Cookie Policy and Tracking Technologies
Last updated: October 01, 2026 · Compliant with ePrivacy Directive, GDPR, and Google Consent Mode v2
This Policy forms an integral part of Tredi's Legal Notice and Privacy Policy (Perk Drop SL). Herein we transparently detail which local storage mechanisms, cookies, web beacons, and mobile software development kits (SDKs) we utilize across our website and mobile apps (iOS and Android), for what purposes, and how you may configure or revoke your consent at any time.
1. What are Cookies, Pixels, and Equivalent Mobile Technologies?
In modern digital systems, operational signals and performance metrics are not confined to browser cookies, but encompass an integrated suite of technologies:
- Web Browser Cookies:Small text files stored within the browser to maintain session states, language preferences, and transactional stability.
- Mobile Local Storage (AsyncStorage / SecureStore):Native mechanisms in iOS and Android applications securely storing encrypted authentication tokens, 'Drop' cache states, and locally favorited offers.
- Pixels and Web Beacons:Code snippets measuring advertising conversions, enabling platforms such as Google or Meta to attribute visits or merchant sign-ups to specific campaigns.
- Attribution and Telemetry Mobile SDKs:Embedded libraries within the mobile application measuring crash reports, rendering performance, and acquisition channels without compromising individual privacy.
2. Taxonomy of Categories Governed by Usercentrics CMP
In compliance with European Data Protection Board (EDPB) and Spanish Data Protection Authority guidelines, Tredi categorizes tracking technologies into 4 distinct groups managed by the Usercentrics Consent Management Platform (CMP):
A. Technical and Strictly Necessary (Consent-Exempt)
Essential for core platform operations. They handle JWT token authentication in Supabase, secure payment processing via Stripe (PCI-DSS), load balancing, DDoS attack mitigation, and consent preference persistence. They cannot be switched off in our systems.
B. Analytics and Performance (Prior Consent Required)
Allow aggregated statistical assessment of visitor volumes, screen traffic, average map session durations, and technical error rates. We deploy Google Analytics 4 (GA4), Firebase Analytics, and Google Tag Manager with mandatory IP anonymization.
C. Marketing, Advertising, and Attribution (Prior Consent Required)
Utilized to optimize user acquisition campaigns on external networks (Google Ads, Meta Pixel / Conversions API, TikTok Ads, Apple Search Ads). They evaluate which campaigns produce registrations in Tredi Partner or app downloads. Without your consent, personalized audiences and remarketing are disabled.
D. Functional and User Support (Prior Consent Required)
Enable enhanced assistance capabilities, such as live customer support messaging (Chatwoot) or advanced vector map interactions (Google Maps Platform).
3. Google Consent Mode v2 Regime (Advanced Mode)
To guarantee compliance with the European Union's Digital Markets Act (DMA), Tredi implements Google Consent Mode v2 in its advanced implementation. This protocol dynamically adjusts how Google services process telemetry according to four explicit user consent signals:
In a denied state, no cookies are written or read from the device, transmitting only aggregated, stateless pings. Upon granted consent, complete measurement and attribution features activate.
4. Full Inventory of Declared Cookies and Technologies
The primary technologies utilized across the Platform are outlined below. The complete dynamic inventory, featuring precise expiration timelines and vendor identifiers, is synchronized live via the Usercentrics CMP, accessible anytime via the 'Cookie Preferences' link in the footer.
| Service / Vendor | Key Identifiers | Category | Duration | Processing Purpose |
|---|---|---|---|---|
| Supabase (PostgreSQL & Auth) | sb-*-auth-token | Essential | Session / Persistent | Secure authenticated sessions for customers and merchants governed by Row Level Security (RLS). |
| Stripe Payments Europe Ltd. | __stripe_mid, __stripe_sid | Essential | 1 year / 30 min | Fraud prevention in B2B subscription transactions and PSD2 compliance. |
| Usercentrics CMP | uc_settings, uc_user_interaction | Essential | 180 days | Auditable proof of user consent per GDPR requirements. |
| Google Analytics 4 / GTM | _ga, _ga_*, _gid | Analytics | 2 years / 24 hours | Aggregated visitation metrics with mandatory IP anonymization. |
| Google Ads (Enhanced Conversions) | _gcl_au, _gcl_aw | Marketing | 90 days | Attribution of merchant sign-ups and app downloads from Google Search campaigns. |
| Meta Pixel / Conversions API | _fbp, _fbc | Marketing | 90 days | Measurement of campaign conversions across Instagram and Facebook. |
| Chatwoot Live Support | cw_conversation, cw_user | Functional | Session | Customer support chat conversation persistence. |
5. Mobile Governance (iOS and Android)
Within native Tredi applications, user privacy is safeguarded by a dual-gate architecture:
- Conditional Apple ATT Prompt (iOS):Apple's App Tracking Transparency (ATT) dialog is only triggered if the user has affirmatively consented to Marketing within the CMP. If Marketing is denied in Tredi, the iOS prompt is never displayed.
- Google Advertising ID (Android):Users may reset or disable personalized ad tracking at any time in device Settings > Google > Ads.
- In-App Revocation:You may tap 'Privacy Settings' inside your in-app Profile at any time to re-summon the Usercentrics modal and alter choices.
6. How to Manage or Revoke Your Consent
You retain the inalienable right to revoke consent at any time as easily as it was granted:
- On the Web Platform: Click the persistent 'Cookie Preferences' link located in the website footer across all Tredi pages to reopen the Usercentrics panel.
- Inside the Mobile App: Navigate to Profile → Settings → Privacy & Cookies to open the interactive configuration panel.
- In Your Web Browser: You can selectively block or delete cookies via your browser settings (Chrome, Safari, Firefox, Edge).
Technical Impact Notice: Completely blocking strictly necessary cookies and local storage tokens will prevent account login, Tred reservations, and digital wallet viewing.