Cookie policy
Last updated: 2026-07-27
This is an informational translation. The Spanish version at /es/legal/cookies prevails in case of any discrepancy.
1. Strictly necessary cookies (always on)
No consent required (LSSI-CE Art. 22.2 technical exception):
- Supabase Auth session cookies — session only.
- `prolio_country_v1` — language/country preference, 1 year.
- `prolio_consent_v1` (localStorage) — banner decision with policy version, timestamp and scope, 1 year.
2. First-party attribution cookies
If you arrive via a campaign link carrying utm_* parameters, we store them in our own cookies so a later form submission (e.g. the waitlist) keeps its source attribution. First-party only: no third party reads them, no external script loads, never used for advertising or profiling.
- `prolio_utm_source`, `prolio_utm_medium`, `prolio_utm_campaign`, `prolio_utm_content`, `prolio_utm_term` — first-touch campaign attribution, 30 days. Basis: legitimate interest in first-party campaign measurement.
3. Analytics cookies (only with your consent)
Regardless of this choice, Prolio performs first-party, aggregate and anonymous audience measurement of published listings (visits, appearances in results and contact clicks, as daily totals per listing). It uses no cookies, no storage on your device and no visitor identifier, so it does not require consent. See the Privacy policy for details.
- Google Analytics 4 — Google LLC (USA), SCCs. Cookies `_ga`, `_ga_*`, up to 2 years. Opt-out: https://tools.google.com/dlpage/gaoptout
- PostHog Cloud US — PostHog Inc. (USA), us.i.posthog.com, SCCs. `ph_*` + localStorage entries, 1 year.
4. Marketing cookies
Prolio does not use advertising, remarketing, social or profiling cookies. The banner's Marketing toggle stays off by default.
5. Accept / reject / change
The first-visit banner offers Accept all, Reject all, and Customise with equal visual weight. Change your choice any time via the footer "Cookie preferences" link.
6. Cookie-less technologies
We use error monitoring (Sentry): when the site fails, the browser sends a technical report (error message, page, browser, IP). It sets no cookies and does not identify you across sessions; basis is our legitimate interest in security and diagnostics. See the Privacy policy (sections 4 and 7).
7. Consent evidence
Every decision is logged with policy version, timestamp and a non-reversible IP hash, retained for 24 months as AEPD evidence.
8. Changes
When the non-strictly-necessary cookie set changes we bump the policy version and the banner reappears.