Legal area

Cookie policy

Last updated: 10 September 2026 · Version 2026-09-10-meta-capi

Scope of the document

This Cookie Policy covers the wayoutapp.it website, including landing page, waitlist, pre-sale page, checkout, contact form and legal pages. It should be read together Privacy Policy of the site, current version.

1. Data controller and contacts

For general information on the processing of personal data, recipients, transfers and rights of interested parties, please refer to Privacy Policy published on the website.

2. What are cookies and other tracking tools

Cookies are small text files that a third party site or service can store in your browser or device and read during your visit or in later accesses. They can be session when they are deleted at the end of the session or after a short period of inactivity, or persistent, when they are stored longer.

The site can also use similar technologies, such as local storage, online identifiers, pixels, tags, URL parameters and network requests. In this policy the term “cookie” includes, where relevant, also such tools.

3. Categories of instruments used

3.1 Strictly necessary tools

They enable navigation, protection of public forms through Google reCAPTCHA v3, session management, cookie preference registration, email verification, checkout, Firebase/reCAPTCHA phone verification, payment and fraud prevention. Their use does not require consent when limited to what is strictly necessary for the requested service and not used for additional purposes, subject to the transparency obligation.

3.2 Analytics

Google Tag Manager and Google Analytics 4 are uploaded only after your consent to the Analytics category. The configuration uses Google Allow Mode in Basic mode: Before interacting with the banner Google tags remain blocked and data is not transmitted to Google.

3.3 Marketing and profiling

Meta Pixel browser side is activated only after consent to the Marketing category. Automatic Pixel Advanced Matching remains disabled. The Conversions API may complement the Pixel following a renewed Marketing consent choice.

4. Management of consent

WAYOUT uses an internal CMP. Only the tools strictly necessary are active at first access. The banner allows, with clear commands and equal evidence, of:

  • accept all unnecessary tools;
  • refuse all unnecessary tools and continue with only technical tools;
  • customize the categories Analytics and Marketing separately;
  • close the banner while keeping the default settings, without any unnecessary tracking.

The scrolling, the continuation of navigation, silence or pre-selected boxes do not constitute consent. You can change or revoke your choices at any time by linking “Manage cookie preferences” available in the footer or by means of an equivalent command always accessible.

The choice is stored by the technical cookie wayout_cookie_consent for 6 months and registered in a pseudonymous server-side log with date/hour, version of the CMP, preferences and hash of IP/user agent. The log is kept for 6 months, except for concrete disputes. The banner can be reproduced before expiry in case of cancellation of the cookie, modification requested by the user or significant changes in the purposes, categories or third parties.

5. Cookies and tools strictly necessary

Name / instrument Supplier and domain Purpose Indicative duration Category / consent
wayout-session WAYOUT / wayoutapp.it It maintains the session and connects the forms, the waitlist, the pre-sale and the administrative area. 120 minutes of inactivity, except for different production configuration Necessary - no consent
wayout_cookie_consent WAYOUT / Internal CMP Stores acceptance, rejection and granular preferences and allows you to apply your choice. 6 months, subject to change or revocation Technical Preference - no consent
Token CSRF and security data WAYOUT / Laravel Protects forms and requests from unauthorized use. It can be stored in the session without autonomous cookie. Duration of session Necessary - no consent
Language Preference WAYOUT / wayoutapp.it Remember the selected language in the session. Duration of session Required functionality - no consent
_ Stripe / Stripe domains Fraud prevention and transaction risk assessment. Up to 1 year Payment/anti-fraud - no consent
_ Stripe / Stripe domains Fraud prevention and transaction risk assessment. About 30 minutes Payment/anti-fraud - no consent
Other anti-fraud identifiers Stripe Stripe / domains Stripe and m.stripe.network Safety and anti-fraud technical signals; names and duration may vary according to the Stripe flow. Variable session or duration according to Stripe Payment/anti-fraud - no consent
Google reCAPTCHA v3 / Firebase Phone Authentication Google / Firebase Anti-spam protection for public forms and phone verification in checkout; may use network requests, tokens, risk scores and technical storage. Session or technical duration necessary for verification; variable details according to Google configuration Required for verification/ authentication - no consent, if limited to the required function
wayout_event_* (localStorage/sessionStorage) WAYOUT / browser Technical deduplication of analytics/conversion events to avoid multiple sendings; does not contain email, phone or form data. Session or technical duration of the flag; deleted/updated according to the logical event Measurement support technician; Google/Meta events leave only after their consent

Stripe.js and technical payment tools are loaded only when the user actually accesses the checkout, not the simple opening of the pre-sale page. Stripe Link is not enabled. The actual list of Stripe identifiers is checked periodically by technical scanning and browser tools.

