Cookie policy
Rev. 26 August 2026 (third revision)
Where this page stands today
The tools described here are loaded through a tag container, and this page is written to be accurate on the day one is switched on rather than to catch up afterwards. If a tool is named below, treat it as running.
The part that is not about timing is the split, so here it is first. Three of the four things on this page run for everyone who visits — Google Analytics, the Meta pixel for Facebook and Instagram, and the visitor identification service retention.com. There is no box to tick for any of those. Session recording is the one that is different: it does not load at all unless you allow it, and the banner on your first visit is where that is asked.
The Privacy choices link at the bottom of every page reopens that question whenever you like, whatever you answered the first time. The same panel lists the three that do not wait, each with the thing that does stop it — including a link that opts you out of visitor identification on every site that uses it, not only this one.
The short version
This site uses measurement and advertising tools: Google Analytics, a Meta (Facebook and Instagram) pixel, Microsoft Clarity, and a visitor identification service called retention.com.
That is worth being blunt about. These tools set cookies, they use identifiers that persist between visits, some of them report your visit to a company that also sees you on thousands of other sites, one of them records what happens on the screen, and one of them tries to work out who you are.
All of them are on from the moment you arrive except one. Microsoft Clarity, the session recorder, is the single thing the banner asks about, and it loads only if you say yes. Analytics, the Meta pixel and retention.com do not wait for an answer — the sections below say what stops each of them instead.
They exist so a small studio can tell whether an Instagram post filled a class. That is a fair thing to want. It is still your visit, so the rest of this page says what each one does in plain terms, what we have ruled out, and what you can do about it.
Two things do not change, whatever you answer and whether or not you are asked. Card details are never on this site — payment happens on Stripe. And the pages where you actually type something that matters — the booking flow with the waiver signature, a child’s name and an emergency contact, and the careers form with your home address — are kept out of session recording and visitor identification entirely, and none of what you type is sent to any of these companies.
What a cookie is
A cookie is a small file a website asks your browser to keep and hand back on your next visit. It is how a site remembers something about you between pages. Some cookies are needed for a site to work at all; others exist to count visitors, or to recognise you again, or to build a profile for advertising.
The same rules in this policy apply to the other ways a site can store or read things in your browser — local storage, device and browser characteristics, an advertising identifier. Calling those something other than cookies would not change what they do.
Cookies we set ourselves
One, and only staff ever receive it.
When Monica or Carolina signs in to the admin area to post a class or check a roster, we set a cookie called sf_admin that keeps them signed in for twelve hours. It holds a signed session token and nothing else — no name, no email, no browsing history. It is marked so that no script on the page can read it, and it is deleted when they sign out.
If you are booking a class or reading this page, you will never be issued this cookie. Every other cookie described below is set by one of the companies named, not by us.
Measuring how the site is doing
We want to know basic things: how many people reached the site, where they came from, which pages they read, and how many finished a booking.
Google Analytics does most of that. It sets first-party cookies — names beginning _ga — that hold a randomly generated number for your browser. That number is how it tells a returning visitor from a new one and stitches your pages into one visit. It does not contain your name or your email. It does mean Google, which sees an enormous share of the web, receives a record of your visit to this site.
Vercel Analytics and Speed Insights measure page views and loading speed without cookies. They do not identify you and do not follow you to other websites. They were here before any of the rest and they stay.
Google Tag Manager is the loader that all of this is configured through. Tag Manager itself sets no cookies; the tags inside it do.
None of it runs on the admin area.
Session recording, and where it is switched off
Before anything else about this one: it does not load unless you allow it. Say no on the banner, or leave it off in Privacy choices, and nothing is ever requested from Microsoft — not a script, not a cookie, not a cookieless version of either.
Microsoft Clarity records how pages are used: where the pointer moved, what was clicked, how far you scrolled, and a replay of the page as it appeared. It is a video-like reconstruction, not a recording of your camera or your microphone. It sets its own cookies — _clck and _clsk — to tie the parts of one visit together, and the recordings sit on Microsoft’s systems under Microsoft’s privacy statement.
This is the tool on the list with the most obvious way to go wrong, so here is the line we have drawn. Clarity does not run on the booking flow, the careers form, or the contact form. Those are the pages where you type a signature on a liability waiver, a child’s name and age, an emergency contact’s phone number, your home address, or a message meant for us. A recording of somebody signing a waiver is not something to leave to a default setting, so those pages are excluded from recording rather than masked and hoped about.
