Cookie Policy

Last updated: June 16, 2026

com (also served at fitness-website-cx3.pages.dev) (the "Website"). It tells you, in plain language, what these technologies are, what we use them for, who else can see the information, how long it lasts, and exactly how you can turn it off. This Cookie Policy works alongside our Privacy Policy (/privacy) and our Terms of Service (/terms). The Privacy Policy is important here because it carries the full details of your privacy rights and the "Do Not Sell or Share My Personal Information" choice that this Cookie Policy refers to. Please read all three together. A note about our app: SOSA FIT is also building a mobile app, which is currently in development and not yet released to the public. This Cookie Policy covers the Website only. Before the app launches, we will update this policy (or publish a separate in-app notice) to describe exactly what the app collects and which providers it uses. Section 11 explains what we expect that to involve.

1. What Cookies (and Similar Technologies) Are

A "cookie" is a small text file that a website places on your device — your computer, phone, or tablet — when you visit. It lets the site remember things about you and your visit, like whether you're logged in or what you did last time. Cookies are extremely common; almost every website you use relies on them in some form.

When we talk about "cookies" in this policy, we also mean a handful of related technologies that do similar jobs on the Website. These include the following:

  • Pixels (also called web beacons or tags) — tiny, invisible bits of code on a page that fire when the page loads. The Meta (Facebook/Instagram) Pixel is one of these. It signals back to Meta that a visit or action happened.
  • Local storage — a way for the Website to store small amounts of data directly in your browser so it can be remembered between visits.
  • Device and browser identifiers — codes tied to your browser or device that help measure activity and, in some cases, support advertising.

2. How We Use Cookies and Similar Technologies

We use these technologies for a few clear purposes. In short, we use them to keep the Website working and secure, to understand how people find and use the site so we can improve it, and to measure and run our advertising. Here is the breakdown:

  • To run the basics — keep you logged in, remember your preferences, protect the site, and balance traffic so pages load reliably.
  • To understand our audience — see which pages are visited, how people arrive, and what's popular, so Diana can make the site and content better.
  • To support advertising — measure whether our ads are working and show relevant ads to people who have visited the Website (this is called retargeting).

3. Categories of Cookies We Use

We group the cookies and similar technologies we use into three categories. The breakdown below names the actual tools and gives examples of the specific cookies you may see, so you know exactly what's running.

  • (a) Strictly Necessary / Essential — These keep the Website functioning and secure. They handle things like your login session, security, and load balancing through Cloudflare (our hosting and content-delivery provider). These cookies do not track you for advertising. They cannot be turned off through controls on our site, though you can block all cookies in your browser settings (see Sections 7 and 8) — doing so may break parts of the Website. Under U.S. law, no consent is required for these essential cookies.
  • (b) Analytics / Performance — We use Google Analytics 4 (GA4) to measure how the Website is used. GA4 collects information such as pages viewed, how long visits last, how you arrived at the site (for example, from a search engine or a social link), your approximate location (from your IP address), and the type of device and browser you use. Example cookies include "_ga" and cookies that start with "_ga_". This helps us understand our traffic and improve the site.
  • (c) Advertising / Targeting — We use the Meta (Facebook/Instagram) Pixel and Google Ads to measure our advertising and to build retargeting and "custom audiences" — groups of people we can show ads to on Facebook, Instagram, and across Google's network, including people who have already visited the Website. These technologies enable what's known as cross-context behavioral advertising (advertising based on your activity across different sites and apps). Example cookies and identifiers include Meta's "_fbp" and "fr," and Google advertising cookies.

4. Analytics and Advertising Are Active for All Visitors on Page Load

We want to be honest with you about how this currently works. Our analytics tools (Google Analytics 4) and our advertising tools (the Meta Pixel and Google Ads) load automatically for every visitor as soon as a page loads. They are not currently placed behind an opt-in "accept cookies" gate, and there is no banner that blocks them until you agree.

Because these tools load on page load and there is no consent banner, some information about your visit may be transmitted to Google and Meta on your very first pageview, before any opt-out takes effect. We want to be clear about the difference between blocking the technologies and opting out of how the data is used:

Blocking collection: To stop these technologies from loading at all, you need to use browser-level cookie or script blocking, or install the Google Analytics Opt-out Browser Add-on, before you visit. These are the only methods that prevent the initial collection on a given visit.

