Legal · Version 2.4.0 · Last updated 2026-07-26
Guest Talk cookie policy
This policy explains how Guest Talk uses cookies and similar technologies on the Guest Talk marketing website at talkg.fabriza.org and inside the authenticated Guest Talk application. It is written to align with the ePrivacy Directive 2002/58/EC as transposed into national law across the European Economic Area, the guidance of the European Data Protection Board on the interplay between the ePrivacy Directive and the GDPR, and the recommendations of the French CNIL, German DSK and Estonian AKI on cookie transparency.
1. What are cookies
Cookies are small text files that a website stores on your device (computer, tablet or phone) when you visit. Similar technologies include local storage, session storage, and pixel tags. Cookies allow a website to recognise your device on subsequent visits, remember settings, keep you signed in, or measure how the site is used.
Cookies can be categorised by the party that sets them (first-party = the site you are visiting; third-party = another domain embedded on the page), by their persistence (session = deleted when you close the browser; persistent = expire at a set date), and by their purpose (strictly necessary, functional, analytics, marketing).
2. Cookies on the Guest Talk marketing website
The marketing website at talkg.fabriza.org uses the minimum possible set of cookies: a single strictly-necessary cookie and, if you set a preference, one functional cookie. It uses no marketing cookies and no third-party trackers. It uses server-side, cookieless analytics (Fathom) to measure aggregate page views.
- gt_session — strictly necessary. Purpose: protects contact and access-request forms against cross-site request forgery (CSRF). First-party (talkg.fabriza.org). Session (deleted when you close the browser). No consent required under the ePrivacy Directive because it is strictly necessary for the service you have explicitly requested (submitting the form).
- gt_preferences — functional. Purpose: stores your language and theme preference (light or dark) if you set one. First-party. Persistent (12 months). Consent is inferred from your explicit act of choosing a preference; you can clear the cookie via your browser settings.
3. Cookies inside the authenticated application
The Guest Talk application, accessible only after you sign in, uses cookies to keep you signed in, protect your workspace against security threats, and remember your interface preferences.
- gt_auth — strictly necessary. Purpose: session token that keeps you signed in. First-party (app.talkg.fabriza.org). Persistent (rolling 30 days from last activity). HttpOnly, Secure, SameSite=Lax.
- gt_csrf — strictly necessary. Purpose: anti-CSRF token for state-changing API calls. First-party. Session. HttpOnly, Secure, SameSite=Strict.
- gt_workspace — strictly necessary. Purpose: identifies the workspace you are currently viewing when you belong to more than one. First-party. Session. HttpOnly, Secure.
- gt_feature_flags — functional. Purpose: caches your feature-flag assignments so the UI can render without waiting on a network round-trip. First-party. Persistent (24 hours).
- gt_lang — functional. Purpose: stores your preferred user-interface language. First-party. Persistent (12 months).
- gt_theme — functional. Purpose: stores your light- or dark-theme preference. First-party. Persistent (12 months).
- gt_last_seen — functional. Purpose: used by the "what's new" tour to know whether to show release notes on next login. First-party. Persistent (90 days).
4. Third-party services embedded in the application
Where a payment method is added or updated inside the application, the payment form is embedded as an iframe from our payment sub-processor, Stripe. Stripe sets its own cookies inside that iframe under stripe.com; those cookies are governed by Stripe's cookie notice at stripe.com/cookies-policy/legal. Guest Talk does not read those cookies and cannot see the sensitive fields (card number, expiry, CVV) that Customer enters into them.
Customers on the Enterprise plan may opt-in to Datadog Real User Monitoring for their own workspace to help our joint incident-response team correlate front-end errors with server logs. When enabled, Datadog sets a first-party cookie (renamed to gt_rum via our reverse proxy) to correlate a session across page loads. RUM is off by default and is only turned on with explicit written request.
5. First-party analytics
We use Fathom Analytics to understand aggregate traffic to the marketing website. Fathom is a cookieless, privacy-first analytics tool: it does not set any cookies on your device, does not track you across sites, and does not build a profile of individual users. Analytics data are aggregated on our behalf and do not require consent under the ePrivacy Directive.
6. How to control cookies
You can control cookies via your browser settings. Most browsers let you block third-party cookies, delete existing cookies, or delete all cookies when you close the browser. Guides for the major browsers:
- Chrome — Settings > Privacy and security > Cookies and other site data.
- Safari — Preferences > Privacy > Manage Website Data.
- Firefox — Settings > Privacy & Security > Cookies and Site Data.
- Edge — Settings > Cookies and site permissions > Cookies and site data.
If you block all cookies from talkg.fabriza.org you will still be able to read the marketing site but you may not be able to submit forms. If you block all cookies from app.talkg.fabriza.org you will not be able to sign in.
7. Do Not Track
Guest Talk honours the browser Do Not Track signal by disabling the optional functional cookies described above; strictly necessary cookies remain in use because they are, by definition, necessary for the requested service.
8. Local and session storage
Beyond cookies, the application uses browser local storage to cache non-sensitive UI state (open panels, column widths, last-viewed dashboard tabs) and session storage for transient form drafts. These entries are not transmitted to the server and can be cleared via your browser's site data settings.
9. Cookies and consent under ePrivacy
The cookies we use on the marketing website are strictly necessary or purely functional cookies set only in response to a user action; under Article 5(3) of the ePrivacy Directive and the CNIL/DSK guidance, consent is not required for such cookies. We nonetheless publish this policy so that visitors can inspect and audit our practices in detail.