On the pages it does run on — the home page, the class list, the schedule, the blog — the only thing there is to type is an email address in the "tell me when a class is posted" box, and text you type is masked. If you ever find a field on a recorded page that takes more than that, tell us through the contact page and we will treat it as a fault.
Advertising
STEPFIT advertises on Meta’s platforms — Facebook and Instagram — and that needs a tag on this site to work the way it is sold.
The Meta pixel reports actions on this site back to Meta: that a page was viewed, that a booking was completed. It sets a first-party cookie called _fbp, and Meta can match what it receives against a Facebook or Instagram account. If you have ever wondered why a studio you looked at once starts appearing in your feed, this is the mechanism.
What the pixel has, and what the measurement tools above do not, is cross-site reach. It is useful to us because it is useful to Meta, and it is useful to Meta because Meta sees you in a great many other places too.
This one is not behind the banner. It loads on your first page view, before you have answered anything, and that is a decision rather than an oversight. STEPFIT buys advertising on Instagram and Facebook, and a pixel that fires only for the people who agreed to it cannot tell the studio whether those adverts brought anyone in — which is the entire reason for spending the money. So the honest arrangement is this one: the pixel runs, and this page says so on the same line as its name instead of leaving you to find out.
The banner would not be the way to stop it even if it offered to. The controls at the end of this page would be — browser tracking protection and a blocker stop the Meta pixel outright, and we would rather point you at something that works than at a switch that flatters us.
To be precise about where they run, because the previous section drew a line and this is the exception to it: the pixel does count a completed booking, so a "booking finished" event reaches Meta. What reaches Meta is that a booking happened, not what was in it. Your name, email, phone, emergency contact, the minor’s details and the signature are not passed to any advertising tool, and the pages carrying those fields are still excluded from session recording and from visitor identification.
Working out who visited
retention.com is different from everything above and deserves its own heading rather than a line in a list.
It used to be the second thing the banner asked about. It is not any more. Since 26 August 2026 it loads on your first page view, before you have answered anything, the same way the Meta pixel does — that is a decision the studio made, and this page says so on the same line as the name rather than leaving you to find out. What replaced the switch is three real ways out, further down this section, and they are better than the switch was.
Analytics counts visits. This service tries to put a name to one. It takes signals from your visit and matches them against a database built from many other sites and sources, and where it finds a match it can tell us that a particular person — with a name and an email address — was on this site, even though you never filled anything in here.
That is what it is for and there is no gentler way to describe it. It runs on the public marketing pages only: never on the booking flow, never on the careers form, never on the admin area. That exclusion is not conditional on anything and does not depend on you answering the banner.
Where it finds a match, that name and email address is sent to us and we keep it, marked as having come from identification rather than from you. Those addresses may be added to our marketing list and used for email from STEPFIT. Nothing has been sent to them yet — that is where it stands as this page goes up, not a promise it will stay there — and anything sent carries a postal address for the studio and an unsubscribe link that works on one click. The privacy policy sets out the rest: what is stored, how long, and how to have it deleted. This page is about what is on your device; that record is on ours.
Now the three ways out, smallest first. One: if you are ever sent something with an unsubscribe link, clicking it removes you and nothing else is needed. Two: ask through the contact page and we delete the record we hold and keep a note that stops the same address being added back — the note is checked when a contact arrives, not only when a message would go out, so the service offering us your address again cannot undo it.
Three, and this is the one that stops the matching itself rather than what we do afterwards: retention.com runs its own opt-out, and it covers every site that uses them, not only this one. It is at app.retention.com/optout and we would rather point you at it than at anything we could have built here.
Two more things that interfere with it directly, whatever you do about the above. If your browser sends a Global Privacy Control signal, this service is not loaded at all — that is checked before anything runs and needs no click from you. And the browser controls at the bottom of this page work on it too: it depends on exactly the kind of tracking that browser privacy protections and tracker blockers are built to interfere with.
Things you might expect to be cookies here, and are not
Some of these are choices made specifically to keep this page shorter:
- Language. English and Spanish are separate addresses — /classes and /es/classes — so your language is usually just the link you followed. If you use the language switch, that choice is remembered by your own browser, in local storage, on your device. It never reaches us, it is not a cookie, and it tells us nothing about you. It only decides which of the two addresses a link points at; the page you asked for is always the page you get.
