This policy explains what cookies and similar technologies VAKA uses in your browser and in the app, what they are for and how you can manage them. The honest summary: today VAKA uses only essential cookies (so you can sign in and use the platform) and preference cookies (language, country, currency). We do not use analytics or advertising cookies. If that changes, we will update this policy and let you know before activating any new tool.
This policy complements the Privacy Policy, which describes the processing of your personal data in general.
1. What cookies and similar technologies are
Cookies are small text files that a website stores in your browser to remember information between visits: from your active session to the language you chose. They can be session (deleted when you close the browser) or persistent (they last until an expiration date or until you delete them), and they can be first-party (set by VAKA) or third-party (set by a service that VAKA integrates, for example the payment processor during checkout).
In addition to cookies, we use similar technologies: the browser's local storage (localStorage), which stores interface preferences on your own device, and a technical device fingerprint used exclusively for fraud prevention, described in section 4.
2. What cookies VAKA uses today
This is the complete, real list of the cookies that VAKA sets in your browser. There are no others.
2.1 Essential (necessary for VAKA to work)
- Supabase session cookies (named with the pattern sb-...-auth-token; may be split into several parts if the content is long) — they keep your session securely active so you don't have to type your password on every page. They renew while you use VAKA and disappear when you sign out. Without them, signing in is not possible.
2.2 Preference
- vaka-country — the country you browse VAKA with (detected from your connection the first time, or the one you choose). It determines the default catalog and currency. Lasts up to 1 year.
- vaka-locale — the language you chose for the interface. Lasts up to 1 year.
- vaka-currency — the currency you prefer to see prices in, only if you change it manually in Settings. Lasts up to 1 year.
- vaka-bypass-geo — created only if you are outside the countries where VAKA operates and you choose to keep browsing anyway; it remembers that choice so it doesn't redirect you on every page. Lasts 30 days.
- vaka-demo-session — used only in demonstrations by the VAKA team; it is not activated in normal use of the platform.
2.3 Analytics and advertising
Today, none. VAKA does not load third-party analytics tools or advertising trackers, not even if you accept the cookie notice. If in the future we add optional analytics to better understand use of the platform, it will always be with prior notice: we will update this policy, let you know and respect the preference you registered in the cookie notice.
3. Local storage (localStorage)
Some preferences are saved in your browser's local storage, which lives only on your device and is not sent automatically to our servers:
- vaka_cookie_consent — remembers the decision you made in the cookie notice (accept or reject) so it does not show it to you again.
- Interface preferences — small experience adjustments (for example, panel states or notices already seen) that improve navigation.
4. Device fingerprint (anti-fraud)
To protect the community against fake, duplicate or fraudulent accounts, VAKA generates a technical fingerprint of your device using the FingerprintJS library. This technology does not use cookies: it computes an identifier from technical characteristics of the browser and device, directly on your equipment, and sends it to VAKA's servers — not to an external service.
The fingerprint is used exclusively for fraud prevention and security — never for advertising or to track you across other sites — and is part of the defenses described in the Anti-Fraud Policy. Because of its security function, it is an essential part of the service and cannot be disabled. The processing of this data is governed by the Privacy Policy.
5. Third-party services
Some services that VAKA integrates may use their own cookies or storage when you interact with them. Each one has its own privacy policy:
- Stripe — when you pay by card, the payment form is served by Stripe and may use its own cookies for security and payment fraud prevention. They only appear in the payment flow. More on how we handle payments in the Payments Policy.
- OneSignal — if you enable push notifications in the browser, OneSignal registers your device so it can deliver them. It is only activated if you accept notifications, and you can revoke them from your browser or your preferences.
- Didit — when identity verification with Didit is active, its flow may use its own cookies or storage only during verification. See the Identity Verification and Biometric Data Policy.
6. The cookie notice
The first time you visit VAKA a notice appears at the bottom of the screen with two options: accept or reject. Your decision is saved in your browser's local storage.
Let's be transparent: since today we don't use analytics or advertising, both options leave VAKA working exactly the same — with the essential and preference cookies described above, which are necessary for the service. The notice exists to record your preference from now on: if in the future we add optional analytics tools, they will only be activated respecting that preference and after updating this policy for you.
If you want to change your decision, delete the site data for vakaland.com from your browser settings: the notice will appear again on your next visit.
7. How to manage cookies from your browser
All browsers allow you to view, delete and block cookies:
- Chrome: Settings > Privacy and security > Third-party cookies and site data.
- Safari: Settings > Privacy.
- Firefox: Settings > Privacy and security.
- Edge: Settings > Cookies and site permissions.
Keep in mind that if you block or delete all cookies, VAKA will not be able to keep your session active and you will have to choose your language, country and currency again on each visit.
8. Cookies and the mobile app
VAKA's mobile app does not use cookies as such: your session is saved in your phone's secure storage. When the app opens an internal web view (for example, a VAKA page inside the app), that view works like the website and the cookies described in this policy apply to it.
9. Changes to this policy
If we add, remove or change cookies or similar technologies, we will update this list. If the change significantly affects your privacy — for example, adding third-party analytics — we will also notify you through the cookie notice or inside the app before activating it.