Limiting use: Industry opt-outs (the Digital Advertising Alliance and Network Advertising Initiative tools) and a Global Privacy Control (GPC) signal limit how your data is used for targeted advertising and for the "sale" or "sharing" of your information. They are legal opt-out signals — they may not stop the pixel from firing on a given visit, but they tell us and our advertising partners how your information may be used going forward.

Section 7 lists every one of these methods so you have real, working ways to say no.

5. Third-Party Cookies and Recipients

Some cookies and technologies on our Website are set and read by other companies rather than by us. These are called third-party cookies. When they fire, those companies receive the information directly and use it under their own privacy policies. For advertising and measurement, this disclosure may be a "sale" or "sharing" of personal information under California (CCPA/CPRA) and similar U.S. state privacy laws — see Section 7 and our Privacy Policy (/privacy) for your opt-out rights. The main third parties involved are:

  • Google (Google Analytics 4 and Google Ads) — receives analytics and advertising information; governed by Google's Privacy Policy and its advertising terms.
  • Meta Platforms (the Facebook/Instagram Pixel) — receives advertising and conversion-measurement information used to build ad audiences; governed by Meta's Privacy Policy.
  • Stripe — our payment processor. When you make a purchase, Stripe may use cookies and similar technology to process the payment securely and help prevent fraud; governed by Stripe's privacy policy.
  • Cloudflare — our hosting, content-delivery, and security provider. Cloudflare uses essential cookies and technologies to keep the site fast, available, and protected; governed by Cloudflare's privacy policy.
  • Our email marketing provider — if you join our mailing list, the provider we use to send our emails may set tracking technologies (such as open and click pixels) in those emails, and may use cookies on the Website when you submit a sign-up form. This helps us see whether our emails are opened and which links are clicked; it is governed by that provider's privacy policy.

6. How Long Cookies Last

Cookies last for different amounts of time depending on what they do. There are two broad types:

  • Session cookies — temporary. They exist only while you're actively using the Website and are automatically deleted when you close your browser. They're used for things like keeping you logged in during a single visit.
  • Persistent cookies — these stay on your device for a set period (anywhere from a few days to many months) or until you delete them. They're used to remember you on return visits, measure traffic over time, and support advertising.

6a. Approximate Lifespans of the Key Cookies We Name

So you know roughly how long the specific cookies we identify can stay on your device, here are their typical durations. These are set by the third parties and may change; the figures below are approximate:

  • "_ga" (Google Analytics) — up to about 2 years.
  • "_ga_*" (Google Analytics 4 session/state) — up to about 2 years.
  • "_fbp" (Meta Pixel) — about 90 days.
  • "fr" (Meta advertising) — about 90 days.
  • Cloudflare essential cookies — typically session-length up to about 30 days, depending on the cookie.
  • You can delete any of these at any time using your browser settings (see Section 7).

7. How to Manage or Disable Cookies and Tracking

You have real control over cookies and tracking, and you don't have to accept them. Below are the main ways to limit or turn them off. You can use as many of these as you like — using more than one gives you stronger coverage.

Browser settings — Every major browser lets you view, block, and delete cookies. Look in your browser's settings or privacy menu:

