Cookie Policy
We use cookies to keep you logged in, process payments securely, measure how the service is used, and measure our advertising. There is no cookie banner and no cookie preferences screen in the product today: analytics and advertising cookies are set when the page loads. Your browser settings are the way to refuse them, and doing so will not stop you using the site — though refusing the authentication cookie will stop you signing in.
Cookie Categories
Authentication Cookies
RequiredKeep you logged in securely across sessions. Set when you sign in; cleared when you sign out.
Payment Cookies
RequiredEnable secure payment processing through Stripe. Set the first time you start a checkout, not on ordinary browsing.
Analytics Cookies
Browser controls onlyPostHog and Google Analytics 4, used to understand how the service is used. Set on page load. We have no in-product switch for these; use your browser settings.
Advertising Cookies
Browser controls onlyThe Meta Pixel, used to measure whether our advertising brought you here. Set on page load. We have no in-product switch for these; use your browser settings.
Cookies We Use
| Cookie | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
sb-<project-ref>-auth-token | Supabase | Holds your signed-in session (access and refresh tokens). Split across .0 and .1 suffixed cookies when the session is too large for one cookie. | Essential | Refreshed while you stay signed in; cleared on sign out |
__stripe_mid | Stripe | Fraud prevention. Set when Stripe.js loads, which happens the first time you start a checkout — not on ordinary browsing. | Payment | 1 year |
__stripe_sid | Stripe | Payment session tracking. Set at the same point as __stripe_mid. | Payment | 30 minutes |
ph_<project-key>_posthog | PostHog | Product analytics: a device identifier and session identifier used to join your page views and feature usage into a single session. Set across our subdomains. | Analytics | 1 year |
_ga | Google Analytics 4 | Distinguishes your browser from others so visits can be counted. IP anonymisation is on and Google Signals and ad personalisation are switched off. | Analytics | 2 years |
_ga_<measurement-id> | Google Analytics 4 | Holds the session state used by Google Analytics for this property. | Analytics | 2 years |
_fbp | Meta (Facebook) | Identifies your browser to measure whether visits and sign-ups came from our Facebook or Instagram advertising | Advertising | 3 months |
_fbc | Meta (Facebook) | Records that you arrived from a Facebook or Instagram ad, so that ad can be credited with the visit | Advertising | 3 months |
vba_social_oauth_state | Virtual Buyers Agent | A short-lived anti-forgery token used only inside our internal admin tools when connecting a social account. It is never set on a customer account. | Essential | Minutes; cleared as soon as the connection completes |
Local Storage and Session Storage
These are not cookies, but they hold data on your device in the same way, so they belong in the same document. This is the complete list of keys Virtual Buyers Agent writes. A placeholder in angle brackets means the key name has that value appended, so there is one key per user or per property.
| Key | Where | What it holds | How long |
|---|---|---|---|
vba_session_cache | Local storage | A short-lived copy of your signed-in session, including your access and refresh tokens, so a page load does not have to wait on the network. | Treated as stale after 60 seconds; removed on sign out |
vba_access_token | Local storage | A copy of your access token, used to authorise requests from the app. | Removed on sign out |
vba_refresh_token | Local storage | A copy of your refresh token, used to renew your session without signing in again. | Removed on sign out |
vba_session | Local storage | The full session object returned by our authentication provider. | Removed on sign out |
vba_user_cache_<user-id> | Local storage | A cached copy of your account record — name, email, subscription tier and property allowance. | Treated as stale after 5 minutes; removed on sign out |
vba_subscription_cache_<user-id> | Local storage | Your current plan tier, cached so the interface does not flicker between states. | Treated as stale after 60 seconds; removed on sign out |
vba_subscription_details_<user-id> | Local storage | Your subscription record — plan, status and renewal date. | Deleted the next time it is read, once more than 60 seconds old |
vba_swr_cache:<user-id> | Local storage | Responses from up to 50 recent requests to our own API, so the dashboard can render immediately on your next visit. In practice this can include property records and account data you have already viewed. | Replaced as you browse; the previous user’s copy is deleted when the account changes |
