Cookie Policy
1. About this Cookie Policy
This Cookie Policy explains how Alovibe ("Alovibe", "we", "us", or "our") uses cookies and similar local-storage technologies when you use the Alovibe web application, our public marketing pages, and the booking and storefront pages that businesses publish through the Service (together, the "Service"). It describes what these technologies are, which ones we actually set, why we set them, the legal basis on which we rely, and how you can control them.
Alovibe is operated by NEXGEN SKYLINEX, S.L., with its registered office at Paseo Virgen del Puerto 51, 28005 Madrid, Spain. This Cookie Policy forms part of, and should be read together with, our Privacy Policy, which explains in more detail how we process personal data and the roles we play (controller or processor) in respect of different categories of data. Capitalised terms not defined here have the meaning given to them in our Privacy Policy and Terms of Service.
We deliberately keep our use of cookies and similar technologies minimal and functional. Alovibe does not use advertising cookies, does not engage in cross-site or cross-device tracking, does not build advertising profiles, and does not sell or share data collected through cookies for advertising purposes. We also do not load any first-party analytics cookie or analytics script through the Service.
2. What cookies and similar technologies are
A "cookie" is a small text file that a website asks your browser to store on your device. When you return to the site, your browser sends the cookie back, which allows the site to recognise your session, remember your settings, or keep you securely signed in. Cookies set by the website you are visiting are called first-party cookies; cookies set by another domain (for example, an embedded payment provider) are called third-party cookies.
Cookies may be session cookies, which are deleted when you close your browser, or persistent cookies, which remain on your device until they expire or you delete them.
Alovibe also relies on related browser technologies that are not technically cookies but serve similar purposes:
- Local storage (the browser's `localStorage` API), which lets the application save small preference values on your device so they persist between visits. Unlike cookies, local-storage values are not automatically transmitted to our servers with every request; they are read by the application running in your browser.
- Session storage and in-memory state, which the application may use transiently while a page is open and which are cleared when the page or tab is closed.
This policy refers to all of these technologies collectively as "cookies and similar technologies".
3. Categories of cookies and storage we use
We classify the cookies and similar technologies we use into the following categories.
(a) Strictly necessary. Essential for the Service to function. They enable core features such as secure authentication, keeping you signed in, maintaining your session across pages, and basic security. The Service cannot operate without them, and they cannot be switched off through our consent mechanism.
(b) Functional / preference. Remember choices you make to personalise your experience, such as your interface language, display currency, and light/dark theme. If you decline or clear these, the Service still works, but it will not remember those preferences and will fall back to defaults.
(c) Consent-state. A single value that records the choice you made in our cookie banner, so that we do not ask you again on every visit.
(d) Analytics / advertising. Alovibe does not set any first-party analytics, advertising, or tracking cookies. No advertising or cross-site tracking technology is loaded by the Service. This category is described here only for completeness and transparency.
4. The specific cookies and storage we set
The tables below list the cookies and browser-storage items that Alovibe itself sets, including the voice-booking session storage described in Section 4.3. This reflects what the application uses today.
4.1 Cookies
| Name | Type | Category | Purpose | Duration |
|---|---|---|---|---|
| `av_sess` | First-party cookie | Strictly necessary | The single session cookie Alovibe sets. It holds an opaque, randomly generated session identifier that is resolved against our server-side session store to keep account owners and team members securely signed in. It is set with the `HttpOnly`, `SameSite=Lax`, and (in production) `Secure` attributes and `Path=/`, so it cannot be read by client-side scripts and is sent only over HTTPS. It carries no personal data itself — only the opaque identifier. | Up to 30 days by default. If "Remember me" is left unchecked at sign-in, it is set as a browser-session cookie (with no expiry attribute, so it is removed when you close your browser) backed by a server-side time-to-live of approximately 24 hours. It is deleted when you sign out and is rotated and invalidated on sign-in, password change, and account deletion. |
`av_sess` is the only cookie Alovibe sets.
