Cookie Policy
Last updated: September 2026.
The programme’s public pages set no cookies in your browser at all. The few that are used appear only after signing in, in the working areas, and are strictly necessary.
What cookies are
Cookies are small files a website leaves in your browser so it can remember something from one page to the next — for instance, that you have just signed in.
The public pages set no cookies
The home page, the business showcase, each business’s page, your card page and the legal documents can all be browsed without a single cookie. A tourist opening their card from the e-mail receives nothing in the browser.
That is why the programme has no consent banner: there is nothing to ask you about.
Strictly necessary cookies
They appear only after signing in, in the working areas of enrolled businesses, receptions and administrators. Without them sign-in cannot work, which is why the law does not require consent for this category. They are listed below, with the exact names you can check in your own browser.
| Cookie | What it does | How long it lives |
|---|---|---|
__Host-authjs.csrf-token | Protects the sign-in forms against forged requests originating from other sites. | Until the browser is closed |
__Secure-authjs.callback-url | Remembers the page you started signing in from, so you are returned there afterwards. | Until the browser is closed |
__Secure-authjs.session-token | Keeps the session open after sign-in, so your password is not requested on every page. | The working session |
card_unitate | Remembers which business you are working on, when one account manages several. It is a working preference, not an authorisation: permissions are checked on every request regardless. | The working session |
What we do not use
The programme uses no analytics, advertising or cross-site tracking cookies. It loads no third-party scripts that could set their own cookies — no social networks, no heatmaps, no advertising pixels. We build no profiles and sell no data.
Programme statistics are computed from the uses recorded at validation, in aggregate, not from browsing surveillance.
The notice on your first visit
On your first visit a strip appears at the bottom saying, in one sentence, exactly what is written above: the public pages use no cookies. It has a single button, to dismiss it.
Your consent is not requested, because there is nothing to consent to. An “Accept all” button would be a formality: strictly necessary cookies cannot be refused without sign-in ceasing to work, and consent that cannot be refused is not consent.
To remember that you dismissed the notice we do not set a cookie — that would have contradicted the very sentence on the strip. We use a key in your browser’s local storage, td-card-anunt-cookies, which is never sent to the server. You can clear it from your browser settings, and the page footer lets you bring the notice back at any time.
How to control them
Every browser lets you delete or block cookies from its settings. Since all the cookies used here are strictly necessary, blocking them does not affect your access to the public part of the programme — but it makes signing in to the working areas impossible.
Signing out deletes the session cookie.
Relation to personal data
What personal data the programme processes and on what basis are explained in the Privacy Policy. The conditions for using the card are in the Terms and Conditions.

