Cookie & Tracking Notice.
Last updated: 30 August 2026
This notice explains what we store on your device and what we send to third parties. It supplements our Privacy Policy. It covers two quite different things, and the distinction matters: our public marketing website (pitlanehq.com.au), where we run advertising and analytics tools; and the product you log into, where we load none. The product is not free of advertising data flows, though — section 2A covers what does happen, which is on our servers rather than through a cookie.
1. The short version
- Inside the product, cookies exist to keep you logged in and to remember your settings. No advertising or analytics tag is loaded in the product, and none of those cookies is read by an advertising network. (The one attribution cookie we do set,
pitlane_ref, is written at sign-up to credit a referral partner and is not read once you are using the product — it is listed below rather than hidden behind this sentence.) - Advertising platforms can still receive data about a workshop's customers from inside the product, though not through a cookie: where a workshop connects its own Google, Meta, Microsoft, TikTok or LinkedIn advertising accounts, or its own Google Analytics 4 property, our servers send conversion events as its customers move through the funnel. Section 2A says exactly what. An earlier version of this notice denied this outright.
- On the marketing website we currently use Google Analytics 4 and the Meta Pixel. Both send data to overseas companies. There is also a flow with no tag and no cookie: if you send us an enquiry, start a trial or subscribe, our servers report that to PitlaneHQ's own Google, Meta and Microsoft advertising accounts, with your email address hashed (and your phone number too, if you gave us one on an enquiry form). Section 3 says exactly what.
- You can block the tracking on the marketing website. Section 5 tells you how, including the browser-level and platform-level controls that work regardless of anything we do. Those controls act on tags in your browser, so they do not reach either of the server-side flows on this page, and the two stop for different reasons. The sends about a workshop's customers (section 2A) stop when the workshop disconnects the platform, when you opt out of that workshop's marketing, or, for conversion events, at the consent gate where it applies. The sends about our own enquirers and subscribers (section 3) are not covered by any of those — no workshop is involved and there is nothing to disconnect, so if you enquire on this website there is nothing you can switch off yourself; the route is to ask us at privacy@pitlanehq.com.au.
- We are honest below about the state of our consent tooling rather than claiming a banner we have not shipped.
2. Cookies in the product (after you log in)
These are strictly necessary — the product cannot work without them. None of them is set by an advertising network, read by one, or sent to one. (That is a statement about these cookies. For the server-side advertising data flow that does exist, see section 2A.)
| Cookie | Purpose | Life |
|---|---|---|
workshop_session / workshop_refresh | Keep you signed in. The session cookie is short-lived and the refresh cookie renews it; both are HttpOnly and Secure, so page scripts cannot read them. Equivalent pairs exist for the admin, customer portal, fleet and affiliate areas. | 4 hours / 7 days |
selected_site | Remembers which of your workshop's locations you are working in. Readable by page scripts, because the site selector needs it. | 1 year |
| Theme preference | Remembers light/dark mode per portal. Readable by page scripts. | 1 year |
| Trusted device | Set only if you choose “remember this device” during two-factor authentication, so you are not challenged on every sign-in. | 14 days |
Connection state (e.g. xero_oauth_state) | Set only while you are connecting a third-party account — accounting, telephony, an advertising account, or single sign-on. It holds a random value that has to come back matching the one the provider returns, which is what stops someone else's account being attached to yours. HttpOnly, scoped to the connection routes it belongs to, and cleared the moment the connection finishes. | 10–30 minutes |
| Cloudflare Turnstile | The bot challenge on our public forms. Set by Cloudflare on its own domain, not by us. | Short session |
pitlane_ref | Set at sign-up only, if you arrived through a referral link, so commission can be attributed to the right partner. It is not used once you are inside the product. | 30 days |
Cross-site request forgery protection generally does not use a cookie — it is done by checking where the request came from. The exception is the connection-state cookie in the row above, which is a forgery check for one specific thing: attaching a third-party account. An earlier version of this notice said we used no such cookie at all, which was wrong in the other direction.
2A. Advertising data sent from inside the product
We set no cookie for this and load nothing into your browser for it, which is why it sits outside the table above. It still belongs in this notice, for two reasons: it is how data about a workshop's customer reaches an advertising platform from inside the product, and the values it forwards include advertising cookies (_fbc, _fbp, _ttp) already set on the page that customer arrived through.
PitlaneHQ has a marketing-attribution feature. A workshop can connect its own advertising accounts — Google Ads, Meta, Microsoft Advertising, its own Google Analytics 4 property, TikTok, LinkedIn — and when it has, our servers report conversions back to them as that workshop's customers move through the funnel: an enquiry made, a quote sent, a quote accepted, an invoice paid. Email addresses and phone numbers are SHA-256 hashed first, and so are names, for every platform that receives them but one. Some things are not, because the receiving platform will not match them hashed: ad click identifiers and the advertising cookie values picked up from the page the customer arrived through; the customer's IP address and browser user-agent, for Meta and TikTok; country and postcode, for Google Ads; and a plain-text first and last name for LinkedIn, in the case where we hold no hashed email or LinkedIn identifier for that person.
There is a second flow on the same footing: where the workshop has separately accepted Google's, Meta's or Microsoft's customer-data terms, hashed contact lists are uploaded to Google Customer Match, Meta Custom Audiences and Microsoft Customer Match to build advertising audiences: customers with an invoice paid in the last 540 days, and customers sent a quote in the last 90 days that has not converted. Google and Meta receive a hashed email and a hashed phone number, each only where we hold it for that customer; Microsoft receives a hashed email and never a phone number, because its list format has no phone field. Connecting the account alone does not turn that on.
