For everyone
Cookie Policy
Every cookie Glo sets, why each one is necessary, and why there is no cookie banner.
Version 1.3. Effective 7 September 2026.
Glo
Operated by Connor Wu trading as Glo, ABN 23 380 080 435
This policy sits alongside our Privacy Policy and our Terms of Service. The Privacy Policy governs how we handle personal information, and where this page and the Privacy Policy disagree, the Privacy Policy governs. This page carries the detail: it accounts for every cookie set on a Glo page, ours in section 3 and any set by the advertising tags in section 5.2, and we update the two documents in the same piece of work. If you ever find them out of step, tell us at hello@welcomeglo.com and we will fix it.
Clause 3.2 of our Terms of Service sets out which documents make up the subscription agreement for a business using Glo, and the order they apply in if they conflict. This page is a disclosure. It does not change that order.
In the product, Glo sets two cookies that matter to you, plus a small number of sign-in housekeeping cookies set by the authentication library we use, all four listed below. All of them are needed to make the thing you asked for work. The product means the signed-in dashboard, the booking, tracking, invoice, quote and unsubscribe pages a business's clients open, and these legal pages. On those pages we run no session recorders and no third-party trackers, and nothing on a page a business's clients use follows you anywhere.
Our public marketing pages may carry advertising tags from Meta and Google, so that we can advertise Glo to businesses. Where we use them, they run on our home page at www.welcomeglo.com and nowhere else. The pages a business's clients open, a booking page, a tracking page, a public invoice, a public quote and an unsubscribe page, carry none of it, and neither do these legal pages or any part of the signed-in dashboard. Section 5.2 sets out what those tags are, which pages they may run on, and what they never receive.
We do measure how the signed-in dashboard is used, by the businesses that subscribe to Glo. It sets no cookie, it loads nothing from another company, and it does not run on the pages a business's own clients see. Section 5 sets out what it is and what it is not.
1. Who this policy is for
This policy covers every page we operate at www.welcomeglo.com. That includes two very different groups of people who use Glo, and anybody at all who reads the pages we advertise on.
1.1 Businesses that use Glo. If you run a business and you have a Glo account, this policy covers the pages you sign in to.
1.2 Their customers. If a business sent you a link to book a job, to track a job, or to view an invoice or a quote, you are on a page we operate on that business's behalf. You do not have a Glo account and you never need one. This policy covers those pages too, and section 3.2 is the part that concerns you.
1.3 Anybody reading our public marketing pages. If you are looking at Glo and have not signed up for anything, and nobody has sent you a link to a job, you are on a marketing page. Those pages may carry advertising tags. The pages in 1.1 and 1.2 do not carry them at all, and section 5.2 is the part that concerns you.
2. What a cookie is
A cookie is a small piece of text a website asks your browser to keep, and to hand back the next time you load a page from that same website. It exists because the web has no memory of its own: without one, every page load would look like a stranger arriving for the first time.
3. Every cookie Glo sets in the product
There are four. Two of them do work you would notice, and two are sign-in housekeeping set by the authentication library we use. Section 3.3 covers the last two.
This is the list for the product: every page a business signs in to, and every page a business's clients open. The advertising tags our public marketing pages may carry set cookies of their own. They are not in this table, they are not counted in the four, and we are not going to add them together into one number, because they are a different thing set on different pages for a different reason. Section 5.2 is where they are set out.
| Cookie | What it is for | Type | How long it lasts | Who gets it |
|---|---|---|---|---|
__Secure-authjs.session-token | Keeps you signed in to your Glo account as you move between pages | Strictly necessary. First party. Set by us | Up to 30 days, counted from the last time you used Glo rather than from when you signed in, so an account in regular use stays signed in. Deleted immediately when you sign out | Businesses that use Glo, and their staff, only |
glo_booking_draft | Carries your answers from one step of a booking form to the next | Strictly necessary, with one convenience element described in section 8.2. First party. Set by us | 2 hours, and deleted the moment the booking is made | A customer filling in one business's booking page |
__Secure-authjs.callback-url | Records which page to send you back to after you sign in | Strictly necessary. First party. Set by the authentication library we use | Until you close your browser | Businesses that use Glo, and their staff, during sign-in and sign-out |
__Host-authjs.csrf-token | Protects a sign-in from being triggered by another website | Strictly necessary. First party. Set by the authentication library we use, in some circumstances | Until you close your browser | Businesses that use Glo, and their staff, in the circumstances described in section 3.3 |
All four are first party, which means they belong to welcomeglo.com and no other company can read them. All four are httpOnly, which means no JavaScript running in the page can read them either, including our own. They are sent only over an encrypted connection. None of them is used to build a profile of you, and none of them is shared with anybody.
