and no Meta cookie is set.
3.7 Email tracking
Transactional and marketing email is delivered by Resend. Delivery, bounce, and complaint status is reported back to us by the mail provider. Marketing email may contain a tracking pixel or wrapped links that tell us the message was opened or a link was clicked, so we can measure whether a campaign worked and stop sending to addresses that never engage. Disabling remote image loading in your email client prevents open tracking. Every marketing email contains a working unsubscribe link.
3.8 Scheduling, payments, and door access
Stripe, Google Calendar, and Seam are used to take payment, sync scheduling, and control door access. Stripe sets its own cookies on the Stripe-hosted checkout pages you are redirected to, including cookies used for fraud detection, and Stripe’s privacy terms govern those pages. Google Calendar and Seam operate server-to-server and do not set cookies in your browser through our site.
4. Technologies we do not use
For the avoidance of doubt, as of the effective date of this Policy:
- We do not use cookies to perform facial recognition, biometric matching, or any biometric processing.
- We do not sell personal information collected through cookies, and we do not share it for cross-context behavioural advertising as those terms are defined by U.S. state privacy law.
- We do not operate cross-device advertising graphs, data-broker enrichment, or fingerprinting scripts.
- We do not record ordinary, error-free browsing sessions. Session replay is triggered only by an error.
- We do not place advertising or analytics cookies inside the authenticated member portal beyond the conversion events described in Sections 3.5 and 3.6.
Forward-looking categories. If we later add a technology in a category described in Section 2 — for example a product-analytics platform, a heatmap tool, a chat widget, or a consent-management platform — we will update the tables in this Policy before or at the time it goes live, and, where the law requires consent, we will obtain it first.
5. How to control cookies
5.1 Browser controls
Every major browser lets you view, block, and delete cookies, and clear local and session storage. The relevant setting is usually under Settings → Privacy and security. You can typically:
- Block all third-party cookies, which stops the Google and Meta tags from setting theirs
- Block all cookies, which will prevent you from signing in to the member portal
- Delete cookies and site data for jaybirdsims.com specifically
- Use a private or incognito window, which discards cookies and storage when the window closes
Because cookie settings are stored per browser and per device, you will need to repeat your choices on each browser and device you use.
5.2 Platform opt-outs
- Google Analytics: install the Google Analytics Opt-out Browser Add-on, or manage ad personalisation in your Google account settings.
- Meta: manage ad preferences and off-Facebook activity in your Facebook or Instagram account settings.
- Industry opt-outs: the Digital Advertising Alliance, the Network Advertising Initiative, and the European Interactive Digital Advertising Alliance each operate an opt-out page covering participating advertising vendors.
An opt-out is itself usually recorded as a cookie, so clearing your cookies may clear your opt-out.
5.3 Global Privacy Control
We honour the Global Privacy Control (GPC) signal. If your browser or extension sends a GPC header, we treat it as a valid request to opt out of any sale or sharing of personal information for cross-context behavioural advertising, and we will not treat you as having consented to advertising or analytics technologies. Because we do not sell or share personal information for cross-context behavioural advertising in the first place, a GPC signal does not change how your data is handled by Jaybird — but it is respected, and it is respected without requiring you to identify yourself.
5.4 Do Not Track
There is no industry consensus on how a Do Not Track (DNT) browser header should be interpreted, and no accepted technical standard for responding to one. Jaybird therefore does not respond to DNT headers. We do respond to Global Privacy Control, as described above.
5.5 Consequence of blocking strictly-necessary cookies
If you block the cookies in Sections 3.1 and 3.2, the following stops working:
- Signing in, and staying signed in
- The member portal, bookings, onboarding, and compliance uploads
- Checkout, because you cannot be identified when you return from Stripe
- Form submissions that rely on cross-site request forgery protection
We cannot provide a members-only service to a browser that will not hold a session. If you cannot or will not accept these cookies, you can still browse the public marketing pages, and you can contact us at support@jaybirdsims.com to arrange anything you need to do in person or by phone.
5.6 Consent management
Jaybird does not currently display a cookie consent banner. Analytics and advertising tags load only where the corresponding identifier is configured for the deployment, and we rely on the browser and platform controls above together with the Global Privacy Control signal. If we introduce a consent-management banner, this Policy will be updated and the banner will govern from the date it appears. Visitors covered by the GDPR or UK GDPR may withhold or withdraw consent for non-essential technologies at any time by writing to privacy@jaybirdsims.com, and we will suppress those tags for that visitor.
6. Retention
| Technology | Typical lifetime |
|---|---|
| Supabase authentication and refresh cookies | Until sign-out, revocation, or expiry; generally up to one year |
| Framework and anti-forgery session cookies | Until the browser closes |
| Vercel hosting and routing cookies | Session, or short-lived per platform configuration |
| Local storage preferences | Until you clear site data |
| Session storage flags | Until the browser tab closes |
| Sentry error data and error-triggered session replay | Per Sentry retention, typically 90 days |
Google _ga and _ga_ container cookies | Up to 2 years |
Google _gcl_au conversion linker cookie | Up to 90 days |
Meta _fbp browser identifier | Up to 90 days |
| Email open and click records | 3 years after last contact, or life of account for members |
Server-side records derived from these technologies are retained on the schedule in Section 17 of the Privacy Policy.
7. Your rights
Data collected through cookies is personal information and is covered by Section 13 of the Privacy Policy. You may request access, correction, deletion, and portability, and you may opt out of marketing, by emailing privacy@jaybirdsims.com. The legal-retention exception explained in Section 13.5 of the Privacy Policy applies to compliance records only and does not apply to cookie data, which we delete on request.
8. Third-party sites
Our site links to third parties — Stripe’s checkout pages, Google Calendar, social profiles, and partner flight schools. Once you leave our domain, that party’s cookies and privacy terms apply, not ours. We do not control and are not responsible for their technologies. Review their notices before providing information.
9. Governing law
This Policy is governed by the laws of the State of Arizona, without regard to conflict-of-law rules, with exclusive jurisdiction and venue in the state and federal courts of Maricopa County, Arizona. Nothing here limits any non-waivable right you hold under the privacy law of your own state or country.
10. Changes to this document
We may update this Policy when we add, remove, or reconfigure a tracking technology, or when the law changes. The revised version takes effect on the date shown in your member account or on the posted document, and material changes will be announced by email or portal notice. Continued use of the site after the effective date constitutes acceptance, except where applicable law requires consent. Prior versions are available on request.
11. Contact
Cookie and privacy questions, and requests to suppress non-essential technologies: privacy@jaybirdsims.com
General support: support@jaybirdsims.com
Post: Jaybird Sim Center, Attn: Privacy Request, 2550 N Thunderbird Cir #132, Mesa, Arizona 85215
Questions: support@jaybirdsims.com
Published text mirrors the active rows in agreement_templates (versioned). Signed snapshots are stored in signed_agreements at onboarding and checkout events. Have Arizona counsel review before treating any clause as final advice.