you.aero Cookie Notice
Operator: JETSONIC TRADING - FZCO
Version: 1.2
Effective date: 2 September 2026
Last updated: 1 September 2026
Contact: team@you.aero
1. Scope
This Cookie Notice explains how JETSONIC TRADING - FZCO uses cookies and similar browser technologies on the public website at you.aero and the closed workspace at app.you.aero.
A cookie is a small value stored by a website in a browser. Local storage and session storage are similar browser technologies but are not automatically sent with every web request. We describe them here because they may store preferences, identifiers or locally saved work.
2. Categories
Strictly necessary
Necessary technologies support authentication, security, routing, language, remembering the cookie choice, company context and drafts deliberately saved on the device. The requested functions may not work without them.
Analytics
Google Analytics is optional and is used only on the public website after a clear affirmative choice. It is disabled in the closed workspace during the pilot. Rejecting analytics does not prevent access to the public website or eligible access to the workspace.
Advertising storage, advertising user data, personalised advertising, Google Signals and user provided data collection are disabled for the pilot. No advertising or remarketing tag is approved by this Notice.
3. Cookie inventory
| Name | Provider and surface | Category and purpose | Duration | When set |
|---|---|---|---|---|
youaero_cookie_consent |
First party, public website | Necessary preference. Records granted or
denied for optional analytics. |
180 days | When the visitor makes or changes a choice. |
NEXT_LOCALE |
First party, workspace | Necessary preference. Remembers the selected language. | 365 days | When the user selects a language. |
youaero_session |
First party, workspace API | Necessary security. Server controlled authenticated-session
credential. It is host-only on the API origin, with Secure, HttpOnly,
SameSite Lax, Path / and no Domain attribute. Workspace
JavaScript cannot read it. |
No more than 24 hours from successful authentication, with a two-hour inactivity limit. Reissue during active use does not extend the absolute lifetime. | After successful authentication, email verification or an approved authentication step-up. Cleared on logout and revoked on material account changes. |
youaero_csrf |
First party, workspace and API | Necessary security. Readable random nonce for signed double-submit
CSRF protection. It uses Secure, SameSite Lax and Path /,
with Domain .you.aero in production and
.staging.jetsonictrade.ae in staging so the workspace can
read it and echo it in the X-CSRF-Token header. It is not
HttpOnly and is not an authentication bearer token. |
No more than 24 hours from authentication. Rotated with a newly issued authenticated session and cleared on logout. | Set with a new authenticated session. State-changing cookie-authenticated requests also require an allowed Origin and a matching header. |
_ga |
Google Analytics, public website | Optional analytics. Distinguishes browsers for measurement. | Up to two years unless rejected, withdrawn or deleted earlier. | Only after affirmative analytics consent. |
_ga_73S4CQ58NN |
Google Analytics measurement ID G-73S4CQ58NN, public
website |
Optional analytics. Maintains session state for the active data stream. | Up to two years unless rejected, withdrawn or deleted earlier. | Only after affirmative analytics consent. |
The exact Google stream suffix is verified in the production cookie inventory before release. No cookie outside the verified inventory may be deployed without updating this Notice and, where required, obtaining a new choice.
4. Browser storage
| Key or family | Surface | Storage | Purpose | Removal |
|---|---|---|---|---|
youaero.company_context |
Workspace | Local storage | Remembers the company context selected by the user and lets other open workspace tabs detect a context update through the browser storage event. | Logout, context reset or manual browser clearing. |
youaero.rfq-wizard |
Workspace | Local storage | Recovers an unfinished restricted demo or internal test RFQ. | Successful completion, user deletion or manual clearing. |
youaero.offlineDrafts |
Workspace | Local storage | Stores drafts deliberately saved on the device. Attachment bytes are not stored. | User or application deletion, or manual clearing. |
youaero.signup_attribution.v1 |
Public website and registration handoff | Session storage | Holds permitted UTM and referral fields for the current browser session. It must not contain email, invitation tokens or other secret data. | Successful registration, end of tab session or manual clearing. |
youaero.ai-crew.pending-submission.v1 |
Workspace, only if enabled | Session storage | Temporary retry state and non secret request identifiers. | Completion, failure handling or end of tab session. |
youaero.ai-crew.draft.v1:* |
Workspace, only if enabled | Session storage | Unsent conversation draft text. | Send, user removal or end of tab session. |
youaero.ai-crew.spoken-locale.v1 |
Workspace, only if enabled | Local storage | Remembers the selected spoken language. | User change, feature removal or manual clearing. |
youaero.activity.session.v1 |
Workspace, only when activity telemetry is enabled | Session storage | Random per-tab activity session identifier used to join bounded heartbeat, page timing and allowlisted action records. | Logout, account or company context reset, end of the tab session or manual clearing. |
youaero.activity.sequence.v1 |
Workspace, only when activity telemetry is enabled | Session storage | Monotonic per-tab sequence used to reject duplicate or out-of-order activity updates. It contains no form or message content. | Removed with the related activity session. |