4.2 Browser local storage
The following preference values are stored in your browser's local storage. They remain on your device until you clear them and are not advertising or tracking identifiers.
| Key | Category | Purpose |
|---|---|---|
| `av-lang` | Functional / preference | Remembers your chosen interface language. |
| `av-cur` | Functional / preference | Remembers your chosen display currency. |
| `av-theme` | Functional / preference | Remembers your light/dark theme choice. |
| `alovibe_cookie_consent` | Consent-state | Stores your single cookie-banner choice (`accepted` or `declined`) so the banner is not shown to you again. This is the only thing the consent banner persists. |
| `alovibe_w_<business>` | Functional / preference | On a business's public voice-booking page, an anonymous per-visitor identifier (a random string, not your name or contact details) used to apply per-visitor usage limits and to link your voice session. It is not an advertising or cross-site tracking identifier. It persists on your device until you clear it. |
4.3 Voice-booking session storage
On a business's public voice-booking page, if you type your contact details to start a call, the Service saves them in your browser's session storage so that the booking form stays pre-filled for the rest of that visit:
| Key | Storage | Category | Purpose |
|---|---|---|---|
| `alovibe_voice_contact_<business>` | Session storage | Functional / preference | Holds the name, email address, and phone number you typed on that business's voice-booking page, so you do not have to re-enter them while you are on the page. Because it is kept in session storage, it is cleared automatically when you close the browser tab and is not stored on our servers as an identifier. |
Unlike the interface-preference keys above, this value contains the contact details you entered, so it is personal to you. It lives only in your own browser for that session and is used solely to pre-fill the booking form.
We may also use a small number of additional local-storage keys to remember minor interface state — for example whether you have collapsed a navigation panel or dismissed an in-app prompt. Apart from the voice-booking contact details described above (which you enter yourself and which are personal to you), these interface-state keys are cosmetic preferences saved on your device and are not advertising or cross-site tracking identifiers.
By default, any non-essential analytics or tracking is treated as declined, and — because Alovibe loads no analytics or advertising technology — none is loaded regardless of your choice.
5. Cookies on public booking and storefront pages
When a customer visits a business's public booking or storefront page hosted on Alovibe, the same approach applies: only what is strictly necessary to display the page and complete a booking, order, or payment is used, together with the same functional preferences described above (such as language and currency). No advertising or cross-site tracking cookies are set on these pages.
Where a page requires access to a device feature — for example, the microphone on the voice-booking page — that access is requested explicitly by your browser at the time the feature is used and is governed by your browser's own permission controls, not by a cookie. The voice-booking feature is enabled by default, though a business can turn it off in its settings, in which case it is not offered on the page.
6. Third-party cookies and external providers
Alovibe itself does not embed third-party advertising, analytics, or social-media cookies, and the third-party providers we rely on to deliver the Service generally operate on the server side rather than by setting cookies in your browser.
(a) Payment (Stripe). The one situation in which a third party may set cookies through the Service is payment. Card and other payments are processed by Stripe. When you reach a Stripe-hosted checkout page or interact with Stripe's embedded payment element, Stripe may set its own cookies on its own domain — for example, to enable secure payment processing and to help detect and prevent fraud. These cookies are set and controlled by Stripe under Stripe's own cookie and privacy policies, not by Alovibe, and Alovibe does not control or have access to them. We recommend reviewing Stripe's policies (available at stripe.com) for details. Stripe acts as an independent controller for the data it collects in connection with payment processing.
(b) Server-side providers. Other third-party services that Alovibe relies on to deliver the Service — including our AI provider (OpenAI), our email-delivery provider (Resend), and the messaging platforms a business connects (such as Meta's WhatsApp, Instagram, and Facebook, and Telegram) — operate on the server side and do not set cookies on your browser through your use of Alovibe. Where you communicate with a business over an external messaging channel, any cookies set by those platforms when you use *their* own apps or sites are governed by those platforms' own policies and are entirely outside Alovibe's control. A full list of the service providers (sub-processors) we use is set out in our Privacy Policy and Data Processing Agreement.
(c) Optional error monitoring. We use an optional error-monitoring tool to detect and diagnose technical problems. Where it is enabled, it may use a limited amount of browser storage to correlate and de-duplicate error reports during a single visit. It is not used for advertising, analytics, or cross-site tracking, and it captures technical error context (such as the page and stack trace involved) rather than building a profile of you.
