1. What this Policy covers
This Policy explains cookies and similar browser technologies used by PicchuSpot. A cookie is a small value stored by the browser and sent with relevant requests. Local storage and session storage are browser-held values that are not automatically sent like cookies but can serve similar preference or continuity purposes.
The current site uses necessary technology, user-requested functional preferences, on-demand support technology and optional analytics. This Policy should be read with the Privacy Policy.
2. Your analytics choice
The consent banner offers Reject and Accept analytics. Before a choice, Google Consent Mode defaults analytics and advertising-related consent to denied. PicchuSpot enables its Google Analytics page-view setup and analytics events only after acceptance. Advertising storage, advertising user data and advertising personalisation remain denied.
The Google tag can initialise in denied mode. Depending on Google's consent-mode behaviour, limited cookieless consent and technical signals may be transmitted even though PicchuSpot has not enabled its page-view and event measurement. Rejecting prevents PicchuSpot from granting analytics storage.
You can change the choice at any time using Cookie settings in the footer. Withdrawing consent affects future use and does not undo processing that was lawful before withdrawal.
3. PicchuSpot cookies and browser storage
Authentication session
- Storage
- Necessary first-party cookies managed through Supabase
- Purpose
- Sign-in, session continuity and server-side authentication
- When used
- When account/authentication features are used
- Duration
- Session/security configuration; may be refreshed or removed at sign-out
picchuspot_cookie_consent
- Storage
- Local storage
- Purpose
- Remember accepted or rejected analytics choice
- When used
- After a banner choice
- Duration
- Until changed in Cookie settings or browser storage is cleared
picchuspot_language / picchuspot-language
- Storage
- One-year first-party cookie / local storage
- Purpose
- Remember the language selected by the user
- When used
- After a language choice
- Duration
- Cookie: one year; local storage: until replaced or cleared
picchuspot_region and picchuspot_currency
- Storage
- One-year first-party cookies
- Purpose
- Remember selected region and display currency
- When used
- After a region/currency choice
- Duration
- One year
picchuspot-region and picchuspot-currency
- Storage
- Local storage
- Purpose
- Keep the selected region and currency consistent in the browser
- When used
- After a region/currency choice
- Duration
- Until replaced or cleared
Order, draft and support-prefill recovery
- Storage
- Session storage
- Purpose
- Recover limited form state or continue an order action during the browser session
- When used
- When the relevant form/action is used
- Duration
- Browser session or earlier removal after completion
picchuspot_support_chat_session_v1
- Storage
- Session storage
- Purpose
- Keep a capped recent support conversation available in the widget
- When used
- When the support assistant is used
- Duration
- Browser session or earlier manual/automatic clearing
| Name/category | Storage | Purpose | When used | Duration |
|---|---|---|---|---|
| Authentication session | Necessary first-party cookies managed through Supabase | Sign-in, session continuity and server-side authentication | When account/authentication features are used | Session/security configuration; may be refreshed or removed at sign-out |
| picchuspot_cookie_consent | Local storage | Remember accepted or rejected analytics choice | After a banner choice | Until changed in Cookie settings or browser storage is cleared |
| picchuspot_language / picchuspot-language | One-year first-party cookie / local storage | Remember the language selected by the user | After a language choice | Cookie: one year; local storage: until replaced or cleared |
| picchuspot_region and picchuspot_currency | One-year first-party cookies | Remember selected region and display currency | After a region/currency choice | One year |
| picchuspot-region and picchuspot-currency | Local storage | Keep the selected region and currency consistent in the browser | After a region/currency choice | Until replaced or cleared |
| Order, draft and support-prefill recovery | Session storage | Recover limited form state or continue an order action during the browser session | When the relevant form/action is used | Browser session or earlier removal after completion |
| picchuspot_support_chat_session_v1 | Session storage | Keep a capped recent support conversation available in the widget | When the support assistant is used | Browser session or earlier manual/automatic clearing |
4. Provider technology
Google Analytics
- Category and purpose
- Optional audience and conversion measurement
- Activation
- Tag may initialise with consent denied; PicchuSpot measurement is enabled after acceptance
- Consent/control
- Consent; Reject or Cookie settings
- Duration
- Provider-controlled according to the Analytics configuration and browser controls
Crisp
- Category and purpose
- Requested live-support session and conversation continuity
- Activation
- Only after an explicit request to speak with human support in production
- Consent/control
- User-requested support action; you can use the contact page instead
- Duration
- PicchuSpot configures the Crisp support cookie for 30 days
Cloudflare Turnstile
- Category and purpose
- Necessary security and automated-abuse detection on relevant forms
- Activation
- When a protected authentication or property-enquiry form is shown
- Consent/control
- Necessary for the protected form when configured
- Duration
- Provider-controlled; PicchuSpot does not establish a fixed cookie name or period here
Stripe Checkout
- Category and purpose
- Necessary hosted payment, fraud prevention and transaction continuity
- Activation
- When an eligible customer opens Stripe-hosted Checkout
- Consent/control
- Necessary to complete the requested online payment; leave Checkout to avoid proceeding
- Duration
- Controlled by Stripe on its hosted service
| Provider | Category and purpose | Activation | Consent/control | Duration |
|---|---|---|---|---|
| Google Analytics | Optional audience and conversion measurement | Tag may initialise with consent denied; PicchuSpot measurement is enabled after acceptance | Consent; Reject or Cookie settings | Provider-controlled according to the Analytics configuration and browser controls |
| Crisp | Requested live-support session and conversation continuity | Only after an explicit request to speak with human support in production | User-requested support action; you can use the contact page instead | PicchuSpot configures the Crisp support cookie for 30 days |
| Cloudflare Turnstile | Necessary security and automated-abuse detection on relevant forms | When a protected authentication or property-enquiry form is shown | Necessary for the protected form when configured | Provider-controlled; PicchuSpot does not establish a fixed cookie name or period here |
| Stripe Checkout | Necessary hosted payment, fraud prevention and transaction continuity | When an eligible customer opens Stripe-hosted Checkout | Necessary to complete the requested online payment; leave Checkout to avoid proceeding | Controlled by Stripe on its hosted service |
5. Necessary and functional technology
Authentication and security storage is necessary to sign in, protect forms and keep the requested service secure. Disabling it can prevent account, checkout or protected-form functions from working.
Language, region and currency values are set after a user makes the corresponding selection. They remember a requested preference rather than create an advertising profile. Session storage supports the action currently requested and normally ends with the browser session.
First-party property content counters do not use an application visitor cookie or local-storage identifier. Their database record contains a property/event reference and time, not a visitor ID.
6. How to manage storage
- Use Cookie settings in the footer to accept or reject future Google Analytics use by PicchuSpot.
- Use your browser's privacy controls to inspect or delete cookies, local storage and session storage for
picchuspot.com. - Sign out to end the active account session, then clear site data if you also want to remove remembered local preferences.
Blocking all cookies can stop authentication, security, payment or preference functions. Browser controls do not necessarily delete records that must be retained in provider or PicchuSpot systems for a contract, security or legal reason.
7. Changes and contact
This inventory reflects the current application. Providers may update their technology, and PicchuSpot may revise this Policy when features change. The effective date and version appear at the top.
Questions about cookies or browser storage can be sent to hello@picchuspot.com.
Questions about cookies or browser storage?
Contact PicchuSpot