6. Google Tag Manager and Google Analytics 4

6.1 Google Tag Manager

Google Tag Manager is used to administer and distribute site tags and not as a user database. The container is loaded only after consent Analytics. Tags belonging to other categories can only be activated after specific consent to the relevant category.

6.2 Google Analytics 4

After consent Analytics, WAYOUT uses Google Analytics 4 for site usage statistics and conversion measurement. The initial configuration includes Google Signals, advertising customization, User-ID, cross-domain tracking and Enhanced Conversions disabled. WAYOUT does not send Google emails, telephone number, tax code or other directly identifiable data.

Name / instrument Supplier and domain Purpose Indicative duration Category / consent
_ Google / wayoutapp.it Distinguish browsers and allow statistical measurement. Up to 2 years, except for configuration or browser limits Analytics - required consent
_ Google / wayoutapp.it It maintains the session status for the specific Google Analytics 4 property. Up to 2 years, except for configuration or browser limits Analytics - required consent

The event and user data retention period in the GA4 account is configured in 14 months; this period is distinct from the duration of cookies in the browser.

7. Meta Pixel

After Marketing consent, WAYOUT uses Meta Pixel in the browser and, when configured, the server-side Conversions API to measure visits and conversions from campaigns, understand the effectiveness of advertising, create public and carry out any remarketing. Meta can receive online identifiers, browser and device information, IP address, page visited, referrer and events made on the site, even when you do not have a Facebook or Instagram account or are not authenticated.

Name / instrument Supplier and domain Purpose Indicative duration Category / consent
_ Meta Platforms / wayoutapp.it Measurement, campaign attribution, audience creation and Meta advertising. Up to 90 days, according to configuration and Meta policy Marketing/profiling - required consent
_ Meta Platforms / wayoutapp.it Stores the advertising click identifier when the URL contains the fbclid parameter. Up to 90 days, if present Marketing/profiling - required consent

8. External links and social networks

The footer can contain simple links to WAYOUT profiles on Instagram and TikTok. In the absence of embedded social buttons, embed video, SDK or widget, the simple link does not determine the installation of social cookies on the WAYOUT website. After clicking and accessing the external platform, its provider processes data according to its own information.

9. Transfers to countries not belonging to the EEA

The main hosting of the site through Aruba is configured in the European Union. Google, Meta, Stripe or some of their suppliers and subcontractors may however process or make data accessible even outside the European Economic Area. Transfers take place, according to their respective roles, on the basis of adequacy decisions, Standard Contractual Clauses or other mechanisms provided for in Articles 44 and following GDPR. Further details are available in Privacy Policy and in the information of suppliers.

10. How to manage cookies from the browser

You may delete or block cookies through your browser settings. The blocking of the instruments strictly necessary can prevent the proper functioning of the forms, the session, the pre-sale, the administrative area or the checkout. Browser settings do not replace the site preferences panel, which allows you to manage the Analytics and Marketing categories instantly.

11. Update of inventory and Cookie Policy

Names, domains and durations of third-party cookies may change for updates of suppliers, browsers or technical configuration. WAYOUT periodically checks the inventory through scans and tests in the production environment and updates this policy and CMP when changing tools, purposes, categories, durations or third parties. In case of significant changes affecting the choices already expressed, the banner is redesigned or a new choice is required.

12. Contact

For questions about this Cookie Policy or the use of tracking tools you can write to amministrazione@wayoutapp.it. To exercise the rights provided by the GDPR, please refer to Privacy Policy of the site.

Effective date: from the publication on the website wayoutapp.it.

Meta Conversions API

When enabled in the website configuration, the Conversions API sends verified waitlist registrations and server-confirmed purchases to Meta only with valid prior Marketing consent, separate from consent to promotional emails. Data may include a normalized SHA-256-hashed email, IP address, user agent, _fbp and _fbc cookie identifiers when available, event name, time and identifier, a source page without tokens or confidential parameters and, for purchases, value and currency. Hashing does not make the email anonymous. Pixel and server share an event identifier to prevent double counting. Pending data is stored encrypted for up to seven days and event payloads are removed after delivery; checks and cleanup run through the website scheduler. Consent is checked again before every attempt: withdrawal through cookie preferences prevents subsequent deliveries associated with that consent. The purposes, recipients, transfers and rights described in the Privacy policy also apply.