Pattio · legal

Cookie policy

Last updated: 11 August 2026 (version 1.0)

1. The short version

This website sets no measurement cookies by default, and neither does the guest portal.

The portal always stores one thing: the anonymous session that lets you open the link someone sent you. Without it there is no page, and that is why we do not ask your permission for it: the law exempts what is strictly necessary from consent.

And only if you press “Accept” on the banner are Google Analytics 4 cookies added. Until you answer, and also if you say no, not a single byte is downloaded from Google.

The Pattio app uses no cookies: the iOS binary contains no Google Analytics, no cookies, no advertising and no trackers.

But the app does write one thing to your device, and this is the place to say so. It has its own pseudonymous product analytics (§3.7 of the Privacy policy) and its measurement service stores a file on the device: a random identifier for this installation and the queue of events still to be sent. It is not a cookie — there is no browser involved — but it is storage on your terminal equipment, which is exactly what article 5.3 of the ePrivacy Directive governs, and so it must not hide behind a “we use no cookies”. It carries nothing of what you write, it cannot follow you from one app to another or across the web, and it is erased when you turn off the switch in Pattio’s Settings ▸ Privacy & security ▸ Privacy.

2. What a cookie is, and why this page talks about more than cookies

A cookie is a small file a website stores in your browser. Next to it there are other stores that play the same role — localStorage, for example — and the law treats them alike: article 5.3 of the ePrivacy Directive — article 22.2 of the Spanish LSSI — is about storing information on your equipment, whatever the technology.

That is why this page lists everything stored in your browser, and says of each item whether it is a cookie or a localStorage entry.

3. What is always stored, and why we do not ask permission

These things are strictly necessary and therefore exempt from consent: without the first the portal link would not open, and the others are precisely what remembers your answer.

If you browse in strict private mode, or if storage is blocked, both the portal and this site still work: what happens is that your choice does not outlive the tab and the banner comes back.

  • sb-…-auth-token (where “…” is the project reference) — localStorage entry — set by the guest portal (Supabase) — keeps the anonymous session the portal uses to read what was shared with you; without it the page cannot open — until you clear your browser data. The token inside expires on its own and is renewed while you use the page.
  • pattio.portal.consent — localStorage entry — set by the guest portal — remembers whether you said yes or no to analytics, so we do not ask again on every visit. It stores three things and nothing else: the version of the purposes, your answer and the date — 12 months. After that the choice expires and the banner asks again.
  • pattio-consent — localStorage entry — set by this website — remembers your choice on this site’s cookie notice, so we do not show it to you again — until you clear your browser data.

4. What is stored only if you say yes

Before measuring anything we show you a banner with two equally easy options: accept and reject. Neither is the preferred one and there is no wall: the page looks exactly the same if you refuse.

Google’s Consent Mode v2 starts with every permission denied by default, and the googletagmanager.com script is never requested unless there is an acceptance.

Both cookies are flagged SameSite=Lax; Secure, and Google signals and ad personalisation, which come on by default, are switched off.

What is NEVER sent to Google from the guest portal, and this is the important part: the link token (the key to the board), any board or item identifier, any guest name, any content. The path that is sent is not the one in the address bar but one of three fixed strings (/convidat, /e or /). The detail of the processing, its legal basis and international transfers are in the Privacy policy (/privacy).

There are no advertising cookies, no social network cookies, no heatmaps and no profiling. There are none because none exist, not because we leave them off the list.

  • _ga — cookie — Google Analytics 4 (Google Ireland Limited / Google LLC) — telling one visit from another so that we can count how many people arrive — 2 years (Google’s default, which we do not change).
  • _ga_IDENTIFIER — cookie — Google Analytics 4 — keeping the measurement session state for the GA4 property — 2 years (same).

5. How to change your mind, and how to delete it all

  • At the foot of this page there is the cookie settings button. It reopens the banner with both options, and works just as well for saying no after you said yes as for the reverse. As soon as you withdraw consent, measurement stops and we delete its cookies.
  • The guest portal’s footer has “Cookies”, which does the same there. That button only appears if analytics is configured: if it is not, there is nothing to withdraw.
  • From your browser you can inspect, block and delete cookies and storage for any site. You will find it in the privacy settings of Safari, Chrome, Firefox or Edge.
  • From Google, if you want to avoid Google Analytics everywhere and not only here, there is the browser opt-out add-on: https://tools.google.com/dlpage/gaoptout.
  • If you delete the consent entry, the banner will ask you again next time. Nothing else changes.

6. Changes and contact

If the purposes ever change, everyone is asked again: the choice is stored with a version, and a “yes” given in 2026 is not valid for a purpose nobody has ever seen.

This page explains what is stored in your browser. The processing done with it — what data, on what legal basis, for how long and what rights you have — is in the Privacy policy (/privacy), and the conditions for using the app are in the Terms and conditions (/terms).

For any question: hola@somiadigital.com.