Easy A2P cookie policy
Policy version: 1
Your choices
Optional services stay off until you explicitly allow them. Accept all enables eligible services, Reject all keeps them off, and Customize lets you choose individual services. Closing the controls or continuing to browse does not give consent.
You can reopen Cookie settings at any time and reject previously allowed services. Withdrawal stops future use through these controls and removes accessible storage listed for removal below. It cannot retract information already transmitted or erase records held by a provider.
Global Privacy Control keeps services classified here as sale/sharing, and their dependent services, off. Accept all cannot override an active signal. Removing the signal does not restore revoked choices.
Necessary storage and requests
The first-party rl_consent cookie stores a random consent ID, service choices, scopes and timestamps on this host at /. It is available to the consent code, uses SameSite=Lax and uses Secure over HTTPS. Grants expire after 180 days; saved choices are retained for up to 180 days from your last choice. A changed processing scope can require another choice.
If your browser prevents storage, choices apply in the current page but may not be remembered on another page or visit. The controls display a warning when saving fails.
/: Deliver requested pages and first-party images, scripts and styles.
/consent-log: Record cookie choices independently of optional services.
Earlier cookie banner
easya2p.app previously used a different cookie banner, which kept your choice in this browser's local storage under easya2p_consent_v1. These controls delete that record and do not reuse it, so you are asked again. app.easya2p.app keeps its own choices separately.
easya2p.app no longer uses Page Pulse. These controls also delete the visitor and session identifiers it stored in this browser (_pp_vid, _pp_sid).
Google Analytics 4
Category: analytics. Purpose: Measure visits to easya2p.app pages after explicit permission. Page addresses keep campaign tags (utm_*) and drop every other query parameter.
Provider integration: Google Analytics 4. Classified as sale/sharing for these controls; restricted by Global Privacy Control.
Required services: none. All required services must also be allowed.
Declared request destinations: https://www.googletagmanager.com, https://www.google-analytics.com, https://region1.google-analytics.com, https://analytics.google.com.
_ga (cookie): Google browser and session identifiers. Scope: this host/. Duration: Up to 400 days (about 13 months). Accessible storage is removed on withdrawal.
_ga (cookie): Google browser and session identifiers. Scope: easya2p.app/. Duration: Up to 400 days (about 13 months). Accessible storage is removed on withdrawal.
_ga_E9MYKG489Y (cookie): Google browser and session identifiers. Scope: this host/. Duration: Up to 400 days (about 13 months). Accessible storage is removed on withdrawal.
_ga_E9MYKG489Y (cookie): Google browser and session identifiers. Scope: easya2p.app/. Duration: Up to 400 days (about 13 months). Accessible storage is removed on withdrawal.
Google Ads measurement
Category: marketing. Purpose: Let Google Ads credit a sign-up to the ad click that brought you, through Google Analytics 4. Ad click IDs (gclid, gbraid, wbraid) stay in page addresses only while this is allowed. Advertising personalization and remarketing stay off.
Provider integration: Google Ads measurement through Google Analytics 4. Classified as sale/sharing for these controls; restricted by Global Privacy Control.
Required services: Google Analytics 4. All required services must also be allowed.
Declared request destinations: https://www.googletagmanager.com, https://www.google-analytics.com, https://region1.google-analytics.com, https://analytics.google.com.
_gcl_au (cookie): Google Ads click and conversion identifiers. Scope: this host/. Duration: Up to 90 days. Accessible storage is removed on withdrawal.
_gcl_au (cookie): Google Ads click and conversion identifiers. Scope: easya2p.app/. Duration: Up to 90 days. Accessible storage is removed on withdrawal.
_gcl_aw (cookie): Google Ads click and conversion identifiers. Scope: this host/. Duration: Up to 90 days. Accessible storage is removed on withdrawal.
_gcl_aw (cookie): Google Ads click and conversion identifiers. Scope: easya2p.app/. Duration: Up to 90 days. Accessible storage is removed on withdrawal.
_gcl_gb (cookie): Google Ads click and conversion identifiers. Scope: this host/. Duration: Up to 90 days. Accessible storage is removed on withdrawal.
_gcl_gb (cookie): Google Ads click and conversion identifiers. Scope: easya2p.app/. Duration: Up to 90 days. Accessible storage is removed on withdrawal.
_gcl_ag (cookie): Google Ads click and conversion identifiers. Scope: this host/. Duration: Up to 90 days. Accessible storage is removed on withdrawal.
_gcl_ag (cookie): Google Ads click and conversion identifiers. Scope: easya2p.app/. Duration: Up to 90 days. Accessible storage is removed on withdrawal.
Microsoft Clarity
Category: analytics. Purpose: Record how pages are used (clicks, scrolling and layout) as session replays and heatmaps, to find what confuses visitors. Clarity masks text typed into forms.