7. Legal basis for using cookies and similar technologies
Under the EU and UK ePrivacy rules and the General Data Protection Regulation (GDPR / UK-GDPR), our legal basis for these technologies depends on their category:
- Strictly necessary cookies and storage (the `av_sess` session cookie and the consent-state value) are exempt from the consent requirement because they are essential to provide a service you have explicitly requested. To the extent they involve processing of personal data, we rely on our legitimate interests (and, where applicable, the performance of a contract with you) in operating the Service securely and reliably.
- Functional / preference storage (`av-lang`, `av-cur`, `av-theme`, and similar interface-state keys) is used to honour the choices you make. Where consent is required for these in your jurisdiction, we rely on your consent; otherwise we rely on our legitimate interests in providing a usable, personalised interface. These items remain on your device and are read locally by the application.
- Analytics and advertising cookies — we set none, so no consent is sought or required for them.
You can withdraw consent or change your choices at any time as described in Section 8. Withdrawing consent does not affect the lawfulness of any processing carried out before withdrawal.
8. How to control cookies and storage
You have several ways to control cookies and similar technologies.
(a) Our in-app consent banner. When you first visit, we present a cookie banner. It does not block the page; it is a dismissible notice. Choosing "Accept" or "Decline" records your choice in the `alovibe_cookie_consent` value so we do not ask again, and nothing non-essential is set either way. Because Alovibe loads no analytics or advertising technology, declining does not reduce the functionality of the Service — the strictly necessary session cookie remains in place so you can sign in and use the Service. To make a new choice, you can clear the `alovibe_cookie_consent` value (by clearing your browser's local storage for our site) and the banner will reappear on your next visit.
(b) Your browser settings. All major browsers let you view, block, and delete cookies and clear local storage. You can usually find these controls in your browser's privacy or security settings, and you can set your browser to warn you before accepting cookies or to refuse them entirely. Helpful instructions are available in the help pages of your browser (for example Chrome, Firefox, Safari, and Edge). Please note:
- If you block or delete the strictly necessary `av_sess` session cookie, you will not be able to sign in to the Service or will be signed out.
- If you clear local storage, your interface preferences (language, currency, theme) and your saved cookie-banner choice will be reset.
(c) Device and platform controls. Many devices and operating systems offer additional privacy controls (such as "Do Not Track" or "Global Privacy Control" signals). Because Alovibe does not perform cross-site tracking or sell personal data, there is no tracking behaviour for these signals to disable; we will continue to honour our no-tracking commitment regardless of the signal sent.
9. Cookies and your privacy rights
Depending on where you live, you may have rights in relation to personal data processed through cookies and similar technologies — including the right to access, correct, delete, or port your data, to object to or restrict certain processing, and to withdraw consent. Residents of California and certain other U.S. states have analogous rights under laws such as the California Consumer Privacy Act (CCPA/CPRA), including the right to know what personal information is collected and the right to opt out of the "sale" or "sharing" of personal information. Alovibe does not sell or share personal information for cross-context behavioural advertising and does not use cookies for that purpose, so there is no such activity to opt out of; nonetheless, you may exercise your rights as described in our Privacy Policy.
How these rights apply depends on the role Alovibe plays. For data relating to your Alovibe account, login, and security (including the `av_sess` session cookie), Alovibe acts as the controller. For personal data that a business processes about its own end customers through the Service, that business is the controller and Alovibe acts as its processor; end customers should direct requests about such data to the relevant business. Full details, including how to exercise your rights, are set out in our Privacy Policy.
10. Changes to this Cookie Policy
We may update this Cookie Policy from time to time — for example, to reflect changes in the technologies we use, in the Service, or in applicable law. When we do, we will revise the "Last updated" date at the top of this page and, where the changes are material, we will take reasonable steps to bring them to your attention. We encourage you to review this policy periodically. Your continued use of the Service after an update takes effect constitutes acceptance of the revised policy, except where additional consent is required by law.
11. Contact
If you have any questions about this Cookie Policy or about how we use cookies and similar technologies, please contact us at:
- Email: privacy@alovibe.com (general support: support@alovibe.app)
- Postal address: NEXGEN SKYLINEX, S.L., Paseo Virgen del Puerto 51, 28005 Madrid, Spain
If you are located in the European Economic Area or the United Kingdom and have unresolved concerns, you also have the right to lodge a complaint with your local data protection authority.
This Cookie Policy is governed by and construed in accordance with Spain.