Cookie Policy
Cademy runs cademy.io, the minisites of the educators who use Cademy (for example acme-training.cademy.io), the checkout, and the course lists and checkouts that educators embed on their own websites. This page lists every cookie and similar storage those pages can use, who sets it, and when.
Your choice
Nothing beyond the strictly necessary cookies is set until you choose. On the marketplace and on an educator's minisite or checkout, the cookie banner asks once and your answer is kept for 12 months in the cademy_consent cookie for that site. You can change or withdraw it at any time from the Cookie Settings link in the footer of every page, or right here:
An educator's course list or checkout embedded on the educator's own website never shows its own banner. It follows the choice you made on that website's cookie banner and stays off if that website has none.
Categories
- Strictly Necessary. Sign-in, checkout, fraud prevention and your consent choice itself. Always on; the site cannot work without them.
- Analytics. Measures visits and which pages are read, for Cademy on the marketplace and for the educator on their own pages. Off until you allow it.
- Marketing. Lets advertising tags measure campaigns and show relevant ads on other sites. Off until you allow it.
Cookies we use
"The educator" means the organisation whose minisite, checkout or embed you are using. Educators choose which of their own tools to connect; the categories and the rules for when a tool may load are Cademy's and are the same for every educator.
| Name | Set by | Scope and lifetime | Where | Category | Purpose |
|---|---|---|---|---|---|
PRODUCTION_ACCESS_TOKEN, PRODUCTION_ID_TOKEN, PRODUCTION_REFRESH_TOKEN | Cademy | .cademy.io, 30 days | Every page, when signed in | Necessary | Keeps you signed in across Cademy hosts. |
cademy_consent | Cademy | This site only, 12 months | Marketplace, minisites, checkout | Necessary | Records your cookie choice: an id, the policy version, the time and the Analytics and Marketing flags. Set per site, so a choice on one educator’s site never applies to another. |
__stripe_mid, __stripe_sid | Stripe | .cademy.io, 1 year and 30 minutes | Checkout | Necessary | Fraud prevention and payment processing. |
_GRECAPTCHA | Google reCAPTCHA | www.google.com, 6 months | Forms, checkout | Necessary | Tells real visitors apart from bots. |
Sentry (no cookie) | Cademy | Not applicable | Every page | Necessary | Error reporting. Session replay only after Analytics consent. |
_gcl_au and Google Ads / LinkedIn Insight cookies | Cademy (Google Tag Manager) | .cademy.io, 90 days for _gcl_au; set by the vendor for the rest | Marketplace only | Marketing | Measures Cademy’s own advertising. Loads only after a Marketing decision; never on minisites, checkout or embeds. |
ph_* (PostHog, via e.cademy.co.uk) | Cademy | Browser storage on the marketplace, persistent | Marketplace, checkout | Analytics | Product analytics and session replay. Kept in memory with no replay until Analytics consent; inputs are masked when replay runs. |
_ga, _ga_* | The educator’s Google Analytics 4 | .cademy.io, 2 years | Minisites, checkout, embeds | Analytics | Measures visits to the educator’s pages. Loads only after Analytics consent (in an embed, the host website’s consent). |
Educator Google Tag Manager container | The educator | Depends on the tags in the container | Minisites, checkout, embeds | Marketing | Loads the educator’s own tags. Loads only after a decision that grants at least one category, with your choice already passed to it; never after Reject All. |
_fbp, _fbc | The educator’s Meta Pixel | .cademy.io, 90 days | Minisites, checkout, embeds | Marketing | Lets the educator measure and target ads. Loads only after Marketing consent and is removed when you withdraw it. Meta sets it for cademy.io as a whole, so it is visible across minisites once you consent on one. |
Enhanced conversions (no cookie) | The educator (opt-in) | Not applicable | Checkout | Marketing | Sends a hashed version of your checkout email to Google Ads with purchase events. Only when Marketing is granted. |
cademyUtms | Cademy | Browser storage, no expiry | Marketplace, minisites, checkout | Analytics | Remembers campaign parameters for attribution. Kept in memory until Analytics consent; never written on educators’ own websites. |
How we record your choice
Your answer lives in the cademy_consent cookie on your device. It holds a random id, the policy version you agreed to, the time, and your Analytics and Marketing flags. Cademy's servers note those same values on their request logs, which are kept for 90 days, so we can show that consent was asked for and what was answered. No IP address or account is stored with it. If this policy changes in a way that matters, the version number above changes and the banner asks again.
Questions
Write to privacy@cademy.io. Our Privacy Policy explains how we handle personal data more generally.