Provider integration: Microsoft Clarity. Classified as sale/sharing for these controls; restricted by Global Privacy Control.
Required services: none. All required services must also be allowed.
Declared request destinations: https://www.clarity.ms, https://scripts.clarity.ms, https://*.clarity.ms, https://c.bing.com.
_clck (cookie): Clarity visitor identifier. Scope: this host/. Duration: Up to 1 year. Accessible storage is removed on withdrawal.
_clck (cookie): Clarity visitor identifier. Scope: easya2p.app/. Duration: Up to 1 year. Accessible storage is removed on withdrawal.
_clsk (cookie): Clarity session identifier. Scope: this host/. Duration: Up to 1 day. Accessible storage is removed on withdrawal.
_clsk (cookie): Clarity session identifier. Scope: easya2p.app/. Duration: Up to 1 day. Accessible storage is removed on withdrawal.
_cltk (sessionStorage): Clarity session tracking. Scope: this host/. Duration: Until the tab closes. Accessible storage is removed on withdrawal.
CLID (cookie): Clarity visitor identifier (third-party, set by Microsoft). Scope: www.clarity.ms/. Duration: Up to 1 year. This site's JavaScript cannot remove this storage.
MUID (cookie): Microsoft visitor identifier (third-party, set by Microsoft). Scope: clarity.ms/. Duration: Up to 13 months. This site's JavaScript cannot remove this storage.
MUID (cookie): Microsoft visitor identifier (third-party, set by Microsoft). Scope: bing.com/. Duration: Up to 13 months. This site's JavaScript cannot remove this storage.
SRM_B (cookie): Microsoft identifier synchronisation (third-party, set by Microsoft). Scope: c.bing.com/. Duration: Up to 13 months. This site's JavaScript cannot remove this storage.
MR (cookie): Microsoft identifier refresh (third-party, set by Microsoft). Scope: c.bing.com/. Duration: Up to 7 days. This site's JavaScript cannot remove this storage.
MR (cookie): Microsoft identifier refresh (third-party, set by Microsoft). Scope: c.clarity.ms/. Duration: Up to 7 days. This site's JavaScript cannot remove this storage.
SM (cookie): Microsoft session marker (third-party, set by Microsoft). Scope: c.clarity.ms/. Duration: Until the browser closes. This site's JavaScript cannot remove this storage.
ANONCHK (cookie): Microsoft identifier check (third-party, set by Microsoft). Scope: c.clarity.ms/. Duration: A few minutes. This site's JavaScript cannot remove this storage.
Content loaded when you ask for it
Some pages offer content from another provider, such as a form or a chat. It is not loaded with the page: you see a button, and nothing is requested from the provider until you press it. Pressing it is a request for that content, not permission for optional services, and it is not remembered on other pages.
The sign-up form: Collect the details you choose to submit, such as your email address for the TCR Rejection Decoder or new-guide notifications. Inside the form, HighLevel loads Cloudflare Turnstile (bot protection) and Google Fonts, and its form code also downloads Facebook's tracking script; no Facebook pixel is set up, so no Facebook events are sent. Provided by HighLevel (LeadConnector). Once loaded it may contact: https://link.garyvogtconsulting.com, https://link.msgsndr.com, https://backend.leadconnectorhq.com, https://stcdn.leadconnectorhq.com, https://challenges.cloudflare.com, https://fonts.googleapis.com, https://fonts.gstatic.com, https://storage.googleapis.com, https://connect.facebook.net.
embedded_iframe_inline-* (localStorage): HighLevel's record of the embedded form's layout. Scope: this host/. Duration: Until you clear this site's data. Set by the provider's scripts after you load the content; the cookie controls do not remove it.
Consent records
Choices are sent to the same-origin /consent-log endpoint. Records contain site and random consent IDs, an event ID, submitted and effective choices, Global Privacy Control state, client/server timestamps and the policy/configuration/package versions. Cookie-choice records do not include a visitor name, email, full page URL, query string, raw IP address or browser fingerprint.
Configured record-processing providers: Railway, Cloudflare, Supabase. Hosting and network providers may process connection metadata; their logs and retention require separate review.
Consent events are retained for 730 days according to the configured deletion schedule. Referenced policy snapshots remain available for retained records. Database backups are kept for 7 days, so a deleted record can remain in a backup for up to 7 more days.
Your choices take effect even if record delivery fails. A bounded in-memory queue retries delivery; pending events can be lost when a page closes or the browser stops. Local choices are not proof that an audit record was delivered.
Contact and changes
Contact Easy A2P at info@easya2p.app about cookie choices or retained consent records. A consent ID alone is not authorization to obtain records; requests require a separate identity/access review.
This policy and service inventory are versioned. Processing changes are reviewed before deployment; the banner may ask again when an existing grant no longer matches a service's scope.