Cookie policy
Last updated: 14 August 2026
This website
This marketing site is static and sets no cookies of its own, and carries no advertising network and no cross-site tracking.
It does run two product-analytics tools, which tell us which parts of the site people actually use — where they scroll, where they click, and where a page loses them:
| Tool | What it sets | What it does |
|---|---|---|
| Microsoft Clarity | _clck, _clsk |
Heatmaps and a replay of the visit |
| PostHog | ph_* |
Page views, funnels and a replay of the visit |
Whether we ask you first depends on where you are.
- In the EU, the EEA and the UK — decided from your browser's timezone, so we never have to look your address up — nothing loads until you accept. No request is made to either vendor and no cookie is set while the banner is on screen. Decline and nothing loads, on that visit or any later one.
- Elsewhere they load by default, which is what the law where you are allows, and you can turn them off at any time — see below.
Two ways out that need no banner, honoured everywhere. If your browser sends Global Privacy Control or Do Not Track, we treat that as a no and load nothing. And whatever you choose is remembered in your browser's local storage under viaquo-analytics-consent; clearing your site data resets it, and setting it to denied turns analytics off permanently on this browser.
We do not use either tool for advertising, we do not sell what they record, and neither is joined to a traveller's trip data.
The agency console
The console at your sign-in URL uses only what it needs to work:
| Purpose | What it stores |
|---|---|
| Session | An authentication token identifying your signed-in session |
| Security | A CSRF token, so a third-party site cannot act as you |
| Preferences | Your chosen interface language |
These are strictly necessary: without them you cannot stay signed in or submit a form safely. They are not used for advertising or profiling.
Traveller pages
Day pages, recaps and portal links are opened from a link containing a token. That token is the credential; it is not stored as a cookie. The traveller app stores a sign-in token in local storage so a traveller does not have to sign in on every visit.
Controlling it
You can clear or block browser storage at any time through your browser settings. Blocking it for the console will sign you out and prevent sign-in.
The console and analytics
The console runs the same two tools, under the agency agreement rather than a banner, because its users are named staff of a customer rather than anonymous visitors.
Both are configured to mask the content area. The pages are recorded as layout and interaction — which screen, which button, in what order — and not as data, so traveller names, documents, passport details and message threads are not captured. PostHog additionally records unhandled errors, so we can see that something broke and on which screen.
We identify a console session by its user id, never by email address. See Privacy policy for the full picture.
Changes
If we add analytics or anything else non-essential, we will update this page, and anything that is not strictly necessary will keep asking for consent before it loads.