3.1 The session cookie, in detail
Name: __Secure-authjs.session-token.
What it holds: your name and email address, your user id, the id of your business, your role in that business, and some technical information about the state of your account. It does not hold your password. It does not hold your payment details, which we never see at all.
What it does: it is what tells our server that a request for your dashboard is coming from you. Without it there is no way to sign in.
How long: up to 30 days. The clock restarts every time you use Glo, so if you use it regularly you stay signed in and the cookie is reissued with a fresh 30 day expiry. Thirty days without using Glo signs you out. Signing out deletes it straight away.
Access changes take effect quickly. An owner removing a staff member or changing somebody's role, or a password being reset, takes effect promptly rather than waiting for the cookie to expire.
Signing out is worth being precise about, because this is exactly the thing a person acts on when they are worried. Signing out deletes the cookie on the device you signed out from, immediately. If you think somebody else has your password, change your password, which ends your sessions on your other devices.
Who gets it: only people who sign in to a Glo account. A customer who books a job through a link never has one.
3.2 The booking draft cookie, in detail
Name: glo_booking_draft.
What it holds: the answers you have typed into a booking form so far. That means your name, your mobile number, your email address, the service address and Google's id for it if you picked it from a suggestions list, the colour of the vehicle the job is for, and any notes you added. The form records the thing a job is for as a vehicle. If that ever changes, we will update this page first.
It also holds an identifier for your client record with that business, which is written only after you have proved your email address by opening a link we sent you. That identifier is what lets that business's booking page offer you the vehicle you booked with last time, and the addresses you have used before, instead of a blank form. It is meaningless to anybody else, and it is written only by our server and never by anything in your browser.
What it does: a booking form runs over several screens, and the booking is not saved until the last one. This cookie is how your answers survive the walk from screen to screen.
How long: two hours. Long enough to think about it, short enough that a shared or borrowed computer does not hand your address to the next person who sits down. It is also deleted the instant the booking is created, so your details do not sit on your device any longer than the form that needed them.
How it is looked after, and this is for your benefit. Your browser will only ever send it back to the one booking page you are filling in. It is not sent to any other page on our site, and another business's booking page cannot see it. It cannot be read by a script in the page or by a browser extension, and it cannot be altered on your device without being rejected.
Who gets it: a customer filling in a business's booking page. The business does not get one unless they are testing their own booking page.
3.3 Sign-in housekeeping
Signing in and signing out also involves housekeeping cookies set by the authentication library we use. We list them here rather than leave them out, because a cookie policy that undercounts cookies is not a disclosure.
__Secure-authjs.callback-url. It records which page to send you back to
after you sign in. It is httpOnly, it lasts until you close your browser, and it
holds no personal information: just the address of a page on our own site. It is
set when you sign in and when you sign out, so if you sign in to Glo you will
have one.
__Host-authjs.csrf-token. A random string that protects your sign-in from
being triggered by another website. It is httpOnly and lasts until you close
your browser. It is set during sign-in in some circumstances rather than every
time.
Both are strictly necessary, both are ours, and neither tracks anything.
4. Why the booking form uses a cookie instead of the address bar
This is a deliberate design decision, and it protects you.
The obvious way to carry answers between the steps of a form is to put them in the web address, as a query string. It is easy to build and you can see the result on a lot of websites: a URL with somebody's name and phone number sitting in it in plain view.
We do not do that, because a web address does not stay in the address bar. It goes into your browser history, where anybody with your device can scroll back through it. It goes into a bookmark if you save one. It is what gets pasted into a message when you send somebody a link. And on many sites it is handed to the next site you visit as a referrer, where our pages are set up so that the page address and anything in it are not passed on that way.
Your name, your mobile number, your email address and your home address are exactly the things that must never end up in any of those places. So they travel in a short-lived cookie instead, one that expires in two hours and that your browser sends back only to the booking page you are filling in. That is the right answer, so that is what we do.
