For hosted pages
Flip.to hosts some guest-facing pages on our own domain (your post-stay experience, storyteller invitations, certificates and landing pages, to name a few).
Your website's consent banner doesn't reach them, so here's how we run your consent platform on those pages instead, and what we need from you.
What's different about hosted pages
You own everything on your site, from the experiences to the data. Flip.to only uses first-party cookies, and acts as your data processor.
On your own experiences we read the signal your platform provides when you set up Consent Management for your Website.
Hosted pages are different. They're served from a Flip.to domain. Rather than show our own consent banner, we install yours.
Using the consent platform account ID, we load your platform's script on hosted pages. Guests see your consent banner so that your categories govern what runs, and their choices are honored.
Where no consent platform is configured, hosted pages still apply a default policy (analytics storage denied in regions that require it) before any tags load.
Setup at a glance
Send us your account ID so we can load your platform.
Add our hosted domain to your platform, and allow our scripts.
Add our cookies to your cookie declaration.
Send us your account ID
If you use one of the consent platforms below, we load it on hosted pages directly. We need one value: the consent platform account ID issued when you set up a site. It isn't a secret—it's visible in the script on any page where your banner already runs. Find it using the links below and send it to your Flip.to account manager.
It may not be the ID from your main website. Most platforms issue an account ID per site or domain group, and our experiences are hosted on a different domain than yours.
If your hosted pages use stories.travel, you'll likely need to add that hostname as a new site in your consent platform and send us that ID—Cookiebot and OneTrust in particular issue a separate CBID or domain script per domain group. A branded subdomain of your own domain usually keeps you on your existing ID.
Don't see your platform? Tell your account manager which one you use—the list above is the set we currently load, and we can look at adding others.
Didomi uses a vertical bar. Sending an API key and a notice ID together? Separate them with | rather than a slash—apiKey|noticeId. Every other two-part value on this page uses a slash.
Matching your category names
To honor a guest's choice, we need to know which of your categories covers strictly necessary cookies and which covers analytics. Most platforms use standard names and we match them automatically.
If yours was set up with custom category names, send those along with your account ID.
OneTrust customers: both category names are required. OneTrust identifies categories by codes specific to your configuration (commonly C0001 through C0004) so there's nothing for us to fall back on. Send the code for your strictly necessary category and the code for your analytics category along with your domain script ID. You'll find them in Cookie Consent under your site's categories.
Domains to add
Your hosted page domain
Consent platforms only run on domains listed in your account. Hosted pages are served from a Flip.to domain, so add it alongside your website. Your account manager will confirm which of these applies to you and give you the exact hostnames.
Your branded subdomain
Preferred. If your hosted pages are served from your own domain (stories.yourhotel.com) it likely sits under a root domain your platform already covers.
yourhotel.stories.travel
The default, where no branded subdomain is set up. One hostname per property.
Wildcards generally aren't supported. Consent platforms don't accept *.stories.travel in a domain field. Most cover subdomains of a root domain you've already registered, so a branded subdomain under your own domain usually needs no change at all.
Cookiebot is the exception. It treats every subdomain as a separate domain with its own subscription. If your hosted pages use stories.travel, ask your account manager about a branded subdomain instead.
Add the same hostname to your platform's cookie scanner. A scan pointed only at your website won't crawl the hosted pages, so the cookies below would be missing from the declaration it generates.
Scripts to allow
Where your platform offers automatic script blocking, we turn it on for hosted pages. It holds back any script it doesn't recognize, so categorize ours:
Your hosted page domain
The page itself, and the scripts that render it
Necessary
integration.flip.to
Flip.to's own tag container
Necessary
cdn.flip.to
Flip.to scripts and assets
Necessary
sa.flip.to
Spacetime analytics
Analytics
www.googletagmanager.com
Your own Google Tag Manager container
Analytics
Blocking a necessary domain stops the page rendering. It doesn't reduce tracking—Flip.to already applies your guest's choice before anything is measured. The analytics domains above are gated by that choice whether or not your platform also blocks them.
Cookies we set
Most of these are named with a prefix and a suffix specific to your property or campaign. Include the asterisk (*) when you add them to your consent platform.
Analytics ANALYTICS
Set only when a guest grants analytics consent. If a guest later withdraws it, we remove any that were already set. A guest who denies analytics is still measured anonymously—we count the visit, without an identifier tied to them.
sa_ft*
Spacetime analytics identifiers. Also stored in local storage.
Up to 2 years
ft-it*
Remembers which parts of the experience a guest engaged with.
Session, 6 or 18 months
flipto*
Set on your website after a guest signs up, so they aren't invited twice.
Varies
Strictly necessary NECESSARY
These keep the experience working and are never used for measurement.
ftvoter*
Records a photo contest vote so it isn't counted twice.
6 months to 1 year
ftcontestpromotioncode*
Remembers whether the visitor arrived as a guest, a friend or a browser.
6 months to 1 year
ft-invitee*
Stops a guest being invited to the same contest twice.
1 year
ftDiscoveryState
Local storage. Keeps the guest's plan state as they move through the experience.
Until cleared
ftReturningUserPopupState
Session storage. Stops a message repeating within the same visit.
Session
What happens once it's set up
Your platform's script loads first on every hosted page, before anything that could set a cookie.
Guests see your banner, with your branding, categories and language.
Your own Google Tag Manager container is loaded on these pages too, and the guest's decision reaches it, so tags gated on
analytics_storagebehave the way they do on your site.Every hosted page carries a control to reopen your banner, so a guest can change their mind.
Consent given on a hosted page is recorded by your platform as usual, so it appears in your consent records alongside everything else.
If the banner doesn't appear. Check the hosted domain is listed in your consent platform first—that's the most common cause, and the script will load without rendering anything.
After that, check the account ID wasn't copied incompletely: a missing character, or only one half of a two-part value. Then let your account manager know so we can confirm what's stored.
Compliance
Hosted pages operate under the same terms as the rest of the platform: first-party cookies only, Flip.to as data processor, and full ownership of collected data remaining with you. The experiences served on these pages comply with GDPR, CCPA and other privacy regulations.
Last updated