Legal · Cookies
Cookie Policy
Last updated: · v2026.05.17
1. What is a cookie
A “cookie” is a small text file a website stores in your browser. Some are essential to make a site work (such as the cookie that keeps you logged in); others are used for analytics or advertising (we don't use those). This Policy explains what we set and why, and is published under the EU/UK ePrivacy Directive, the Turkish Communications Law, and analogous requirements.
2. Categories of cookies we set
- Strictly necessary. Required for the Service to function (sign-in, secure payment, fraud prevention, consent storage). These do not require consent under the ePrivacy Directive.
- Functional. Remember your preferences (language). Sets only after you interact in a way that implies the preference (e.g. choosing a language).
- Security.Anti-abuse signals such as Cloudflare's bot-management cookie and our trial-abuse rotation cookie.
- Marketing / analytics third-party cookies — we do not use these.
3. Full cookie inventory
| Name | Set by | Purpose | Type | Duration |
|---|---|---|---|---|
| sb-access-token, sb-refresh-token | Supabase | Authenticated session — keeps you signed in. | Strictly necessary | Session + 7 days (refresh) |
| NEXT_LOCALE | First-party (Poi Geo) | Remembers your language preference. | Functional | 1 year |
| __cf_bm | Cloudflare | Bot-management heuristic on our edge. | Security | 30 minutes |
| pg_demo | First-party (Poi Geo) | Anti-trial-abuse signal (rotates on use). | Security | 30 days |
4. No advertising or cross-site tracking
We do not allow advertising networks, social-media plug-ins, or analytics vendors that combine data across sites to set cookies on our domain. We do not engage in “cross-context behavioural advertising” within the meaning of the California CCPA/CPRA. We do not respond to Global Privacy Control signals because we do not engage in any sale or sharing that they would govern.
5. Local storage & similar technologies
The Service uses a small amount of localStorage to cache map-tile preferences and recent analyses on your device, and uses sessionStorage for transient UI state. These behave like cookies for the purposes of this Policy.
We use a non-tracking browser fingerprint hash — a one-way hash of canvas and WebGL render output — solely for anti-trial-abuse detection. It is described in the Privacy Policy §3 and is retained for no more than 30 days.
6. Managing cookies in your browser
7. Region-specific consent
Every cookie listed in Section 3 is either strictly necessary (sign-in, payment-fraud prevention), security (bot management, trial-abuse rotation), or functional and set only on explicit user action (language choice after you switch the locale switcher). Under EU/UK/Swiss/Brazilian law these categories are exempt from prior consent (ePrivacy Directive Art. 5(3) exception; UK ICO guidance; Swiss FADP; LGPD Art. 7(II)/(V)/(IX)). Consequently, no consent banner is shown.
If at any future point we add cookies that do require consent (analytics, marketing, third-party tracking), we will deploy a region-aware consent interface before activating those cookies, and this Policy will be updated accordingly.
California / other U.S. opt-out states:we do not engage in “sale” or “sharing” as defined by the CCPA/CPRA, and we do not engage in cross-context behavioural advertising. There is therefore nothing to opt out of; nevertheless, you may write to privacy@poigeo.app and we will confirm in writing.
Türkiye: KVKK Article 5(2)(c) and (f) cover cookies necessary to perform a contract and for legitimate interest balanced against your fundamental rights — both apply to the inventory above. No further explicit consent is collected because none is legally required.
8. Changes to this Policy
We may add, remove, or change cookies as the Service evolves. The inventory above will be kept current and the “Last updated” date reflects the most recent revision.