5. What Glo does not use
We want to be plain about this, because it is unusual enough that people assume otherwise.
This list is about the pages you use: the dashboard a business signs in to, and the booking, tracking, invoice, quote and unsubscribe pages a business's clients open. These legal pages are on it too. Our public marketing pages are a separate question with a separate answer, and section 5.2 gives it in full rather than burying it in a footnote here.
On those pages, Glo does not use:
- Any analytics service. No Google Analytics, no third-party product analytics, no page-view counting service, and nothing that reports to another company. What we measure ourselves is section 5.1.
- Advertising or retargeting pixels. Nothing from any ad network reaches them. No Meta or Facebook pixel, no LinkedIn insight tag, no Google Ads tag. If a business sent you a link, you have never been on a Glo page carrying one of these, and you never will be.
- Social media pixels or share buttons that phone home.
- Session recorders or heatmaps. Nothing records your mouse, your scrolling or your keystrokes. That one is true everywhere, marketing pages included.
- Third-party tracking cookies of any kind, and no cross-site tracking.
- Cross-device tracking. Nothing we run tries to work out that a browser on one device and a browser on another are the same person. That one is true everywhere, marketing pages included.
- A/B testing or personalisation tools. That one is true everywhere as well, marketing pages included. No page of Glo is quietly showing you a different version of itself to see which one works better.
- Selling advertising. We do not sell advertising, on any page, and nobody pays us to put a message in front of you. We do buy advertising to reach businesses that might want Glo, which is what section 5.2 is about, and we would rather write that down than let this bullet imply otherwise.
We also do not sell, rent or trade any personal information, cookie-derived or otherwise, and that one has no exception anywhere.
There is one structural reason this is easy for us to promise: there is no third-party script on any of those pages. Nothing on them loads code from another company, and loading somebody else's code is what a script-based tracker or an analytics beacon needs. Section 6.2 explains the one place where your browser talks to another company while you are still on one of those pages, what is sent to it, and what is not. Section 5.2 names the marketing pages, which are the exception and the only one. Section 9 sets out what we would do before any of this changed, and records the one item on that list that has already happened.
5.1 The one thing we do measure, and where
We record which parts of the Glo dashboard get used, so we can tell which of them are worth keeping and improving. It is our own product, measured by us, and it is the ordinary thing a software company needs to know about the software it sells.
Four boundaries matter more than the mechanism, so they are the four we commit to rather than describe:
-
It runs only when you are signed in to a business account. A booking page, a tracking page, a public invoice and a public quote are not measured. If you are a client of a business that uses Glo, nothing on this page's list applies to you and nothing on those pages measures you. That is not a setting we could quietly change: the measurement needs a signed-in account to record anything at all, and a client of a business never has one.
-
It is not a cookie and it is not stored on your device. The four cookies in section 3 are still the whole list for the product. This adds nothing to it, and section 7 still holds.
-
It goes nowhere else. No third party, no advertising network, no analytics vendor. It never reaches the advertising tags in section 5.2 either: those may run on a marketing page and never on the dashboard, so the two do not meet. It is recorded by Glo, on Glo's own systems, and it is covered by the disclosure rules in our Privacy Policy like everything else we hold.
-
It records screens and features, not people and not content. We do not record an IP address or a browser fingerprint against it, and it never contains anything you or your clients typed: not a name, not an address, not a note, not a message, not a client's identifier. Where the address of a screen would name one of your clients, the name is removed before anything is recorded.
-
You can tell us to stop, and we will. Email us and we will switch it off for your account, usually the same day. You do not have to give a reason, nothing else about your account changes, and no feature stops working. There is no button for this in Glo and we would rather say why than pretend the omission is an oversight: there are very few businesses using Glo today, so a control anybody could press by accident would take a large part of the picture with it and leave us with numbers that look reliable and are not. A request is honoured the same way regardless, and the switch behind it already exists, so it is a change we make rather than a change we have to build. That reasoning is revisited as Glo grows.
Privacy Policy clause 4.1 lists it with everything else we hold about a business and its team, clause 7.1 states the purpose in Privacy Act terms, and clause 12.1a gives the period: thirteen months, then it is deleted.