vba_quiz_v4_draft_<user-id> | Local storage | An unfinished Investor Profile Quiz, saved so you can come back to it. This includes the financial answers you have given so far — income band and deposit amount among them. It stays on your device until the quiz is submitted or the draft expires. | 14 days, then discarded; cleared when you submit the quiz |
vba_plan_intent | Local and session storage | The plan you selected before signing up, so we can show the right option afterwards. | Cleared once the choice has been recorded on your account |
vba_acquisition_channel | Local and session storage | Which channel brought you to the sign-up page (for example an ad, a search result or a direct visit), derived from the campaign parameters and referrer of that visit, so a sign-up can be attributed to it. | Overwritten on each visit to sign-up; not otherwise cleared |
vba_new_signup | Local and session storage | A one-shot marker so a new sign-up is counted once and not on every later page load. | Cleared as soon as it has been read |
vba_login_submitted | Local and session storage | Marks that a sign-in was submitted, so the resulting session can be attributed to it. | Cleared once the sign-in completes |
vba_login_method | Local and session storage | Which method you used to sign in (email, Google or Apple). | Cleared once the sign-in completes |
vba_login_submitted_at | Local and session storage | The timestamp of that sign-in attempt. | Cleared once the sign-in completes |
theme | Local storage | Whether you prefer the light or dark interface. | Until you clear it |
vba_section_collapsed_<section> | Local storage | Which dashboard sections you have collapsed. | Until you clear it |
vba_dashboard_tour | Local storage | Whether you have completed or skipped the dashboard tour. | Until you clear it |
vba_beacon_dismissed_<area> | Local storage | Which guidance beacons you have dismissed. | Until you clear it |
vba_dismissed_tooltips | Local storage | Which guidance tooltips you have dismissed. | Until you clear it |
abs-banner-dismissed-<property-id> | Local storage | Which per-property notices about Australian Bureau of Statistics estimates you have dismissed. | Until you clear it |
vba_first_property_celebration | Local storage | Whether the first-property message has already been shown to you. | Until you clear it |
vba_review_prompt_state | Local storage | When you were last asked to leave a review, how many times you have been asked, and whether you accepted or dismissed it — so we do not ask again too soon. | Until you clear it |
vba_testimonial_collection_state | Local storage | Whether you have already been asked for a testimonial. | Until you clear it |
ph_<project-key>_posthog | Local storage | PostHog’s own copy of the device and session identifiers described in the cookie table above, plus events waiting to be sent. | Managed by PostHog; cleared with site data |
vba_signup_email | Session storage | The email address you typed into the homepage form, carried across to the sign-up page so you do not have to type it twice. It is not sent anywhere until you submit the sign-up form. | Until you close the tab |
vba-sticky-cta-dismissed | Session storage | That you dismissed the sticky call-to-action bar on our marketing pages. | Until you close the tab |
vba-email-banner-dismissed | Session storage | That you dismissed the “please verify your email” banner. | Until you close the tab |
vba-payment-banner-dismissed | Session storage | That you dismissed the payment-problem banner. | Until you close the tab |
vba_nps_shown | Session storage | That a satisfaction survey has already appeared this session. | Until you close the tab |
vba_review_surface_session | Session storage | That a review prompt has already appeared this session. | Until you close the tab |
How to Refuse Cookies
Your browser settings are the only way to refuse cookies on this site. We do not offer a cookie preferences screen, and analytics and advertising cookies are set when the page loads rather than after a choice. Blocking or clearing site data for virtualbuyersagent.com.au removes the analytics and advertising cookies along with the local storage and session storage keys listed above.
Note: blocking the authentication cookie will prevent you from signing in, and blocking Stripe will prevent payment.
Full Cookie Policy
1. What Are Cookies?
Cookies are small text files stored on your device when you visit a website. They help websites remember your preferences, keep you logged in, and provide a better user experience. Cookies can be "session" cookies (deleted when you close your browser) or "persistent" cookies (remain until they expire or you delete them). Alongside cookies, this policy also covers browser local storage and session storage, which are separate mechanisms that hold data on your device in the same way; every key we write to either of them is listed above.
