Skip to content
Legal letguru TENNIS INSIGHTS System · ready
← back to home

Cookie Policy

Last updated: 2026-05-24.

This page explains the cookies (and similar local storage) that ALANDALA SOFTWARE SOLUTIONS SRL uses on letguru.app, the legal basis for each category, and how you control them. Read alongside our Privacy Notice.

Contents
  1. 1. What is a cookie
  2. 2. Legal basis
  3. 3. Categories used on letguru.app
  4. 4. How to manage your consent
  5. 5. Updates to this policy
  6. 6. Contact

1. What is a cookie

A cookie is a small text file stored on your device by your browser when you visit a website. Similar mechanisms (HTML5 localStorage, sessionStorage, IndexedDB) raise the same privacy concerns and are treated identically in this policy.

2. Legal basis

Romanian Law 506/2004 (transposing EU ePrivacy Directive 2002/58/EC) and the EU General Data Protection Regulation (Regulation (EU) 2016/679) require prior, freely-given, specific, informed consent before any non-essential cookie is set. Essential cookies (strictly necessary for the service you requested) are exempt from consent.

3. Categories used on letguru.app

3.1 Essential (no consent required)

  • Access token (__Host-access_token) — short-lived httpOnly cookie issued on successful login; identifies your session for authenticated API requests. Lifetime: ~15 minutes (auto-refreshed by the refresh cookie below).
  • Refresh token (refresh_token) — long-lived httpOnly cookie paired with the access token. Used by our SSR layer to mint a fresh access token before expiry without prompting you to log in. Lifetime: 30 days (sliding window — every refresh extends it).
  • CSRF token (csrf_token) — set on form pages and read back on POST submissions to prevent cross-site-request-forgery. Required to be paired with the refresh cookie on every refresh call. Lifetime: same as the refresh cookie.
  • Cloudflare Turnstile (cf_chl_*) — anti-bot challenge cookies set when the sign-up or login form loads. Lifetime: session-scoped up to 30 minutes depending on challenge type. Vendor: Cloudflare Inc. (Ireland establishment).

3.2 Functional (first-party preference storage)

Consent not typically required under Romanian regulator practice when first-party + purpose-limited to the feature you requested, but listed here for transparency.

  • UI tweaks (letguru.tweaks.v1) — stored in browser localStorage (not a cookie, but treated identically under ePrivacy Article 5(3)). Holds your theme + density preferences so reloads do not flash the default. Lifetime: until you clear browser storage.

3.3 Analytics (cookieless — no consent required)

Planned — not currently active.

  • Umami self-host — first-party analytics served from stats.letguru.app. Cookieless by architecture (daily-rotating IP hash, no device-side storage). Confirmed exempt from Article 5(3) ePrivacy consent under CNIL + EDPB precedent for cookieless tools.

3.4 Marketing / advertising (consent required)

No marketing cookies are currently set on letguru.app. The list below is published in advance so you can preview the categories the consent banner will request once we begin running ad campaigns. Each entry will fire ONLY after you grant marketing-category consent through the banner — and only if we have first deployed the associated tag.

  • Meta Pixel (_fbp, _fbc) — first-party cookies set by Meta's pixel script for ad attribution + retargeting audiences. Lifetime: 90 days. Vendor: Meta Platforms Ireland Ltd. _fbc is set only when you arrive via a Meta ad link carrying a fbclid query parameter.
  • Google Ads (_gcl_au, _gcl_aw) — first-party cookies set by Google's tag for conversion measurement + Enhanced Conversions. Lifetime: up to 90 days. Vendor: Google Ireland Ltd.

4. How to manage your consent

Once our consent banner is live (a self-hosted Klaro consent manager), you will be able to:

  • Accept or reject any non-essential category at first visit.
  • Re-open the consent banner from a footer link to change your choice at any time.
  • Withdraw consent retroactively — withdrawal triggers active deletion of the relevant cookies on next page load.

Browser-level controls (Settings → Privacy → Cookies) override our banner. You can also block third-party cookies entirely; the site will continue to work, with reduced analytics + marketing functionality.

5. Updates to this policy

When we add a new processor (vendor) or category we update this page in the same release that ships the change. The "Last updated" date at the top reflects the most recent material change. Significant additions (a new category, or a vendor in a country with no GDPR adequacy) re-prompt the consent banner.

6. Contact

Questions about cookies or to exercise your data subject rights: privacy@letguru.app. See the Privacy Notice § 8 for the full rights list + response timelines.

How it works · Roadmap · Privacy · Imprint · Terms · Cookies · Contact ·