Cookie Policy
Last updated: 23 September 2026 · Effective immediately for all visitors and registered users.
Manage your cookie choices at any time
You can grant, customize, or withdraw consent with a single click.
This Cookie Policy explains how DPA TECH SOLUTIONS S.R.L. (“WhereU”, “we”, “us”) uses cookies, local browser storage, and related device technologies across the WhereU website (whereu.fun), mobile web applications (PWA), and native applications for Android and iOS.
We adhere strictly to Directive 2002/58/EC as amended by Directive 2009/136/EC (the European “ePrivacy Directive”), the European Data Protection Board (EDPB) Guidelines 05/2020 on consent, and Romanian Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector.
1. What Are Cookies and Local Storage Technologies?
A cookie is a small text file placed on your computer, tablet, or mobile phone by your web browser when you visit a website. In addition to HTTP cookies, modern web applications utilize comparable client-side technologies:
- localStorage: Persistent key-value browser storage used to store interface preferences (such as dark/light theme, language, and map zoom settings) that survive browser restarts.
- sessionStorage: Temporary storage that automatically clears when you close your browser tab, used for per-tab session identifiers.
- Service Workers & Cache Storage: Browser-level background workers that cache application assets so WhereU functions offline or during poor network conditions.
- Native Secure Storage: Apple iOS Keychain and Android EncryptedSharedPreferences used to securely maintain user session tokens in the native app wrappers.
2. How We Classify Cookies & Storage
In strict compliance with EU guidelines, we divide our cookies and client storage into four clear categories:
Category 1: Strictly Necessary (Always Active – No Consent Required)
These items are essential for technical operation, security, and authentication. Under Article 5(3) of the ePrivacy Directive, your consent is not required because the service cannot function without them.
Category 2: Functional & Preferences (Optional – Consent Based)
These store your personalized settings (such as chosen language, radar sounds, tracker presets, and Ghost Mode status) to provide a tailored user experience across sessions.
Category 3: Payments & Fraud Prevention (Web Session-Specific)
Operated by Stripe Payments Europe, Ltd. when you open WhereU PRO subscription checkout, Host Hub billing, or event ticketing on the web. These prevent transaction fraud and satisfy 3D Secure / PSD2 banking requirements. Note: Native in-app subscriptions on Android (Google Play In-App Billing) and iOS (Apple In-App Purchase) are handled directly through operating system frameworks and do not set browser cookies.
Category 4: Behavioral Analytics & Telemetry (Optional – Explicit Opt-In)
Used to measure application performance and feature engagement (e.g. search filters, screen dwell times) to help us improve WhereU. Analytics logging is completely disabled until you grant explicit consent. We never sell your data or use cross-site advertising cookies.
3. Detailed Itemized Inventory of Cookies & Storage Keys
| Key / Cookie Name | Provider | Category | Storage Type | Duration | Purpose |
|---|---|---|---|---|---|
sb-*-auth-token | Supabase (WhereU) | Strictly Necessary | localStorage / Cookie | Session / 1 Year | Maintains secure cryptographic session and authentication state. |
whereu.cookie-consent.v2 | WhereU | Strictly Necessary | localStorage | 12 Months | Stores your cookie consent preferences and decision timestamp. |
whereu.lang / whereu_lang | WhereU | Functional | Cookie / localStorage | 12 Months | Remembers your chosen language (en, ro, de, es, pt, bg). |
theme | WhereU | Functional | localStorage | Persistent | Remembers dark or light interface theme preference. |
whereu.tracker.preset | WhereU | Functional | localStorage | Persistent | Remembers your GPS tracker power profile (Battery / Balanced / High Precision). |
whereu.ghost-mode | WhereU | Functional | localStorage | Persistent | Stores local Ghost Mode or Ghost Mode+ privacy preferences. |
whereu.sound.enabled | WhereU | Functional | localStorage | Persistent | Stores audio synthesizer mute preference for radar proximity alerts. |
wu:analytics-session | WhereU | Analytics | sessionStorage | Per-Tab Session | Rotating anonymous session ID for product engagement events (only active if consented). |
public.behavior_events | Supabase (WhereU) | Analytics | Database queue | 90 Days | Privacy-preserving interaction logs (screen views, filter changes); erasable on demand. |
__stripe_mid, __stripe_sid | Stripe Europe | Payments / Security | HTTP Cookie | 1 Year / 30 Min | Fraud detection, bot prevention, and 3D Secure verification during Stripe Checkout. |
cf_clearance / Cloudflare Beacon | Cloudflare | Strictly Necessary / Analytics | HTTP / Beacon | Session / Anonymous | TLS routing, DDoS bot challenge clearance, and cookieless privacy-first site performance metrics. |
4. Third-Party Integrations & Data Flows
- Supabase: Encrypted token storage for session authentication and real-time database subscriptions.
- Stripe Payments Europe Ltd. (Ireland): Sets payment cookies exclusively within secure checkout sessions to comply with EU Revised Payment Services Directive (PSD2) strong customer authentication.
- Cloudflare Web Analytics: Privacy-preserving, cookieless metrics. Cloudflare does not use client storage or fingerprinting to identify individuals across sites.
- Mapbox / MapTiler / OpenStreetMap: Map tiles and vector styling are cached in standard browser HTTP memory to minimize network bandwidth. No user tracking is performed by map tile providers.
5. How to Control, Customize, or Withdraw Consent
You have total control over all optional cookies and local storage:
- Direct Preference Center: Click the Open Cookie Preferences button above or visit whereu.fun/cookie-preferences at any time.
- Immediate Revocation: When you disable Analytics in preferences or click “Reject optional”, all behavioural event queuing terminates instantly, and your session ID is cleared.
- Delete Analytics Data: Registered users can wipe all historically recorded analytics events at any time by navigating to Settings → Privacy & Data → Delete my analytics data.
- Browser Controls: You can configure your browser to reject all cookies or notify you before a cookie is set. Note that disabling strictly necessary cookies will prevent authentication and core map functionality from working.
6. Updates to This Cookie Policy
We review our cookie inventory regularly to ensure complete accuracy whenever new features or third-party integrations are launched. The “Last updated” date at the top of this document always reflects the currently active audit.
7. Questions & Data Protection Officer Contact
If you have questions regarding our use of cookies or wish to submit a data protection inquiry, please contact our Data Protection Officer at privacy@whereu.fun.