Cookie Policy

Last updated: 29 July 2026

Manage your cookie choices at any time:

This Cookie Policy explains how DPA Tech Solutions SRL uses cookies, local storage and similar technologies on the WhereU website, the native apps for Android and iOS, and the in-app web views.

This page is maintained by DPA Tech Solutions SRL. It describes the current behaviour of the Service and is not a certification.

1. What we mean by "cookies"

"Cookies" here covers browser cookies as well as related client-side storage that we treat under the same consent rules: localStorage, sessionStorage, IndexedDB, service workers, and — in the native apps — the equivalent secure device storage (Keychain on iOS, EncryptedSharedPreferences on Android) plus push notification tokens (APNs / FCM).

2. Categories we use

CategoryPurposeConsent
Strictly necessaryAuthentication (Supabase session), CSRF/security, load balancing, saving your language and cookie choice, PWA service worker for offline shell.Not required
FunctionalMap centre and zoom, dark/light theme, Ghost Mode preference, Pulse sensitivity, location tracker preset (Battery / Balanced / Precise), notification preferences, onboarding progress, saved places filter, radial menu state.Set by you when you change the setting
PaymentsStripe Checkout, WhereU PRO subscriptions and ticket purchases use Stripe's own cookies for fraud prevention and 3D Secure. These load only when you open a checkout.Required to complete a payment
Push notificationsDevice token stored for friend live status, proximity alerts, pings, DMs and ticket confirmations. Web push uses your browser's push service.You grant it in the OS/browser permission prompt
AnalyticsAggregated, privacy-friendly usage statistics to understand which features to invest in. No cross-site tracking, no advertising profiles.Optional — asked via the consent banner

3. Third parties that set cookies or receive data

  • Supabase — authentication token and session (necessary).
  • Stripe — payments, subscription management and fraud prevention when you open Checkout or the billing portal.
  • Mapbox and OpenStreetMap-based routing (OSRM) — required to render the interactive map and draw routes to friends.
  • Cloudflare — TLS termination, DDoS protection and static asset caching for whereu.fun and its subdomains.
  • Apple Push Notification service and Firebase Cloud Messaging — deliver push notifications to iOS and Android devices when you opt in.

4. Location, background permissions and PWA

Location is not a cookie but is asked for separately by your OS or browser. On Android and iOS we may request background location so features like proximity alerts and stop detection keep working when the app is not in the foreground; you can revoke this at any time from your device settings. The PWA service worker stores an offline copy of the app shell and can be removed from your browser's site settings or by adding?sw=off to the URL.

5. Managing your choices

Use the Manage cookie preferences button above to change your consent for optional categories at any time. You can also clear or block cookies from your browser settings; blocking strictly necessary cookies will break login and most features. To withdraw consent for analytics or push notifications, use the in-app Notifications and Settings screens, or write to privacy@whereu.fun.

6. Retention

Session cookies live until you sign out or close the browser. Functional preferences persist on your device until you clear them. Push tokens are removed when you disable notifications or uninstall the app. Payment cookies are governed by Stripe's own policy.

7. Updates

We update this Cookie Policy when we add or remove technologies, integrations or categories. The "Last updated" date above always reflects the current version.