Last updated: October 1, 2026
Effective: October 1, 2026
1. Essential operation and security
We use technology needed to operate and secure the website. Cloudflare Turnstile processes browser and network signals to distinguish visitors from automated abuse. Hosting and security providers may use necessary technical storage for these functions; it is not used by us for advertising.
The private operations console uses an eight-hour, signed session cookie named fcc_ops_session, limited to the operations area. It is HttpOnly, Secure in production, and SameSite Strict. Public customers do not need an account or this cookie.
2. Your saved preference
The local-storage entry fcc_optional_cookies_consent_v1 remembers one choice for all optional site analytics and advertising technologies until you change it or clear browser storage. Earlier provider-specific permissions do not count as consent to this combined choice; visitors with only an earlier preference are asked again. Rejecting keeps all optional tags off. A Global Privacy Control signal keeps advertising tracking off even if you accept optional cookies; site analytics may still run if you accept.
A signed, HttpOnly payment-confirmation cookie lasts up to 30 minutes and lets the confirmation page recognize a server-verified purchase without putting a private checkout link in its address. If you permit measurement, local storage also records a pseudonymous purchase identifier to avoid counting the same purchase again in this browser.
3. Optional measurement and advertising
If you accept optional cookies, Google Analytics may set first-party cookies such as _ga to measure visits and purchases. Google Ads measurement may use advertising cookies such as _gcl_au and valid ad-click identifiers (gclid, gbraid, or wbraid) on public landing pages to measure our Google campaigns. When Google Ads account linking is configured, consented measurement may also be shared with that account. Google ad personalization, Google Signals, and remarketing remain disabled.
If you accept optional cookies and Global Privacy Control is not active, Meta Pixel may use cookies such as _fbp and _fbc, browser and network information, public page URLs, and purchase events to measure Facebook and Instagram ads and build advertising audiences. See Meta’s Privacy Policy and Cookie Policy. We do not provide form contents or enable automatic advanced matching.
Tracking scripts are excluded from private checkout, report, and operations pages. A separate confirmation page can send the purchased plan, value after discounts excluding tax, currency, and a pseudonymous transaction identifier when the relevant tracking is permitted. Google also receives the tax separately. Neither service receives flight details, email, card information, raw payment references, or private access tokens through our event parameters.
4. Referral information
Same-tab session storage under fcc_campaign_attribution may hold short, non-personal campaign codes to preserve referral information as you navigate. It expires when the browser-tab session ends. It is not a customer account or cross-device identifier. Sending these codes to Google Analytics requires analytics permission.
5. Hosted checkout
Opening a hosted checkout can load the payment provider’s security, fraud-prevention, and payment technologies. These are governed by that provider’s policy, separately from optional website analytics. For a Paddle checkout, see Paddle’s Privacy Policy.
6. Managing storage
Use “Cookie settings” in the footer to accept or reject all optional tracking, or to withdraw a previous acceptance. You can also clear browser storage. Declining optional tracking does not prevent use of the service. Blocking essential security or payment technologies may prevent form submission or checkout.
7. Updates and contact
We will update this policy and any required consent controls before introducing materially different tracking. Questions may be sent to privacy@flightchangecheck.com.