You do not have to go looking for any of this. It is written out in Glo, under Settings, in a panel called "What Glo records about your use of it", which also shows you whether it is currently switched on for your account.
5.2 The advertising tags our marketing pages may carry, and where they are not
We advertise Glo to businesses, and our public marketing pages may carry advertising tags from Meta and Google. This policy covers those tags from 7 September 2026. Section 9 commits us to updating this page before a change like that goes live rather than after, and this section is that commitment being kept.
Which pages. Our home page at www.welcomeglo.com, and nothing else. If we ever add another marketing page, a landing page or a comparison page, it joins that list and this section is updated first.
Which pages they are not on, and this is the half that matters most. A booking page, a tracking page, a public invoice, a public quote and an unsubscribe page carry no advertising tag, no code from another company and nothing embedded from another company's site. Neither do these legal pages, which are where somebody comes to read what we do with their information, and loading an advertising tag while they read it would be its own answer. Neither does any part of the signed-in dashboard. If a business sent you a link, you have never been on a Glo page carrying one of these tags, and you never will be.
What the tags are. Two of them, a Meta pixel and a Google Ads tag. Where we use them, they tell Meta and Google that a browser opened our marketing page, and whether one of their advertisements is what brought it there. That is how a small business finds out whether the money it spends on advertising is doing anything.
What they set on your device. Where they run, each of them sets cookies of
its own on welcomeglo.com, Meta's _fbp among them, to recognise the
same browser if it comes back. They are not strictly necessary and we are not
going to describe them as if they were. Nothing on the page breaks without
them. The exact set is Meta's decision and Google's decision rather than ours,
and each publishes its own list; what is ours to say is which pages they may run
on, which is the paragraph above.
What never goes to them, and this is the part we do control. Nothing about a business's clients ever reaches an advertising network. We upload no customer list, we import no offline conversions, and we send Meta and Google nothing about a booking, a job, an invoice, a quote or a client. The tags do not run on the pages that information is on, and there is no other road from our systems to theirs. The dashboard measurement in section 5.1 is not shared with them either: it needs a sign-in, the tags need a marketing page, and the two never meet.
Meta and Google are our subprocessors for what these tags collect on our marketing pages, and our Subprocessors page sets out what that means and where the information goes. Section 8 explains why there is still no consent banner, and it does not get there by calling these cookies necessary, because they are not.
6. When another company is involved
On the pages in section 5 there are two of these, and they are not the same shape as each other. One takes you to somebody else's website. The other happens while you are still on ours. There is a third case on our marketing pages, the advertising tags they may carry, and section 5.2 sets that out in full rather than this section repeating it.
6.1 Where we hand you over to another company's website
Paying by card. Where you pay by card, the payment runs through Stripe. There are two separate directions a card payment can go in Glo and they are unrelated to each other: a customer paying the business they booked with, where the money goes to that business's own Stripe account and never to us, and a business paying us for their Glo subscription. Both of them work the same way here.
Paying is a full page redirect to Stripe's own checkout page on Stripe's own domain. Stripe will set its own cookies there, under Stripe's privacy policy, and we cannot see them. When you come back, you are back on our site. We chose the full redirect partly for this reason: it means Stripe's code never runs on a Glo page, and Glo never sees your card number. What Stripe receives is set out on our Subprocessors page.
6.2 Where your browser talks to another company while you are still on our page
Address autocomplete. This is the one case where another company is involved without you going anywhere, and we prefer to say so plainly rather than let the heading above cover it.
Address autocomplete is switched on. When you type into an address box on a Glo page, whether that is a public booking form or an address field in a business's dashboard, what you type is sent by your own browser to Google's Places service, directly, while you are still on our page, so that Google can send back a list of matching addresses for you to pick from. Because the request comes from your browser rather than from our server, Google receives the characters you typed, the address you pick, and the ordinary technical details of any web request including your IP address.
What goes to Google is narrow, and the edges of it are worth setting out. The request carries what you have typed into the address box, a short-lived random reference that ties one burst of typing together, which section 7 describes, and a fixed setting telling Google to look in Australia. It carries nothing else: not your name, not your mobile number, not your email address, and nothing else about the booking. It is sent only while you are actually typing in an address box, and at no other moment on any Glo page.
