Cookie & Tracking Notice

What we store in the browser, and why.

Gardien keeps browser storage to a minimum: what sign-in needs to work, and privacy-friendly analytics. This page also explains the tracker that business customers embed on their own websites.

Essential

Cookies the product cannot run without.

gardien_sessionKeeps you signed in after login. Strictly necessary; set only after you authenticate.
gardien_oauth_state / redirectShort-lived cookies that protect the Google sign-in flow from tampering. Deleted right after login.

Essential cookies do not require consent because the service you asked for cannot work without them.

Analytics

How we measure our own site.

Cloudflare Web AnalyticsAn always-on, cookie-free performance beacon injected by Gardien's network provider. Cloudflare states that this service does not collect or use visitors' personal data.
Vercel AnalyticsOptional aggregate traffic measurement for gardien.io, loaded only after you allow analytics. No cross-site advertising identifiers.
Gardien first-party trackerWhen enabled and you consent, records pathname-only page views to power our own dashboards.

Cloudflare documents Web Analytics as privacy-first real-user performance measurement that does not collect or use visitors' personal data. The Privacy choices control applies to Gardien's optional Vercel and first-party analytics.

The embedded tracker

What runs on a customer's website.

When a business installs the Gardien checkpoint, a small script runs on that business's site and stores two random identifiers in the visitor's browser. These identifiers are not names and are not used for cross-site advertising.

gardien_analytics_consent_v1Remembers whether you allowed or declined optional analytics so Gardien can honor your choice.
gardien_anonymous_idA random visitor identifier so repeat visits can be counted without names; created only after analytics consent.
gardien_session_v2A random session identifier that rotates after 30 minutes of inactivity; created only after analytics consent.

The business that installs Gardien is responsible for its own cookie/consent notice to visitors. Gardien acts as that business's processor under the Data Processing Addendum. Customer-domain tracking must remain monitor-only until the site's consent configuration and registered origin are active.

Your controls

Turning tracking off.

Use the Privacy choices link in the footer to allow or decline optional Vercel and Gardien analytics at any time. Cloudflare's cookie-free performance beacon does not create Gardien browser identifiers and, according to Cloudflare, does not collect or use personal data; you can still block it with browser or network controls. You can also clear or block cookies and site data in your browser settings; blocking essential cookies will prevent sign-in. Customer-domain analytics remain disabled until each site has an enforceable consent and origin configuration. Questions: admin.gardien.io@gmail.com.