Cookie Policy
Current Car&Vibe legal content from the launch legal package. Backend booking snapshots remain authoritative for accepted request records.
1. Purpose of this Policy
This Policy explains how Car&Vibe uses cookies, local storage, scripts and similar technologies on carandvibe.com, including the consent-controlled analytics foundation and possible future advertising conversion measurement.
2. Consent categories
The website provides three categories: Necessary, Analytics and Marketing. Necessary technologies remain enabled where required for security, authentication, booking and payment integrity, recording legal preferences and basic Platform operation. Analytics and Marketing are optional and can be accepted, rejected or changed independently.
Before any optional choice, Google Consent Mode v2 defaults `analytics_storage`, `ad_storage`, `ad_user_data` and `ad_personalization` to denied. Analytics controls `analytics_storage`. Marketing controls `ad_storage`, `ad_user_data` and `ad_personalization`.
3. Technologies
| Technology | Provider | Category | Purpose | Consent required | Verified storage mechanism | Verified duration |
|---|---|---|---|---|---|---|
| Car&Vibe consent preference | Car&Vibe | Necessary | stores the versioned Analytics and Marketing choices and timestamp so the website can respect them | no; required to remember the User's choice | first-party browser local storage key `carvibe_cookie_consent`, version 1; no personal information | 180 days unless changed earlier |
| Car&Vibe Google organic attribution | Car&Vibe | Analytics | measures a consented Google organic landing-to-booking funnel and attributes backend-confirmed platform revenue to the normalised landing route | yes, Analytics | first-party HTTP-only cookie `carvibe_google_organic_session` with a random session identifier; the server record excludes search query, full referrer, IP address, browser user agent, account identity and free text | up to 30 days; the browser cookie is cleared when Analytics consent is withdrawn |
| Google Tag Manager | Necessary technical tag management | loads and manages configured tags after the denied defaults are established; GTM does not by itself determine each tag's processing purpose | no separate optional consent for the manager; every configured tag must follow its own category and consent requirement | container script and in-page data layer; Car&Vibe does not use GTM as the consent-preference store | page runtime; no separate browser-storage duration is claimed for GTM itself | |
| Google Consent Mode v2 | Necessary consent signalling for Analytics and Marketing | communicates denied or granted consent states to consent-aware Google tags | no separate optional consent; it communicates the choice | consent commands and signals; no separate Car&Vibe browser record beyond `carvibe_cookie_consent` | current page/session for signals; the source preference lasts 180 days | |
| Google Analytics 4 | Analytics | website usage, technical interaction, reliability and service-improvement reporting | yes, Analytics | when granted, GA4 may use first-party cookies `_ga` and `_ga_<container-id>`; under advanced Consent Mode while denied, a configured Google tag may send limited cookieless pings | Google documents a default cookie duration of up to 2 years, subject to browser and tag settings; GA4 user/event data retention must be configured to a maximum of 14 months before activation | |
| Vercel Web Analytics | Vercel | Analytics | aggregate page-view and basic technical website-usage reporting | yes, Analytics | no third-party cookies; Vercel describes request-based hashing and aggregate data points | Vercel states that its visitor-session hash is discarded after 24 hours; no separate browser cookie duration applies |
| Google Ads conversion measurement (future) | Marketing | measuring advertising effectiveness if separately approved and activated | yes, Marketing | inactive now; configuration-specific advertising or measurement storage will be documented before activation | not applicable while inactive; no duration is claimed before configuration |
Google Tag Manager is a tag-management mechanism, not a separate business purpose. Loading GTM does not authorise Analytics or Marketing tags to ignore the User's choice.
4. Analytics and Consent Mode
Car&Vibe uses GA4 analytics reporting only after the User grants Analytics consent. Vercel Web Analytics is also consent-gated by the Analytics choice, does not use third-party cookies and is loaded only after Analytics consent.
After Analytics consent, Car&Vibe may measure aggregate booking funnels for Rent and Leisure in GA4. The Rent steps are viewing vehicle results (`search_results_viewed`), selecting a Rent listing (`listing_selected`), beginning submission of a booking request (`booking_request_started`) and successful submission of a booking request (`booking_request_submitted`). The Leisure steps are beginning submission of a booking request (`booking_request_started`) and successful submission of a booking request (`booking_request_submitted`). For both verticals, successful submission is recorded only after the server confirms that the request was created.