- Club mode. The dark high-contrast display setting is remembered by your own browser, in local storage, on your device. It never reaches us and it tells us nothing about you.
- Your answer to the banner. Also local storage, on your device, and deliberately not a cookie — a site that set its own first cookie in order to ask whether it may set cookies would have started by doing the thing it was asking about. It records the one thing you were asked about and when you answered. It never reaches us, and clearing your browser storage means you are asked again.
- Booking. A booking is submitted and confirmed by email. There is no account, no login, and no session to keep for a customer. Nothing on the booking path depends on a cookie.
- Fonts. The typefaces are served from this site rather than from a font network, so loading a page does not announce your visit to anyone else.
Other people’s cookies, on other people’s pages
Two parts of booking and finding us hand you to another company, and their cookies are theirs, not ours.
Paying. Card payment happens on Stripe’s own hosted checkout page, at a stripe.com address. Stripe sets the cookies it needs there to process the payment and to detect fraud, under Stripe’s privacy policy at stripe.com/privacy. Your card details are never entered on getstepfit.com.
The map. The Tampa page can show a Google map of the venue, and it does not load until you press the button that loads it. Press it and you are loading a piece of Google, which may set cookies at that point. Never press it and nothing is requested from Google and nothing is stored. The address and a plain link to directions are on the page either way, so you never have to load the map to find us.
Links out to Instagram or anywhere else behave the same way: once you are on their site, their policy applies, not this one.
About the banner
There is a banner on your first visit. It asks about one thing out of the four on this page, and here is exactly what it does and does not do.
Florida does not have a law requiring a site to get your permission before setting a cookie, and the Florida Digital Bill of Rights — which does create rights around targeted advertising and the sale of personal information — applies to companies far larger than this one. So the banner is a choice STEPFIT made rather than a legal formality, and it was made narrow on purpose.
What it holds back, it really holds back. Say no to session recording and that tag is never loaded: no request leaves your browser for Microsoft, so there is nothing for it to see and no cookie for it to set. Not loaded and asked to behave. Not loaded without a cookie. Not requested at all. Both answers are one click, on two buttons the same size, and refusing is not the longer road.
What it does not cover is measurement, advertising and visitor identification, which run either way. The banner says so on its face, in the same two sentences as everything else, because a switch that appears to turn off a tag already running is worse than no switch — it spends your attention and returns nothing. The Privacy choices panel lists those three as well, each with what does stop it, and it carries the retention.com opt-out as a link you can click.
If your browser sends a Global Privacy Control signal, that counts as a no to the thing the banner asks about, and you are not asked again. It also switches off visitor identification, which the banner does not ask about — the signal is a refusal you have already made, so there is nothing for it to wait for. It does not reach the measurement and advertising tags.
The booking-page exclusions above are not conditional on any of that. They apply whether or not anything is ever asked.
Controlling this yourself
Every browser lets you block or delete cookies and clear local storage, usually under Settings, then Privacy. Blocking all of it will not stop you booking a class — nothing on the booking path depends on a cookie.
Blocking third-party trackers does more than deleting cookies does, and most browsers now have it built in. Safari and Firefox do it by default. Chrome has settings for it. A tracker blocker extension will stop most of what is described on this page, and we would rather say so than pretend the choice is only ours to give.
You can opt out of Google Analytics across every site with Google’s own browser add-on at tools.google.com/dlpage/gaoptout, and you can control ad personalisation in your Google account and in your Facebook or Instagram settings.
For visitor identification specifically, retention.com runs an opt-out of its own that applies to every site using them: app.retention.com/optout. That is the most complete answer on this page for that one, because it stops the matching rather than stopping what we do with a match.
Two honest notes. "Do Not Track" is a browser setting almost nobody acts on, and we do not act on it either. Global Privacy Control we do act on, automatically: if your browser sends it, session recording and visitor identification are both switched off before anything loads and no banner appears to pester you about it. That is unchanged by identification no longer waiting for an answer — a GPC signal is a refusal already given, not a question left unanswered. It does not stop measurement or advertising — for those, the browser controls and the blocker in the paragraphs above are what work.
Questions and changes
The privacy policy covers what we collect when you book, how long we keep it, and how to ask for a copy or a deletion. This page covers what is stored on, or read from, your device.
If we change this policy we will update the date at the top. If we add a tool that is not on this page, this page changes before it goes live, not after.