  • Google Chrome: Settings then Privacy and security then Third-party cookies (and "Clear browsing data").
  • Apple Safari: Settings/Preferences then Privacy then Manage Website Data / Block all cookies.
  • Mozilla Firefox: Settings then Privacy & Security then Cookies and Site Data.
  • Microsoft Edge: Settings then Cookies and site permissions then Manage and delete cookies and site data.
  • Google Analytics Opt-out Browser Add-on — Stops Google Analytics from collecting your data across sites. Because it works at the browser level, it can prevent collection before it happens. Available at tools.google.com/dlpage/gaoptout.
  • Google Ads Settings — Manage or turn off ad personalization for your Google account at adssettings.google.com.
  • Meta ad preferences / Off-Facebook Activity — In your Facebook or Instagram settings, you can manage ad preferences and review or disconnect "Off-Facebook Activity" so your browsing isn't used to target ads.
  • Digital Advertising Alliance (DAA) — Opt out of interest-based advertising from participating companies at optout.aboutads.info.
  • Network Advertising Initiative (NAI) — Opt out of participating ad networks at optout.networkadvertising.org.
  • Global Privacy Control (GPC) — Some browsers and extensions can broadcast a GPC signal. We treat a GPC signal as a valid request to opt out of the "sale" or "sharing" of your personal information for targeted advertising. Please note that, because we have no consent banner, GPC does not stop the pixels from loading on a given visit — it tells us not to use the resulting information for the sale or sharing of personal information going forward.
  • Do Not Track (DNT) — Many browsers can send a "Do Not Track" signal. There is no common industry standard for how to respond to DNT, so our Website does not currently respond to DNT signals. If you want to limit tracking, please use the GPC, browser, and industry tools described in this section instead.
  • Our "Do Not Sell or Share My Personal Information" option — Because our advertising cookies may involve a "sale" or "sharing" of personal information under California and similar state laws, you can opt out. The request is handled through our Privacy Policy (/privacy), which explains how to make the request and how we apply it to GA4 and Meta sharing. If you would also like to remove existing cookies from this device, use the browser controls above.
  • Mobile devices — For apps generally, including ours once it is released, you can use the device-level controls "Limit Ad Tracking" (iOS) or "Opt out of Ads Personalization" (Android) to reduce ad tracking. These controls apply at the device level and are useful to set now even though the SOSA FIT app is still in development.

8. Consequences of Disabling Cookies

You're free to block or delete cookies, but it's fair to know the trade-offs. If you turn off strictly necessary cookies (by blocking all cookies in your browser), parts of the Website may not work properly — for example, you may not be able to stay logged in or complete a secure checkout.

If you turn off analytics or advertising cookies, the Website will still work normally for you. We'll simply collect less information about how the site is used, and you may see less relevant advertising from us. Disabling these does not prevent you from using any of our services.

9. Children's Privacy

The Website and the SOSA FIT app are intended for adults and are not directed to children under the age of 13. We do not knowingly use cookies or similar tracking technologies to collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us at the email in Section 11 and we will take appropriate steps to delete it.

10. Where We Operate and International Visitors

SOSA FIT is based in Miami, Florida, USA, and we operate the Website from the United States. Our primary audience is in the United States. Because our analytics and advertising providers (Google and Meta) are U.S.-based, information collected through cookies may be processed in the United States.

The Website is publicly accessible worldwide, but it is not specifically directed at visitors in the European Union or the United Kingdom, and it is not designed to meet the consent-banner requirements of those regions. If you access the Website from outside the United States, you do so on your own initiative and you understand that your information may be processed in the United States.

11. The SOSA FIT App (In Development)

Our mobile app, SOSA FIT, is still being built and is not yet available to the public, so it is not collecting data from users today. We are including this section so you know what to expect and so this policy never describes something that isn't actually running.

When the app launches, it will use Supabase as its backend to store your account and app data (for example, your profile, workouts, and nutrition entries). Mobile apps commonly use software development kits (SDKs) and device identifiers — the app equivalents of cookies — to keep the app working, sign you in, and understand usage. Before the app is released to the public, we will update this Cookie Policy (or provide a clear in-app notice) to name the specific SDKs and identifiers the app uses, what they do, and how to control them. We are not relying on this section to describe any tracking that is live today.

12. Changes to This Cookie Policy

We may update this Cookie Policy from time to time — for example, if we add or change the tools we use, if we launch the app, or to reflect changes in the law or our practices. When we make changes, we'll post the updated version here with a new "Last Updated" date at the top. If we make a significant change, we'll take reasonable steps to let you know.

We encourage you to review this page periodically so you are aware of any changes. The version posted here, with its Last Updated date, is the version that applies. Importantly, this Cookie Policy will always describe what is actually running on the Website — we won't describe a consent banner or control that isn't really in place.

13. More Information and Contact

If you have any questions about this Cookie Policy, about how we use cookies and similar technologies, or about exercising your privacy choices, please reach out. For more detail on the personal information we collect and your full privacy rights — including the "Do Not Sell or Share My Personal Information" process — please see our Privacy Policy (/privacy).

You can contact us at [email protected] — Miami, Florida, USA. We're a small, new business and we read every message, so don't hesitate to ask if anything here is unclear.