Cookie Policy
Last updated: August 5, 2026 · Consent version v2.0
This page covers app.geoready.dev, the GeoReady application. The inventory below is generated from the same configuration the consent banner uses, so what you read here is what the app actually does. For the public website see the cookie policy on geoready.dev.
Cookies, local storage, and why both matter
A cookie is a small file a site stores on your device. Browsers also offer localStorage, which does the same job without sending anything back with each request. The law treats them the same way: storing or reading information on your device needs your consent unless it is strictly necessary to provide what you asked for (ePrivacy Directive art. 5(3)). We list both below and ask for consent for both.
Because the app is a signed-in tool, most of what it stores is the session itself — that is the strictly necessary part, and it exists only after you log in.
Your choice also travels as a signal. Through Google Consent Mode v2 this domain declares all four Google consent types — analytics storage, ad storage, ad user data and ad personalisation — as denied before any Google tag can run, and updates them only when you decide. Because the Analytics property is linked to Google Ads so the subscription conversion can be attributed to a campaign, that declaration is what keeps a refusal meaningful on Google's side rather than only on ours. No advertising cookie is set here in either case.
Categories
1. Necessary
always onEssential for the app to work: keeping you signed in, taking a payment, and storing your privacy choice itself. Cannot be disabled.
5 item(s) — see the inventory below.
2. Preferences
off unless you acceptRemember settings and choices you make so they persist between visits.
Nothing is stored in this category today.
3. Analytics
off unless you acceptLet us see which parts of the app are used and which subscriptions complete, through PostHog and — on the payment confirmation page only — Google Analytics. Off unless you accept.
4 item(s) — see the inventory below.
4. Marketing
off unless you acceptGoverns advertising signals. No marketing cookie or tracker is set on this domain, and no advertising tag is loaded. What this controls is the ad-related consent sent to Google: accepting lets the subscription conversion, measured on the payment confirmation page, be attributed in full in Google Ads; declining keeps it limited.
Nothing is stored in this category today.
Full inventory
Every cookie, storage key and third-party request the app can create, with the
legal basis for each. Names shown with <…>
contain a project or container identifier that varies.
| Name | Category | Type | Provider | Duration |
|---|---|---|---|---|
| geo_cookie_consent | Necessary | localStorage | GeoReady | 6 months, or until the consent version changes |
| geo_access_token | Necessary | localStorage | GeoReady | Short-lived — replaced on refresh, cleared on logout |
| geo_refresh_token | Necessary | localStorage | GeoReady | Until it expires server-side or you log out |
| ph_<project-token>_posthog | Analytics | Cookie | PostHog Inc. | 365 days |
| ph_<project-token>_posthog | Analytics | localStorage | PostHog Inc. | Until you withdraw consent or clear site data |
| __ph_opt_in_out_<project-token> | Necessary | localStorage | PostHog Inc. | Until you change your choice or clear site data |
| _ga | Analytics | Cookie | Google Ireland Limited / Google LLC | 2 years |
| _ga_<container-id> | Analytics | Cookie | Google Ireland Limited / Google LLC | 2 years |
| Stripe Checkout cookies | Necessary | External request | Stripe, Inc. / Stripe Payments Europe Ltd. | Determined by Stripe — see their policy |
geo_cookie_consent Necessary localStorage · first-party · app.geoready.dev Stores your cookie and privacy choices so you are not asked again on every visit, and so the choice can be honoured before any non-essential script loads.
- Service:
- GeoReady Consent Manager
- Duration:
- 6 months, or until the consent version changes
- Legal basis:
- Technical necessity — recording a consent choice is required to demonstrate compliance (GDPR art. 7(1)) and is exempt from consent under the ePrivacy Directive
Stays on your device — never sent to a server. Contains only the four category flags, a timestamp and a version string.
geo_access_token Necessary localStorage · first-party · app.geoready.dev Keeps you signed in while you use the app. Without it every page load would send you back to the login form.
- Service:
- GeoReady authentication
- Duration:
- Short-lived — replaced on refresh, cleared on logout
- Legal basis:
- Strictly necessary to provide the service you explicitly requested (ePrivacy Directive art. 5(3) exemption); performance of a contract (GDPR art. 6(1)(b))
A signed token identifying your account. Set only after you log in.
geo_refresh_token Necessary localStorage · first-party · app.geoready.dev Lets the app obtain a new access token when the current one expires, so an active session is not interrupted.
- Service:
- GeoReady authentication
- Duration:
- Until it expires server-side or you log out
- Legal basis:
- Strictly necessary to provide the service you explicitly requested (ePrivacy Directive art. 5(3) exemption); performance of a contract (GDPR art. 6(1)(b))
Revoked server-side on logout. Logging out of all devices invalidates every refresh token issued to your account.
ph_<project-token>_posthog Analytics Cookie · first-party · app.geoready.dev Product analytics: tells us which features of the app are used and where people get stuck, so we know what to fix.
