Viya Marketing

Cookies Policy

What this page covers

This platform is operated by THE GREAT LEARNING TREE PTY LTD (ABN 28 145 031 563). This page lists the cookies we set, what each is for, how long it lasts, and how to remove them.

It sits alongside our Privacy Policy at /privacy, which explains what personal information we hold more broadly and who we share it with.

We set no cookies until you sign in

Browsing our public pages — the home page, this one, the Terms of Service, the Privacy Policy and the data deletion instructions — sets no cookies at all. Nothing is stored on your device unless you sign in or start connecting a social account.

There is no cookie banner on this site because, until you sign in, there is nothing to consent to.

We set no analytics, advertising or tracking cookies

We do not run analytics, advertising or cross-site tracking cookies. There is no advertising pixel, tag manager or third-party measurement script on this site.

Meta appears in our Privacy Policy as a sub-processor because we publish content to your Facebook or Instagram Page on your behalf through Meta's API. That is a server-to-server connection. It does not place a Meta advertising cookie in your browser through this site.

Cookies we set when you sign in

These are set by us, are not readable by JavaScript in your browser, are sent only to this site, and travel only over HTTPS.

  • cc_uid — records which signed-in account this browser is seated as, so switching accounts cannot show you a page cached for someone else. Lasts 7 days.
  • cc_tenant — remembers which workspace you are working in, if you belong to more than one. It selects; it never grants access, and your real membership is re-checked on every request. Lasts 7 days.
  • cc_venue — remembers which of your venues you are viewing in the client portal, if you have more than one. It is the only one here you can lose without anything breaking; we fall back to your first venue. Lasts 12 months.

Cookies that exist only while you connect a social account

Connecting a Facebook, Instagram, LinkedIn or Google account sends you to that provider and back. Two short-lived cookies make that round trip safe. Both expire after ten minutes and are deleted as soon as the step finishes.

  • cc_oauth_nonce — a one-time value created when the connection starts and checked when the provider sends you back, so another site cannot forge that return and attach an account you did not authorise.
  • cc_oauth_page_pick — carries the provider's authorisation to the screen where you choose which Page to connect. To be exact rather than reassuring: this one holds an access token. It is encrypted with AES-256-GCM, is not readable by JavaScript, cannot be replayed once used, and is deleted the moment you choose a Page or leave the step.

Sign-in cookies set by Supabase

We use Supabase for authentication. When you sign in through the emailed link, its library sets cookies named in the pattern sb-<project>-auth-token, sometimes split across numbered parts, plus a short-lived verifier that completes the link securely.

These hold your session so you stay signed in. They are marked Secure, so they travel only over HTTPS. Being accurate about the rest matters too: unlike our own cookies above, they are readable by JavaScript running on this site, and they are set with a long lifetime that the Supabase library fixes and we cannot shorten. Signing out removes them.

Fonts and other requests

Our pages load a typeface from Google Fonts. That is a request for a font file and sets no cookie on this site. Blocking that domain in your browser changes only how the page looks.

Removing cookies, and what happens if you do

You can delete cookies for this site at any time in your browser settings, and you can block them entirely.

Removing the sign-in cookies signs you out; you can sign back in with a new emailed link. Removing the workspace or venue cookies only means we stop remembering which one you had open. Blocking cookies altogether will prevent you signing in, because there is no other way to keep you signed in between pages.

To see what we hold about you or have it deleted, the instructions are at /data-deletion and you can reach us at hello@viyamarketing.com.au.