Cookie policy
Draft pending legal review. This document has yet to be reviewed by a lawyer and may change.
1. What cookies are
Cookies are small files that a website stores in your browser to remember something from one page to the next: for example, that you have signed in with your password, or which language you want to read in. This policy also covers other ways of storing information in the browser, such as local storage (localStorage).
2. We only use technical cookies
validpass.app only uses technical cookies: those needed for what you ask for to work, and those that remember a preference you have chosen yourself. None of them is used to track you or for advertising. They are all our own, except for the Cloudflare cookies explained below. Our own cookies are also protected by your browser: scripts on the page cannot read them, and they are only sent over encrypted connections.
On the public website and the card pages
- lang: remembers the language you have chosen. It is only stored if you choose one, or when you sign in to the board area if you had chosen a language there. Lasts 1 year.
- theme: remembers whether you want the website in light or dark mode. It is only stored if you press the sun or moon button. Lasts 1 year.
In the board area (only if you sign in)
- adm_session: keeps the session of whoever has signed in open. It is signed so that it cannot be forged. Lasts 12 hours, or until you sign out.
- adm_tria: if your email address belongs to the board of more than one association, remembers for 10 minutes which ones you can choose, so that we do not have to ask for your password again.
- adm_flash: shows the confirmation or error message after you save a form. It is deleted once shown and lasts 1 minute at most.
- validpass.a4.back (browser local storage): when you print cards on A4 sheets, remembers the back-side adjustment for your printer. It is never sent to us and stays in your browser until you delete it.
On the internal management address
Only ValidPass staff use it, to support the associations:
- adm_assoc: remembers which association is being supported. Lasts 12 hours.
- CF_Authorization: set by Cloudflare Access, the system staff use to identify themselves; it lasts as long as that session.
Cloudflare security cookies
Cloudflare, the provider that hosts the website and protects it from attacks, may set a cookie of its own when it needs to tell people from bots:
- __cf_bm: tells human traffic from bot traffic. Lasts 30 minutes.
- cf_clearance: remembers that you have already passed a Cloudflare security check, so that you are not asked again. Short-lived (30 minutes by default).
They are technical and are only used for security. You will find more information on Cloudflare’s page about its cookies.
3. No analytics or advertising cookies
We do not use analytics, advertising or social media cookies or tools, nor content from other websites that sets them (videos, maps, external fonts): we serve the fonts ourselves, for example. That is why we do not show you a banner asking for consent: the law does not require it for technical cookies (LSSI-CE, Article 22.2).
4. How to delete or block them
You can delete or block them in your browser settings. If you block them, the public website will still work, but it will not remember your language or theme, and you will not be able to sign in to the board area.
5. If this changes
- If we ever add a cookie or tool that is not strictly necessary (for example, to measure visits or for advertising), we will not use it until you have accepted it. We will ask you first with a banner that lets you accept or reject it just as easily, and you will be able to change your mind at any time.
- If we use a measurement tool that stores nothing in your browser (such as Cloudflare Web Analytics), we will say so here and in the privacy policy.
- In both cases, we will update this policy before the change.
6. Contact
This website belongs to Treserras Multimèdia SL. If you have any questions about cookies, email us at info@validpass.app.