Salta al contenuto principale
GeoReady App Cookie Policy

Cookie Policy

Last updated: August 5, 2026 · Consent version v2.0

This page covers app.geoready.dev, the GeoReady application. The inventory below is generated from the same configuration the consent banner uses, so what you read here is what the app actually does. For the public website see the cookie policy on geoready.dev.

Cookies, local storage, and why both matter

A cookie is a small file a site stores on your device. Browsers also offer localStorage, which does the same job without sending anything back with each request. The law treats them the same way: storing or reading information on your device needs your consent unless it is strictly necessary to provide what you asked for (ePrivacy Directive art. 5(3)). We list both below and ask for consent for both.

Because the app is a signed-in tool, most of what it stores is the session itself — that is the strictly necessary part, and it exists only after you log in.

Your choice also travels as a signal. Through Google Consent Mode v2 this domain declares all four Google consent types — analytics storage, ad storage, ad user data and ad personalisation — as denied before any Google tag can run, and updates them only when you decide. Because the Analytics property is linked to Google Ads so the subscription conversion can be attributed to a campaign, that declaration is what keeps a refusal meaningful on Google's side rather than only on ours. No advertising cookie is set here in either case.

Categories

1. Necessary

always on

Essential for the app to work: keeping you signed in, taking a payment, and storing your privacy choice itself. Cannot be disabled.

5 item(s) — see the inventory below.

2. Preferences

off unless you accept

Remember settings and choices you make so they persist between visits.

Nothing is stored in this category today.

3. Analytics

off unless you accept

Let us see which parts of the app are used and which subscriptions complete, through PostHog and — on the payment confirmation page only — Google Analytics. Off unless you accept.

4 item(s) — see the inventory below.

4. Marketing

off unless you accept

Governs advertising signals. No marketing cookie or tracker is set on this domain, and no advertising tag is loaded. What this controls is the ad-related consent sent to Google: accepting lets the subscription conversion, measured on the payment confirmation page, be attributed in full in Google Ads; declining keeps it limited.

Nothing is stored in this category today.

Full inventory

Every cookie, storage key and third-party request the app can create, with the legal basis for each. Names shown with <…> contain a project or container identifier that varies.

Name Category Type Provider Duration
geo_cookie_consent Necessary localStorage GeoReady 6 months, or until the consent version changes
geo_access_token Necessary localStorage GeoReady Short-lived — replaced on refresh, cleared on logout
geo_refresh_token Necessary localStorage GeoReady Until it expires server-side or you log out
ph_<project-token>_posthog Analytics Cookie PostHog Inc. 365 days
ph_<project-token>_posthog Analytics localStorage PostHog Inc. Until you withdraw consent or clear site data
__ph_opt_in_out_<project-token> Necessary localStorage PostHog Inc. Until you change your choice or clear site data
_ga Analytics Cookie Google Ireland Limited / Google LLC 2 years
_ga_<container-id> Analytics Cookie Google Ireland Limited / Google LLC 2 years
Stripe Checkout cookies Necessary External request Stripe, Inc. / Stripe Payments Europe Ltd. Determined by Stripe — see their policy
geo_cookie_consent Necessary localStorage · first-party · app.geoready.dev

Stores your cookie and privacy choices so you are not asked again on every visit, and so the choice can be honoured before any non-essential script loads.

Service:
GeoReady Consent Manager
Duration:
6 months, or until the consent version changes
Legal basis:
Technical necessity — recording a consent choice is required to demonstrate compliance (GDPR art. 7(1)) and is exempt from consent under the ePrivacy Directive

Stays on your device — never sent to a server. Contains only the four category flags, a timestamp and a version string.

geo_access_token Necessary localStorage · first-party · app.geoready.dev

Keeps you signed in while you use the app. Without it every page load would send you back to the login form.

Service:
GeoReady authentication
Duration:
Short-lived — replaced on refresh, cleared on logout
Legal basis:
Strictly necessary to provide the service you explicitly requested (ePrivacy Directive art. 5(3) exemption); performance of a contract (GDPR art. 6(1)(b))

A signed token identifying your account. Set only after you log in.

geo_refresh_token Necessary localStorage · first-party · app.geoready.dev

Lets the app obtain a new access token when the current one expires, so an active session is not interrupted.

Service:
GeoReady authentication
Duration:
Until it expires server-side or you log out
Legal basis:
Strictly necessary to provide the service you explicitly requested (ePrivacy Directive art. 5(3) exemption); performance of a contract (GDPR art. 6(1)(b))

Revoked server-side on logout. Logging out of all devices invalidates every refresh token issued to your account.

ph_<project-token>_posthog Analytics Cookie · first-party · app.geoready.dev

Product analytics: tells us which features of the app are used and where people get stuck, so we know what to fix.