- Service:
- PostHog Cloud EU (Frankfurt, Germany)
- Duration:
- 365 days
- Legal basis:
- Consent (GDPR art. 6(1)(a) and ePrivacy Directive art. 5(3))
- Data involved:
- Pseudonymous identifier, pages and features used, clicks, referrer, device and browser type
Until you accept analytics, PostHog runs in cookieless mode: no cookie and no local storage are written, and events are not captured. PostHog is a data processor under a DPA and stores data in the EU.
ph_<project-token>_posthog Analytics localStorage · first-party · app.geoready.dev Mirror of the analytics identifier in local storage, which PostHog uses alongside the cookie.
- Service:
- PostHog Cloud EU (Frankfurt, Germany)
- Duration:
- Until you withdraw consent or clear site data
- Legal basis:
- Consent (GDPR art. 6(1)(a) and ePrivacy Directive art. 5(3))
- Data involved:
- Pseudonymous identifier and session state
Written only after you accept analytics. Removed when you withdraw consent.
__ph_opt_in_out_<project-token> Necessary localStorage · first-party · app.geoready.dev Records that you opted out of product analytics, so the opt-out is honoured on later visits.
- Service:
- PostHog Cloud EU (Frankfurt, Germany)
- Duration:
- Until you change your choice or clear site data
- Legal basis:
- Technical necessity — storing an opt-out is required to give effect to your choice
Holds a single flag. Contains no identifier and no behavioural data.
_ga Analytics Cookie · third-party · app.geoready.dev Measures completed subscriptions so we can tell which marketing spend actually converts.
- Service:
- Google Analytics 4
- Duration:
- 2 years
- Legal basis:
- Consent (GDPR art. 6(1)(a) and ePrivacy Directive art. 5(3))
- Data involved:
- Pseudonymous identifier, the plan purchased and its price, and a transaction reference
Loaded on the payment confirmation page only, and only after you accept analytics — not on any other page of the app. Google Signals and advertising features are off; IP addresses are truncated and not retained for EU visitors.
_ga_<container-id> Analytics Cookie · third-party · app.geoready.dev Keeps session state for the specific GA4 property.
- Service:
- Google Analytics 4
- Duration:
- 2 years
- Legal basis:
- Consent (GDPR art. 6(1)(a) and ePrivacy Directive art. 5(3))
- Data involved:
- Pseudonymous session identifier and session counters
Payment confirmation page only, after analytics consent.
Stripe Checkout cookies Necessary External request · third-party · checkout.stripe.com Set by Stripe on its own checkout page to process your payment and detect fraud. Required to take a payment at all.
- Service:
- Stripe Checkout
- Duration:
- Determined by Stripe — see their policy
- Legal basis:
- Strictly necessary to carry out the payment you requested (ePrivacy Directive art. 5(3) exemption); performance of a contract and legal obligations on fraud prevention
- Data involved:
- Name, email, billing address and payment details you enter on Stripe’s page, plus transaction and fraud-detection signals
Set on checkout.stripe.com, not on this domain, and only if you start a subscription. Card details never reach GeoReady servers. Stripe acts as processor for the payment and as its own controller for fraud prevention.
Fonts: self-hosted and served from this domain. No request to an external CDN, no cookie.
Astro, React, Tailwind: the framework itself sets no cookie and stores nothing.
Backend: the API authenticates with bearer tokens, not session cookies. The server sets no cookie of its own.
Changing or withdrawing your choice
Click the Cookies button at the bottom left of any page. Withdrawing analytics consent takes effect immediately: capture stops, the analytics identifier is cleared, and the matching cookies and storage keys are deleted from your device. Withdrawing is as easy as accepting was — no extra steps, no account required.
Your choice is stored per device and per domain. Setting it here does not change it on geoready.dev, and vice versa — each domain asks separately, as the rules require.
You can also manage cookies in your browser:
Clearing browser storage removes the record of your choice too, so the banner will ask again.
Consent Mode
Where a Google tag is present, the app declares Google Consent Mode v2 with every storage type denied before the tag can initialise, and updates it only after you choose. In practice a Google tag loads on the payment confirmation page only, and only with analytics consent.
Data protection
Who processes your data, on what legal basis, where it goes and how long it is kept: see the Privacy Policy. Questions or requests: juancamilo.auriti@gmail.com.
Updates
When we add or remove something that stores data on your device, this page and the consent version change together. A new consent version means the banner asks again rather than carrying over a choice you made about a different inventory.