On these pages we use Google for that one thing and nothing more. There is no map on any of them. We do not ask Google to turn an address into map coordinates, we do not use Google for directions, routes or arrival times, and nothing on any of these pages asks your device for your location or follows where you are. If any of that ever changes, this page is updated before it does. Any Google advertising tag on our marketing pages is a separate thing in a separate place, it is section 5.2, and it is not this.
We also deliberately do not load Google's map library, so no Google script runs on these pages and Google sets no cookie on them. But Google does see the address as you type it, and Google is overseas. Google is one of our subprocessors, and our Privacy Policy and our Subprocessors page set out what that means and where the information goes.
6.3 Where we send you elsewhere
Where we link out to another website, or where we provide an integration that connects Glo to a service you have chosen, that other service's cookie policy applies to that service and not this one.
7. Local storage and similar technologies
On the pages in section 5, the dashboard, the pages a business's clients open and these legal pages, Glo does not use local storage, session storage, IndexedDB, tracking pixels or fingerprinting, and nothing writes anything to your device except the four cookies in section 3. Those four are the whole of it. Our marketing pages are the exception, and section 5.2 says what the advertising tags they may carry set.
One word in that sentence needs care, because it has two meanings. A "web beacon" usually means a tiny invisible image loaded from another company's server in order to follow you. There is none of that on any page a business's client opens, on these legal pages or in the dashboard, and there never has been. An advertising tag of the kind in section 5.2 is exactly that sort of thing, which is the reason it is kept off those pages and named plainly where it is. Browsers also have a feature of their own, confusingly named, for sending a short message back to the site you are already on as you leave a page. The dashboard measurement in section 5.1 uses it, to reach Glo's own servers and nobody else's. It writes nothing to your device, it loads no image, and it exists on no page a client of a business can reach. We would rather name that than let the word do quiet work.
One thing worth naming so the list above is exact. When you use address autocomplete, your browser generates a random reference for that one burst of typing and sends it to Google with the request, which is how Google groups the requests together for billing. It is a fresh random value every time, it identifies nothing about you, it is held in the page's memory and never written to your device, and it is gone the moment you finish the address.
Your browser will keep an ordinary cache of images, fonts and code so pages load faster on your second visit. That is standard browser behaviour on every website and is not something we set or read.
8. Why there is no cookie banner
You have not been shown a cookie banner, and that is on purpose rather than an oversight.
8.1 Australia has no cookie consent law. There is no Australian equivalent of the European Union's ePrivacy rule, the one that produced the click-through banner on so many websites. In Australia, a cookie that carries personal information is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles, which require us to tell you what we collect and what we do with it. That is a disclosure obligation, and this page and our Privacy Policy are how we meet it. It is not a consent obligation.
8.2 The four cookies in section 3 are strictly necessary anyway. Even under the European rules, consent is not required for a cookie that is strictly necessary to provide a service you have explicitly asked for. Keeping you signed in is strictly necessary for signing in. Carrying your answers between the steps of a booking form is strictly necessary for a booking form. Sending you back to the right page after you sign in, and protecting that sign-in from another website, are both part of signing in. None of them would need a consent click even in Europe.
One qualification. The booking draft cookie also carries the identifier described in section 3.2, which lets a booking page offer you the vehicle and the addresses you used last time. That part is a convenience rather than a necessity. The form works perfectly without it: it simply starts from a blank vehicle and a blank address. It rides along inside a cookie the form needs in any event, it is written only after you have opened a link sent to your own email address, and dropping it would not remove the cookie or the need for the cookie. If you would rather it were not there, clearing this site's cookies in your browser removes it, and it expires by itself within two hours in any event.
A second qualification, and it is a larger one than the first. The advertising tags described in section 5.2 set cookies that are not strictly necessary. Nothing on the page breaks without them, so the paragraph above does not cover them and we are not going to stretch it until it does. The answer for those cookies is 8.1 and 8.3 instead, and nothing else: Australia imposes disclosure rather than consent, section 5.2 is that disclosure, and the European rule that would require a click is written as a targeting test that Glo does not meet. If we ever offer or advertise Glo where consent is required, those pages get a real consent request before the tags run, not after. None of this touches the pages in 1.2. The tags are not on them, so there is nothing on a booking page or a tracking page for a banner to ask you about.
