1. What Are Cookies
Cookies are small text files that a website stores on your device when you visit it. They allow the site to recognize you on subsequent visits, remember your preferences, and collect information about how you use it. In addition to cookies, we may use similar technologies such as tracking pixels, tracking tags, local storage (localStorage), or session identifiers.
Cookies can be first-party (set directly by heysally.io) or third-party (set by external services we integrate). They can also be session cookies, which are deleted when you close the browser, or persistent cookies, which remain on your device for a set period.
2. Cookies We Use
2.1 Strictly necessary cookies
These are essential for the platform to function. Without them, you cannot log in, browse, or use the basic service features. They do not require your consent because their legal basis is contract performance. They cannot be disabled from the cookie preferences.
- Session and proprietary authentication: keep your session active while you use the platform.
- Google OAuth / Microsoft OAuth: when you sign in with your Google or Microsoft (Outlook) account, these providers set technical cookies necessary to complete the authentication process. They are outside Sally's direct control and are governed by Google's and Microsoft's respective policies.
- Stripe: when you make a payment, Stripe sets cookies necessary for secure transaction processing. They are governed by Stripe's policy.
2.2 Functional cookies
They allow the platform to remember your choices and offer you a more personalized experience (language, configuration preferences, state of certain interface options). They require your prior consent. If you do not accept them, the platform will work but some preferences may not be saved between sessions.
- Crisp (support chat): we use Crisp to offer you real-time support. Crisp sets cookies to identify your chat session, remember previous conversations, and keep the widget active. Chat data is managed by Crisp Chat SAS in compliance with the GDPR. Policy: crisp.chat/en/privacy.
2.3 Analytical cookies
They collect information about how the platform and website are used to help us improve them. Data is processed in aggregated or pseudonymized form. They require your prior consent.
- Google Analytics: measures web traffic, pages visited, session duration, and user behavior on heysally.io. Data is sent to Google LLC (USA) servers under Standard Contractual Clauses. Policy: policies.google.com/privacy. You can install the opt-out add-on at tools.google.com/dlpage/gaoptout.
- Google Tag Manager: a tag manager that activates and coordinates the other tracking tools configured (Google Analytics, Google Ads). By itself it does not collect user data, but it manages the cookies of the other tools that do. Policy: policies.google.com/privacy.
- PostHog: product analytics to understand platform feature usage. Data is processed with pseudonymization. Policy: posthog.com/privacy.
2.4 Advertising and tracking cookies
These cookies are used to show you relevant Sally ads on other platforms and to measure the effectiveness of our advertising campaigns. They have the greatest impact on your privacy and require your prior explicit consent. If you do not accept them, we may still show you advertising, but it will not be personalized based on your behavior on our website.
- Google Ads: we use Google Ads for advertising on the Google network and remarketing. Google sets cookies to measure conversions (whether you clicked an ad and performed an action on our website) and to show you personalized ads. Data is sent to Google LLC (USA) under Standard Contractual Clauses. You can manage your ad preferences at myadcenter.google.com. Policy: policies.google.com/privacy.
3. Authentication with Google and Microsoft
Sally allows you to sign in using your Google or Microsoft (Outlook) account as an authentication method. When you use this option, the corresponding provider verifies your identity and provides us only with the data necessary to create or access your account (name, email address, and unique identifier). This process means that Google or Microsoft may set their own session cookies on your device during the authentication process.
Sally does not access your password or other data from your Google or Microsoft account beyond what is strictly necessary for authentication. The use of this data is governed by Google's and Microsoft's respective privacy policies.
4. Cookie Summary by Provider
| Provider | Purpose | Consent | Duration |
|---|---|---|---|
| Google Analytics | Web analytics | Required | Up to 2 years |
| Google Tag Manager | Tag management | No own data | — |
| Google Ads | Advertising and remarketing | Required | Up to 540 days |
| PostHog | Product analytics | Required | Up to 1 year |
| Crisp | Support chat | Required | Up to 6 months |
| Google OAuth | Authentication | Not required | Session |
| Microsoft OAuth | Authentication | Not required | Session |
| Stripe | Payment processing | Not required | Session |
| Own cookies | Session and preferences | Not required | Session / up to 1 year |
5. How We Obtain Your Consent
The first time you access heysally.io, we show you a cookie banner that allows you to accept or reject non-essential cookies by category: functional, analytical, and advertising. Your choice is recorded and we will not ask again unless you delete your browser cookies or the consent validity period (12 months) has expired.
You can review and modify your preferences at any time from the "Manage cookies" link available in the footer. Withdrawal of consent does not affect the lawfulness of processing carried out previously.
6. How to Manage and Disable Cookies
In addition to the platform preferences panel, you can manage cookies directly from your browser settings:
- Google Chrome: support.google.com/chrome/answer/95647
- Mozilla Firefox: support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer
- Safari: support.apple.com/guide/safari/sfri11471/mac
- Microsoft Edge: support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge
To specifically opt out of Google advertising tracking, you can visit myadcenter.google.com. For Google Analytics tracking, you can install the official opt-out add-on at tools.google.com/dlpage/gaoptout.
Disabling strictly necessary cookies will prevent the platform from functioning correctly. Disabling the others will not affect access to the service.
7. Updates to this Policy
We will update this Policy when we add new tools or integrations that involve the use of additional cookies. Any relevant changes will be notified via the cookie banner or by email with at least 30 days' notice. The current version will always be available at heysally.io/cookies.
8. Contact
If you have any questions about the use of cookies on heysally.io, you can contact us at:
- Email: legal@heysally.io
- Postal address: EUREKA INNOVATIONS LLC, 254 Chapman Rd, Ste 208 #18613, Newark, Delaware 19702, USA.