Each custom booking-funnel payload contains only its allowlisted event name and one fixed discriminator: `vertical: rent` for Rent or `vertical: leisure` for Leisure. Car&Vibe does not intentionally send a booking or request ID or reference, listing or experience ID, UUID, user or account ID, email, phone, date, time, number of guests or participants, listing title, Partner name, price or payment amount, Stripe or payment data, exact location, real dynamic URL, query string, referrer, free text or any arbitrary dynamic value with these events. `booking_request_submitted` may be configured as a GA4 key event for aggregate conversion measurement.
If the configured Google tag uses advanced Consent Mode while `analytics_storage` or advertising storage remains denied, Google may receive limited cookieless consent-state and basic measurement pings. Google states that these can contain functional information such as timestamp, user agent, referrer, page URL, consent-state indicators and a random number. Analytics or advertising cookies are not read or written while the relevant storage consent is denied.
Browser or device storage and aggregate records held by a provider are distinct and can have different retention periods. The GA4 14-month retention setting applies to user-level and event-level provider data and does not determine browser-cookie expiry or mandatory Car&Vibe booking, invoice, dispute, fraud, tax or accounting retention.
5. Marketing and advertising
After Analytics consent, when the initial referrer is a Google domain and the landing route is on Car&Vibe's fixed public SEO allowlist, Car&Vibe may set the first-party HTTP-only cookie `carvibe_google_organic_session` for up to 30 days. The related first-party record stores a random session identifier, normalised landing route, language and session-level timestamps for landing, listing selection and booking start. It does not store the search query, full referrer, IP address, browser user agent, account identity or free text.
If an authenticated booking request is successfully created during that attribution window, Car&Vibe may attach `google_organic`, the normalised landing route and attribution timestamps to that booking. Referral, hotel and QR attribution has priority and is not overwritten. Staff reporting may then combine aggregate funnel counts with backend-confirmed captured-booking status and Car&Vibe platform revenue, rather than treating the full Partner service price as Car&Vibe revenue. Withdrawing Analytics consent stops future collection and clears the browser attribution cookie; records lawfully created before withdrawal may remain for the stated analytics and business-record retention purposes.
The aggregate Rent and Leisure funnel events are Analytics events. They are not Google Ads remarketing or advertising events.
Google Ads conversion measurement may be activated in the future to measure advertising effectiveness only after the applicable Marketing consent and a separate disclosure and approval.
Google Ads remarketing, personalised advertising audiences, Customer Match and cross-site marketing profiles are not currently active. They require a separate product and privacy review before activation. Google Ads conversion storage, cookies, event definitions and retention will be documented when the actual configuration is approved; no such storage is active now.
6. Data minimisation
Car&Vibe does not configure custom analytics, GTM data-layer, Google Ads or Vercel Analytics events to intentionally send full name, email, phone, exact pickup or meeting address, private messages, OIB or tax data, identity documents, raw Stripe identifiers, payment references, client secrets, exact coordinates or other protected booking or payment data.
The custom booking-funnel events are limited to the allowlisted event name and either `vertical: rent` or `vertical: leisure`. Automatic page-view tools may separately process the page path or route, referrer, browser/device information, coarse location and timestamp.
7. Managing and withdrawing consent
Users can accept all, reject optional categories or manage Analytics and Marketing independently. The persistent Cookie settings action in the website footer reopens the preferences at any time. A change or withdrawal applies immediately going forward and does not retroactively affect processing based on consent before withdrawal.
Browser controls can also delete or block browser storage and cookies. Blocking Necessary technologies may affect security, authentication, language settings, booking requests, payment continuity or other Platform functions.
8. Changes to this Cookie Policy
Car&Vibe may update this Policy when technologies, providers, configurations or legal requirements change. Optional advertising features will not be treated as active merely because they are described as future functionality.
9. Contact
Questions about this Policy may be sent to legal@carandvibe.com.