Nothing is sent for a workshop that has connected nothing, and no conversion event is sent about a customer who has opted out of marketing. The audience uploads exclude them too, and additionally exclude anyone who has asked to be erased. Coming off a list already uploaded differs by platform: an erasure request tells Google and Meta to remove those identifiers, while Microsoft gets no such instruction — the daily upload replaces the whole list, so the person drops out when the next daily replace runs, and stays in the list Microsoft already holds if that sync stops first. The platform-by-platform field list is on our Sub-processors page. If you are a workshop's customer and want to know whether this is switched on, ask that workshop — it controls the connection, and it is the responsible entity for its own customer records.
3. Tracking on the marketing website
These are not strictly necessary. They exist so we can understand which pages bring us customers and measure our own advertising.
| Tool | What it does | Who receives it |
|---|---|---|
| Google Analytics 4 | Aggregate traffic measurement: pages viewed, referring site, approximate location, device and browser, and whether you submitted a form. Uses a pseudonymous identifier, not your name. | Google LLC, United States |
| Meta Pixel | Measures whether our Facebook and Instagram advertising works, and builds audiences for future advertising. It records pages viewed and form submissions. If you are logged into Facebook or Instagram, Meta can match this activity to your account. That is the most privacy-significant thing on this page and we would rather say it plainly than bury it. | Meta Platforms, Inc., United States |
We do not currently run a tag manager container — the two tags above are loaded directly, so those two are the complete set of tags. (A tag manager is something we could configure, and if we ever do, this notice will be updated before it goes live, because a container can load tags this page does not name.) We do not sell personal information and we do not share it with data brokers. Both tools are listed on our Sub-processors page, and both involve disclosure outside Australia — see the cross-border section of our Privacy Policy.
3.1 Our own advertising conversions (no tag, no cookie)
The table above is the browser side, and it is not the whole picture. When you submit an enquiry or demo request on this website, start a trial, or become a paying subscriber, our servers report that event to PitlaneHQ's own advertising accounts — Google Ads, Meta (via its Conversions API) and Microsoft Advertising — and to our own Google Analytics 4 property. This is us measuring our own advertising. It is mechanically the same kind of server-to-server send as section 2A, but the data is about you as our enquirer, no workshop is involved, and no workshop can switch it off.
What goes: your email address, SHA-256 hashed before it leaves our servers, together with the event (enquiry, trial start, subscription), its value and currency, and the time. Your phone number goes too, hashed, but only for an enquiry made through a form on this website — that is the only one of the three events where we hold one, so the trial and subscription events carry the email alone. Google and Meta also get a reference so they do not count the same event twice; Microsoft does not. Your name, your message and your company do not go, and Google Analytics 4 receives no email address or phone number at all.
What this means for the controls in section 5: they will not stop it. Blocking cookies or installing a tracker blocker acts on tags running in your browser, and none of this runs in your browser. There is no self-service switch for it either. If you would rather we did not, ask us at privacy@pitlanehq.com.au: we do it by hand rather than through a switch in the system, and we will stop sending further events about you. An event already sent cannot be recalled, and we would rather say all of that plainly than let section 5 imply a control it does not have.
4. The honest state of our consent tooling
We do not currently present a cookie consent banner on the marketing website. Analytics and advertising tags load when you visit. We are telling you that rather than describing a control that does not exist.
We think that is a gap and we are closing it: a preference control that lets you accept or reject non-essential tracking before it loads is planned, and this notice will be updated with its arrival date when it ships. In the meantime, the controls in section 5 genuinely work and do not depend on us.
If you would rather not be measured at all while we get there, the simplest options are to use the browser-level opt-outs below, or to contact us at privacy@pitlanehq.com.au.
5. How to turn tracking off
These work whatever we do, which is why we are pointing you at them:
- Block third-party cookies in your browser. Every current browser can do this, and most can block trackers by category. Safari and Firefox block a great deal by default.
- Google Analytics opt-out. Google publishes a browser add-on that stops GA4 measuring you on every site that uses it.
- Meta ad preferences. Your Facebook or Instagram settings include controls over off-platform activity, including the ability to disconnect activity businesses have sent to Meta about you.
- Browser privacy modes and tracker blockers both prevent these tags from loading.
Blocking non-essential tracking does not degrade the marketing website or the product in any way. Blocking the strictly-necessary cookies in section 2 will stop you being able to sign in — those are what keep your session alive.
What these controls do not reach. Every control above acts on something running in your browser. Neither server-side flow on this page runs in your browser, so none of them stops the sends in section 2A (about a workshop's customers) or section 3.1 (about people who enquire with us). For section 2A, ask the workshop — it controls the connection and your marketing opt-out with it. For section 3.1, ask us at privacy@pitlanehq.com.au. We would rather point you at the control that works than list one that does not.
6. Embedded widgets on workshop websites
Workshops can embed our booking and messaging widgets on their own websites through Pitlane Connect.
Correcting an earlier version of this notice: it said the widgets set “no advertising or analytics cookies”. That was wrong. The embed surfaces record an anonymous pageview and set a first-party cookie named pitlane_ev (1 year) so a returning visitor's journey on that one site is counted once rather than twice. It is set on our own domain and is partitioned under CHIPS, meaning the browser scopes it per top-level site — it cannot be used to follow anyone from one workshop's website to another. No advertising cookies are set and the widget loads no Google or Meta tags.
The workshop's own website may run its own tracking, which is the workshop's responsibility and governed by their privacy policy, not this notice.
7. Changes
We will update this notice when we add or remove a tracking technology, and the “Last updated” date will change. If we add a tool that receives personal information about you, it will also appear on the Sub-processors page.
8. Contact
- Privacy: privacy@pitlanehq.com.au
- Phone: 07 4800 9005