youaero.activity.owner.v1 |
Workspace, only when activity telemetry is enabled | Session storage | Random per-tab ownership identifier used with the transient lifecycle channel to detect when a duplicated tab inherited the same activity session and make one tab rotate. It contains no account or company identifier. | Removed with the related activity session on logout, account or company context reset, end of the tab session or manual clearing. |
youaero.activity.reset.v1 |
Workspace, only when activity telemetry is enabled | Local storage | Short cross-tab reset marker containing exactly a reset reason, random nonce and creation time. It tells other tabs to close local activity state after logout or an account or company context change. It contains no account or company identifier and no business content. | Removed immediately when another tab consumes it, or by the sending tab after no more than five seconds; manual browser clearing. |
youaero.activity.lifecycle.v1 |
Workspace, only when activity telemetry is enabled | BroadcastChannel transient message | Coordinates duplicated-tab session ownership, logout and account or company context reset between open tabs. Messages use random tab and ownership identifiers. A reset may transiently include the previous company-context identifier solely to close the correct old activity session. Messages are not persistent browser storage and contain no form values, email or message text, attachment content or authentication secret. | Discarded by the browser after delivery; the channel closes with the tab or feature lifecycle. |
youaero.auth.lifecycle.v1 |
Workspace, always-on necessary security | BroadcastChannel transient message | Coordinates immediate cross-tab logout and client authentication or
cache purge independently of activity telemetry. Each message contains
exactly the type auth_reset, a random UUIDv4 nonce and its
finite creation time in epoch milliseconds. It contains no account,
company or user identifier, URL, form value or business content. A
timestamp more than five seconds in the future or a message more than 30
seconds old is rejected. The sender does not deliver the message to
itself or rebroadcast it. |
No persistent browser storage. The browser discards a message after delivery, the listener is removed with workspace-provider cleanup and the singleton channel ends with the tab realm. |
Authentication bearer tokens, raw invitation tokens, verification codes and passwords must never be stored in local storage or session storage.
Workspace activity telemetry uses these necessary browser mechanisms only when the feature is enabled. It is separate from Google Analytics and does not depend on optional analytics consent. Server-side telemetry is limited to controlled page keys, bounded timing, selected allowlisted actions and changed field groups; field values, full URLs, query strings, keystrokes and message or attachment content are not collected.
5. What optional analytics measures
After analytics is accepted, the public website may send:
- page path, page title and displayed locale;
- page views and approved navigation events;
- button, platform handoff, outbound link and file download interactions;
- scroll milestones and section visibility;
- active engagement and maximum scroll depth; and
- web performance metrics.
Google may process device, browser and network information generated when its tag communicates with Google. User ID, user provided data, advertising features and cross product advertising links are disabled for the pilot.
Google Analytics user and event level data is configured for 14 months. This property setting is separate from cookie duration.
6. Your choice
Before analytics is accepted:
- the Google Analytics script is not loaded;
- analytics cookies are not set;
- analytics requests and cookieless pings are not sent; and
- rejecting analytics has no effect on necessary functions.
The banner provides equally clear Reject analytics and Accept analytics choices with no preselected acceptance. The footer provides a persistent Cookie Preferences control.
If you change from acceptance to rejection, future Google Analytics
loading and event transmission stops immediately and first party
_ga cookies are deleted where technically available. The
rejection choice remains stored so that analytics is not reactivated on
the next visit.
You may also delete cookies and browser storage through browser settings. Doing so may sign you out, reset language or remove locally saved drafts.
7. Email measurement
Campaign email open pixels are disabled for the closed supplier pilot. Campaign links may contain disclosed UTM parameters for aggregate and registration attribution, but the URL must not include the recipient's email address, raw invitation token or another directly identifying value.
Every marketing email provides a working unsubscribe method regardless of measurement settings.
8. Security attributes
Production must use HTTPS. The authenticated-session credential is Secure, HttpOnly and host-only on the API origin. The separate readable CSRF nonce uses Secure and SameSite Lax with the shared parent Domain described in the inventory. CSRF header validation, Origin checks, content security policy, rate limits, session rotation and server side revocation are implemented as security controls rather than relying on cookie disclosure alone.
The public consent cookie must not contain personal information. Language and preference cookies use Secure on HTTPS and an appropriate SameSite value.
9. Changes and contact
We update this Notice when technologies, providers, names, durations or purposes change. The current version and effective date appear at the top.
Questions may be sent to:
JETSONIC TRADING - FZCO / you.aero
Email: team@you.aero
Subject: Cookie or Privacy Question