10. Cookies for authentication in detail
Our authentication cookies use rotating refresh tokens: the primary access token lives inside gt_auth for a short window (30 minutes) and is silently renewed by a longer-lived refresh token held server-side, keyed by an opaque identifier that never leaves our infrastructure. This means that even if gt_auth were exfiltrated in a client-side breach, its usefulness to an attacker expires within 30 minutes without further server round-trips. Signing out revokes both the access and refresh tokens immediately and expires the cookie.
11. Regional supplements
United Kingdom. This policy is provided to comply with the Privacy and Electronic Communications Regulations 2003 (PECR) as amended, and the UK GDPR. UK visitors have the same rights over strictly necessary cookies (namely, that consent is not required) and functional cookies (namely, that a clear act of choice constitutes valid consent) as EEA visitors.
Switzerland. This policy is provided to comply with the Federal Act on Data Protection (revFADP) in force since September 2023. Guest Talk treats Swiss visitors as if the ePrivacy Directive applied.
Other jurisdictions. Where local law requires a cookie consent banner, our reverse proxy detects the visitor's approximate country and displays a banner offering explicit consent. In such cases we default all optional cookies to off until consent is granted.
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email to workspace administrators. The change log below records material revisions.
- v2.4.0 (2026-07-26) — added Datadog RUM opt-in disclosure; documented gt_last_seen cookie; added authentication token rotation and regional supplements sections; refreshed browser guidance links.
- v2.3.0 (2026-01-15) — removed HubSpot chat widget from marketing site (chat now over email only), reducing third-party cookie surface to zero.
- v2.2.0 (2025-06-01) — switched analytics to cookieless Fathom.
13. Similar technologies we do not use
For completeness, we note the technologies commonly listed on marketing sites that Guest Talk does not deploy:
- Advertising or retargeting cookies (Google Ads, Facebook Pixel, LinkedIn Insight, TikTok Pixel, etc.).
- Cross-site behavioural tracking scripts.
- Third-party session replay tools (FullStory, Hotjar, Mouseflow, LogRocket) on the marketing site. Where a customer opts in to session replay for their own internal debugging inside the authenticated application, it is limited to their workspace, masked by default, and disabled after 30 days of no activity.
- Device fingerprinting for tracking purposes. We do compute a hashed browser fingerprint solely for anti-fraud checks on high-risk actions inside the authenticated application; that fingerprint is not stored on your device and is not shared with third parties.
- Chat widgets from third-party providers. Our support channel is email at support@talkg.fabriza.org, which does not require cookies.
We publish this negative list because the presence of these tools is often invisible to visitors and a source of legitimate concern.
14. Consent, transparency and audit
Because the marketing site sets no cookies that require consent under the ePrivacy Directive, we do not display a cookie banner on the marketing site. This is not a workaround: it is the intended state of the ePrivacy regime for strictly-necessary and user-initiated functional cookies. We publish this policy to make the reasoning explicit and auditable. Concerned visitors can inspect all cookies set on the marketing site by opening their browser developer tools (Network and Application panels).
Where our reverse proxy detects a visitor from a jurisdiction that imposes stricter cookie-consent obligations than the ePrivacy Directive, or where a Customer configures a workspace to always show a consent banner, we render a banner offering explicit consent for the two functional cookies described in Sections 2 and 3, with a symmetrical "Reject" button. Declining the functional cookies simply means Guest Talk will not remember your language or theme preference between visits; core functionality continues to work.
15. Cookie inspection instructions
If you would like to verify our disclosure against reality, the following instructions let you inspect every cookie set by Guest Talk on your device without installing any tooling.
- Chrome / Edge. Open Developer Tools (F12) > Application panel > Storage > Cookies > talkg.fabriza.org. The full name, value, domain, path, expiry, Size, HttpOnly, Secure, SameSite and Partition Key attributes are shown for each cookie.
- Safari. Enable the Developer menu (Preferences > Advanced > Show Develop menu in menu bar), then Develop > Show Web Inspector > Storage > Cookies.
- Firefox. Open Developer Tools (F12) > Storage tab > Cookies > talkg.fabriza.org.
If you find a cookie set by talkg.fabriza.org that is not documented in this policy, please email dpo@talkg.fabriza.org. We investigate every such report and, where a cookie has been set inadvertently, we deploy a fix and add it to the change log.
16. Interaction with content-security and permissions policies
Guest Talk sends restrictive Content-Security-Policy, Permissions-Policy, Referrer-Policy and Strict-Transport-Security headers on every response. These headers together block the loading of third-party scripts, the use of the browser's precise location or camera without explicit user gesture, and the inclusion of the site in a frame on any other origin. This defensive posture is complementary to the cookie policy: even if a hypothetical third-party dependency attempted to set a cookie, our CSP would not allow the request to reach a third-party origin in the first place.
17. Handling requests from data protection authorities
Guest Talk regularly receives requests for detail from national supervisory authorities carrying out sectoral sweeps of cookie practices. We respond to such requests within the required deadlines. Our audit trail includes the deployed version of this policy at the time the visitor first landed on the marketing site, the exact HTTP response headers, and the browser cookie inventory we would expect to see; combined with the Fathom analytics cookieless aggregation this allows us to demonstrate compliance without processing any personal data of visitors beyond aggregate counts.
18. Contact
Questions about cookies or this policy: dpo@talkg.fabriza.org. Postal: Guest Talk OU, Sepapaja tn 6, 15551 Tallinn, Estonia.