Service:
PostHog Cloud EU (Frankfurt, Germany)
Duration:
365 days
Legal basis:
Consent (GDPR art. 6(1)(a) and ePrivacy Directive art. 5(3))
Data involved:
Pseudonymous identifier, pages and features used, clicks, referrer, device and browser type

Until you accept analytics, PostHog runs in cookieless mode: no cookie and no local storage are written, and events are not captured. PostHog is a data processor under a DPA and stores data in the EU.

Provider privacy policy →

ph_<project-token>_posthog Analytics localStorage · first-party · app.geoready.dev

Mirror of the analytics identifier in local storage, which PostHog uses alongside the cookie.

Service:
PostHog Cloud EU (Frankfurt, Germany)
Duration:
Until you withdraw consent or clear site data
Legal basis:
Consent (GDPR art. 6(1)(a) and ePrivacy Directive art. 5(3))
Data involved:
Pseudonymous identifier and session state

Written only after you accept analytics. Removed when you withdraw consent.

Provider privacy policy →

__ph_opt_in_out_<project-token> Necessary localStorage · first-party · app.geoready.dev

Records that you opted out of product analytics, so the opt-out is honoured on later visits.

Service:
PostHog Cloud EU (Frankfurt, Germany)
Duration:
Until you change your choice or clear site data
Legal basis:
Technical necessity — storing an opt-out is required to give effect to your choice

Holds a single flag. Contains no identifier and no behavioural data.

Provider privacy policy →

_ga Analytics Cookie · third-party · app.geoready.dev

Measures completed subscriptions so we can tell which marketing spend actually converts.

Service:
Google Analytics 4
Duration:
2 years
Legal basis:
Consent (GDPR art. 6(1)(a) and ePrivacy Directive art. 5(3))
Data involved:
Pseudonymous identifier, the plan purchased and its price, and a transaction reference

Loaded on the payment confirmation page only, and only after you accept analytics — not on any other page of the app. Google Signals and advertising features are off; IP addresses are truncated and not retained for EU visitors.

Provider privacy policy →

_ga_<container-id> Analytics Cookie · third-party · app.geoready.dev

Keeps session state for the specific GA4 property.

Service:
Google Analytics 4
Duration:
2 years
Legal basis:
Consent (GDPR art. 6(1)(a) and ePrivacy Directive art. 5(3))
Data involved:
Pseudonymous session identifier and session counters

Payment confirmation page only, after analytics consent.

Provider privacy policy →

Stripe Checkout cookies Necessary External request · third-party · checkout.stripe.com

Set by Stripe on its own checkout page to process your payment and detect fraud. Required to take a payment at all.

Service:
Stripe Checkout
Duration:
Determined by Stripe — see their policy
Legal basis:
Strictly necessary to carry out the payment you requested (ePrivacy Directive art. 5(3) exemption); performance of a contract and legal obligations on fraud prevention
Data involved:
Name, email, billing address and payment details you enter on Stripe’s page, plus transaction and fraud-detection signals

Set on checkout.stripe.com, not on this domain, and only if you start a subscription. Card details never reach GeoReady servers. Stripe acts as processor for the payment and as its own controller for fraud prevention.

Provider privacy policy →

Fonts: self-hosted and served from this domain. No request to an external CDN, no cookie.

Astro, React, Tailwind: the framework itself sets no cookie and stores nothing.

Backend: the API authenticates with bearer tokens, not session cookies. The server sets no cookie of its own.

Changing or withdrawing your choice

Click the Cookies button at the bottom left of any page. Withdrawing analytics consent takes effect immediately: capture stops, the analytics identifier is cleared, and the matching cookies and storage keys are deleted from your device. Withdrawing is as easy as accepting was — no extra steps, no account required.

Your choice is stored per device and per domain. Setting it here does not change it on geoready.dev, and vice versa — each domain asks separately, as the rules require.

You can also manage cookies in your browser:

Clearing browser storage removes the record of your choice too, so the banner will ask again.

Consent Mode

Where a Google tag is present, the app declares Google Consent Mode v2 with every storage type denied before the tag can initialise, and updates it only after you choose. In practice a Google tag loads on the payment confirmation page only, and only with analytics consent.

Data protection

Who processes your data, on what legal basis, where it goes and how long it is kept: see the Privacy Policy. Questions or requests: juancamilo.auriti@gmail.com.

Updates

When we add or remove something that stores data on your device, this page and the consent version change together. A new consent version means the banner asks again rather than carrying over a choice you made about a different inventory.