2. How We Use Cookies
Virtual Buyers Agent Pty Ltd uses cookies and device storage to: authenticate your account and keep you securely logged in; remember your preferences and settings; process payments securely through Stripe; measure how the service is used so we can improve it; measure whether our advertising brought you here; and avoid repeating prompts you have already dismissed. Where a cookie or storage key exists purely to make the interface feel faster or quieter, it is described that way in the tables above rather than being grouped under a broader heading.
3. Essential and Authentication Cookies
Some cookies are strictly necessary for Virtual Buyers Agent to function. The Supabase authentication cookie keeps you logged in, and the Stripe cookies enable secure payment when you start a checkout. You cannot opt out of these while using the service, because the service cannot work without them. The authentication data we hold in local storage (listed above) is cleared when you sign out.
4. Analytics and Advertising Cookies — and the Absence of a Consent Control
We use PostHog and Google Analytics 4 for product analytics, and the Meta Pixel to measure our advertising. These are loaded when the page loads, before you interact with anything, and there is currently no cookie banner and no cookie preferences screen in the product. We are stating that plainly rather than implying a control that does not exist: the only way to prevent these cookies today is through your browser settings or an extension, as described in sections 6 and 7. Google Analytics is configured with IP anonymisation on and with Google Signals and ad personalisation switched off. PostHog also records session replays; every input field is masked, so what you type into email, password, phone, and payment fields is not captured — only that the field was used. PostHog is additionally used for error monitoring: when something breaks, the error message and the code location are sent to PostHog so we can find and fix it. Those reports are scrubbed before they leave your browser — email addresses, tokens, card numbers and similar values are stripped from the message and from the surrounding lines of code — and they are captured under the same controls as everything else on this list, so opting out of analytics opts out of error reports too.
5. Third-Party Cookies
Some cookies are set by third-party services we use: Supabase (authentication), Stripe (payment processing), PostHog (product analytics and session replay), Google Analytics 4 (product analytics), and Meta (advertising measurement). These third parties have their own privacy policies governing how they use cookies. We suggest reviewing the Supabase, Stripe, PostHog, Google and Meta privacy policies. Our hosting provider, Vercel, serves the site; we do not enable its analytics product and it does not set cookies for that purpose.
6. Managing Cookies
You can control cookies through your browser settings. Most browsers allow you to: view what cookies are stored; delete all or specific cookies; block third-party cookies; block cookies from specific sites; and clear all cookies when you close the browser. The same browser controls (usually described as "site data" or "cookies and other site data") also clear the local storage and session storage keys listed above. Note that blocking essential cookies will prevent you from signing in.
7. Browser-Specific Instructions
To manage cookies and site data in your browser: Chrome - Settings > Privacy and Security > Third-party cookies, and Delete browsing data; Firefox - Settings > Privacy & Security > Cookies and Site Data; Safari - Settings > Privacy > Manage Website Data; Edge - Settings > Cookies and site permissions. You can also use browser extensions for more granular control.
8. Local Storage and Session Storage
In addition to cookies, Virtual Buyers Agent writes roughly thirty keys to your browser's local storage and session storage. They are listed individually in the table above rather than summarised, because two of them deserve to be read directly: an unfinished Investor Profile Quiz is saved to your device under vba_quiz_v4_draft_<user-id> and includes the financial answers you have given so far, including income band and deposit amount; and vba_swr_cache holds recent responses from our own API, which can include property and account data you have viewed. Both are written by your browser and stay on your device. Data written by PostHog is transmitted to PostHog. Clearing site data in your browser removes all of these.
9. Do Not Track
We do not currently act on the Do Not Track (DNT) browser signal. Our analytics tools are not configured to detect or honour it, and we would rather say so than claim a protection we have not built. If you do not want analytics or advertising cookies set, use your browser's cookie controls or an extension as described in sections 6 and 7. Global Privacy Control (GPC) signals are likewise not currently acted upon.
10. Updates to This Policy
We may update this Cookie Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will notify you of material changes by posting the updated policy on our website with a new "Last Updated" date. Your continued use of Virtual Buyers Agent after changes constitutes acceptance of the updated policy.
Third-Party Privacy Policies
Our third-party service providers have their own cookie and privacy policies:
Related Policies
Questions?
If you have questions about how we use cookies, please contact us.
info@virtualbuyersagent.com.au