8.3 We are not offering the Service in the EU or the UK. Glo is offered to businesses in Australia. Our prices are in Australian dollars, our times are Australian, and we do not target, market to or offer the Service to people in the European Union, the European Economic Area or the United Kingdom, and we do not monitor their behaviour. Those laws are written as a targeting test, not a visitor test, so a person happening to open a page from overseas does not change the answer.
That sentence is doing more work than it used to, and we would rather write that down than leave you to find it. 8.2 rests the whole answer for the advertising cookies on 8.1 and this clause and nothing else. The tags described in section 5.2 are able to recognise a browser that has been on other sites, which sits closer to the monitoring limb of those laws than anything else on a Glo page. Our position is unchanged, and it is worth stating on its own rather than leaving it inside the paragraph above: we buy our advertising to reach businesses in Australia, we are not targeting Europe or the United Kingdom with any of it, and we are not looking for customers there. Our Privacy Policy clause 17.2 sets out what we think that means under the European rules and what would change it. If it ever stops being true, those pages get a real consent request before the tags run, not after, which is the commitment already made at the end of 8.2.
8.4 A banner would make it worse, not better. A booking form that a customer fills in on their phone is designed to remove every unnecessary step. Adding a consent box to click, for cookies that the page cannot work without, would add friction and teach people to dismiss consent dialogs without reading them. A banner that asks permission for something that cannot be declined without breaking the page is not a real choice. That argument is about the four cookies in section 3 and it does not carry over to the advertising cookies, which can be declined without breaking anything. Their answer is the qualification in 8.2.
If we ever do need consent, you will get a real choice, not a pre-ticked box.
9. What would change this
We are stating a position, so we should state what would move us off it. We will update this policy, and consider whether consent is required, before any of the following ships:
- Analytics. Adding any analytics or page-measurement tool. This one has happened, and this page was updated before it went live rather than after. On 6 September 2026 we began measuring which parts of the signed-in dashboard get used. Section 5.1 says what it is. It set no new cookie, added no third-party script, and does not run on any page a business's client can reach, so items 2, 4 and 6 below were not triggered by it and the cookie list in section 3 is unchanged.
- An advertising or retargeting pixel, including a plain image beacon. This one has been triggered, and this update is us keeping the promise: the page was changed before anything went live, not after. Our public marketing pages may carry a Meta pixel and a Google Ads tag, so that we can advertise Glo to businesses. Section 5.2 says which pages they may run on, which pages they will never be on, what they set and what they never receive. Items 4 and 6 below are triggered along with it on those pages only, and section 5.2 is the disclosure they call for. The four cookies in section 3 are unchanged, nothing on a page a business's client opens changes at all, and section 8 sets out why there is still no banner without pretending these new cookies are necessary.
- A session recorder or heatmap tool.
- Any third-party script or tracking cookie, including a chat widget or support tool that sets one.
- Offering the Service to people in the European Union, the EEA or the United Kingdom, or advertising there, or adding a currency or language selector aimed at those markets.
- Any new cookie or local storage we set ourselves that is not strictly necessary.
- A sign-in method that adds cookies of its own, such as signing in with a third-party account.
Our commitment is that this page is updated first, before the change goes live, not afterwards.
10. Controlling cookies in your browser
You are in charge of the cookies on your own device. Every major browser lets you see what is stored, delete it, and block more from being set. The controls are usually under Settings, then Privacy, then Cookies and site data. Browsers change their menus often, so the browser's own help page is the most reliable guide: Chrome, Safari, Firefox, Edge and Brave all publish one.
You can also browse in a private or incognito window, which discards cookies when you close it.
What happens if you block ours.
