Cookie Policy
Last updated: 29 July 2026
Manage your cookie choices at any time:
This Cookie Policy explains how DPA Tech Solutions SRL uses cookies, local storage and similar technologies on the WhereU website, the native apps for Android and iOS, and the in-app web views.
This page is maintained by DPA Tech Solutions SRL. It describes the current behaviour of the Service and is not a certification.
1. What we mean by "cookies"
"Cookies" here covers browser cookies as well as related client-side storage that we treat under the same consent rules: localStorage, sessionStorage, IndexedDB, service workers, and — in the native apps — the equivalent secure device storage (Keychain on iOS, EncryptedSharedPreferences on Android) plus push notification tokens (APNs / FCM).
2. Categories we use
| Category | Purpose | Consent |
|---|---|---|
| Strictly necessary | Authentication (Supabase session), CSRF/security, load balancing, saving your language and cookie choice, PWA service worker for offline shell. | Not required |
| Functional | Map centre and zoom, dark/light theme, Ghost Mode preference, Pulse sensitivity, location tracker preset (Battery / Balanced / Precise), notification preferences, onboarding progress, saved places filter, radial menu state. | Set by you when you change the setting |
| Payments | Stripe Checkout, WhereU PRO subscriptions and ticket purchases use Stripe's own cookies for fraud prevention and 3D Secure. These load only when you open a checkout. | Required to complete a payment |
| Push notifications | Device token stored for friend live status, proximity alerts, pings, DMs and ticket confirmations. Web push uses your browser's push service. | You grant it in the OS/browser permission prompt |
| Analytics | Aggregated, privacy-friendly usage statistics to understand which features to invest in. No cross-site tracking, no advertising profiles. | Optional — asked via the consent banner |
3. Third parties that set cookies or receive data
- Supabase — authentication token and session (necessary).
- Stripe — payments, subscription management and fraud prevention when you open Checkout or the billing portal.
- Mapbox and OpenStreetMap-based routing (OSRM) — required to render the interactive map and draw routes to friends.
- Cloudflare — TLS termination, DDoS protection and static asset caching for whereu.fun and its subdomains.
- Apple Push Notification service and Firebase Cloud Messaging — deliver push notifications to iOS and Android devices when you opt in.
4. Location, background permissions and PWA
Location is not a cookie but is asked for separately by your OS or browser. On Android and iOS we may request background location so features like proximity alerts and stop detection keep working when the app is not in the foreground; you can revoke this at any time from your device settings. The PWA service worker stores an offline copy of the app shell and can be removed from your browser's site settings or by adding?sw=off to the URL.
5. Managing your choices
Use the Manage cookie preferences button above to change your consent for optional categories at any time. You can also clear or block cookies from your browser settings; blocking strictly necessary cookies will break login and most features. To withdraw consent for analytics or push notifications, use the in-app Notifications and Settings screens, or write to privacy@whereu.fun.
6. Retention
Session cookies live until you sign out or close the browser. Functional preferences persist on your device until you clear them. Push tokens are removed when you disable notifications or uninstall the app. Payment cookies are governed by Stripe's own policy.
7. Updates
We update this Cookie Policy when we add or remove technologies, integrations or categories. The "Last updated" date above always reflects the current version.