| If you block or delete | What happens |
|---|---|
| The session cookie | You cannot sign in to Glo. You can reach the sign-in page and enter your details, but the next page will not know who you are, so you will be sent back to sign in again. There is no way around this |
| The booking draft cookie | The booking form will not carry your answers between steps. In practice this means the form loses what you typed on the screen before, and you may not be able to complete a booking |
| The sign-in housekeeping cookies | Sign-in still works, but you may land on the dashboard rather than on the page you were trying to reach |
| Third-party cookies only | Nothing changes on Glo. All four cookies in section 3 are first party, so blocking third-party cookies does not affect them at all. Our advertising tags are first party by domain as well, so this does not remove what they set on our marketing pages either: the row below is the one for those |
| The cookies our advertising tags set | Nothing on Glo stops working. They are set on our marketing pages only, they do nothing for you, and clearing or blocking them costs you nothing at all. Section 5.2 says what they are |
| All cookies, then clear them | You are signed out of Glo on that device, and an unfinished booking is lost. Other devices you are signed in on are not affected, because each device holds its own session. Nothing else is lost: bookings, invoices and records already saved live in our database, not in a cookie |
"Do Not Track" and Global Privacy Control. Both signals exist to stop a site sharing what you do with other companies, or building a profile of you to sell or to advertise against. On the pages in section 5 we do none of that, for anybody, signed in or not: no third-party tracker, no advertising network, no sale or sharing of personal information, and nothing at all measured on the pages a business's clients use. So on those pages there is nothing for either signal to switch off.
Our public marketing pages are the exception, and we would rather say so than let the paragraph above quietly cover them. The advertising tags in section 5.2 are another company's code, so what each of them does with either signal is Meta's answer and Google's answer rather than ours. What is ours to say is where they may run, which is our marketing pages and nowhere else: not on a booking page, not on a tracking page, not on an invoice or a quote, not on these legal pages and not in the dashboard. The browser controls above apply to what those tags set in the ordinary way, and a private window discards it when you close it.
To be exact rather than reassuring, since the honest answer is not simply "no tracking": the dashboard measurement in section 5.1 is not covered by those signals and is not turned off by them. It records which screens a subscribing business opens in its own account, it is the record-keeping a company does about its own product, and it is neither shared nor sold.
If that is not something you want recorded, ask us and we will switch it off for your account, usually the same day, no reason needed and nothing else changes. Section 5.1 explains why that is an email rather than a button. The contact details are in section 12, and Privacy Policy section 13 covers your rights over what we already hold.
11. Changes to this policy
We will keep this page accurate. If we change what cookies we set, we will update this page, raise the version number at the top and change the effective date.
If a change is material, meaning we add a cookie that is not strictly necessary, or we start using any of the technologies listed in section 9, we will say so clearly on this page and, where the change affects businesses with an account, we will email the account address at least 30 days before it takes effect, telling you in plain English what is changing and why. You can cancel your subscription before the change takes effect. We will not rely on "your continued use means you agree" as the only way of telling you something important changed.
A change that takes nothing away from you takes effect as soon as we publish it. Correcting an error, making something clearer, adding a protection, and anything the law requires. It still gets a new version number and effective date, and we still say what changed.
The thirty days above is for a change that takes something away, which on this page means a new cookie that is not strictly necessary, or starting to use one of the technologies in section 9. Where it is not obvious which kind a change is, we treat it as the second kind. That call is not ours to make in our own favour.
This version is a material change, and it meets both halves of the definition above rather than one. It adds cookies that are not strictly necessary, and it starts one of the technologies listed in section 9. What that means in practice: this page is the notice, and it covers the advertising tags described in section 5.2. If you would rather not be here for it, you can cancel your subscription, and clause A9.6 of our Refunds and Cancellations page refunds the unused part of anything you have already paid, whether or not our email reached you.
12. Contact us
If you have a question about cookies, or about anything else to do with your personal information, write to us and a person will answer.
Email: hello@welcomeglo.com Post: Connor Wu trading as Glo, Unit B14, 161 Arthur Street, Homebush West NSW 2140 ABN: 23 380 080 435
We will acknowledge a complaint within 5 business days and respond in writing within 30 days. If we need longer we will tell you before the 30 days is up, explain why, and give you a date.
One thing to say plainly: hello@welcomeglo.com is our support address and our privacy address. It is one inbox, read by a person, and it is never a no-reply address.
If you are a customer and your question is about a job, the business you booked with is the right first stop, because the booking is between you and them. If your question is about how Glo itself handles your information, or you are not getting an answer, come to us.
You can also complain to the Office of the Australian Information Commissioner. They are the independent regulator, they are free, and they generally expect you to come to us first and give us 30 days.
- Website: oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001
We would rather hear from you first so we can fix it. Our full complaints process is in our Privacy Policy.
Questions about this document?
Email hello@welcomeglo.com.