DRAFT — pending attorney review. An attorney has not reviewed this document yet, and it may change before its final version.
Cookie Policy
Version 0.2.1. In effect since October 3, 2026.
| Version | 0.2.1 |
| Effective date | October 3, 2026 |
| Controller | Osvaldo Rodriguez (an individual) |
| Contact | tripsettled.app@gmail.com |
The short version
- Today we use only four cookies, and all four are needed for the app to work: your session, two temporary protections (one for signing in with Google and one for signing up with a password), and a record of your cookie choice.
- We don't use advertising or analytics cookies, and there are no third-party cookies in Tripsettled.
- If we ever add analytics, they will only run if you accept them, and saying no will be as easy as saying yes.
1. What cookies are
Cookies are small files that a website stores in your browser to remember something from one page to the next, for example that you've signed in. There are similar technologies, such as the browser's local storage; in this policy we call all of them “cookies”.
2. The cookies we use
All of them are strictly necessary: without them you couldn't sign in or stay signed in. That's why they don't ask for your consent, but we explain them here.
| Cookie | Where it's stored | What it's for | How long it lasts |
|---|---|---|---|
__Host-ts_session | The app's server (api.tripsettled.com; in the test version, api.dev.tripsettled.com) | Keeps you signed in. It contains a random value that doesn't reveal who you are. The browser doesn't let other sites or scripts read it (HttpOnly and Secure cookie, with SameSite=Lax). | 90 days at most. The session ends sooner if you sign out or after 30 days without activity; from then on the cookie no longer works. |
__Host-ts_oauth | The app's server | Protects sign-in with Google: it ties the request sent to Google to your browser, so nobody else can complete it in your place. | 10 minutes; deleted when sign-in finishes |
__Host-ts_signup | The app's server | Protects signing up with a password: it ties the email verification link to the browser you signed up in, so nobody else can use it to take over the account. Only set if you sign up with a password. | 15 minutes, the same as the link |
ts_consent | The website (tripsettled.com; in the test version, dev.tripsettled.com) | Remembers your cookie choice, which version of this policy you saw, and the date, so we don't ask you every time. It contains no data about you. | 12 months, or until this policy changes in an important way |
We don't use any other storage technology in your browser. The app's language is set by the page address (/es or /en), without cookies.
3. Third-party cookies
There are no third-party cookies in Tripsettled. If you choose to sign in with Google, during that step you'll be on Google's pages, and Google uses its own cookies under its privacy policy. We don't control or receive those cookies.
4. Analytics in the future
Today we don't measure how the app is used. If we do in the future:
- we will ask for your consent first, in a notice where saying no is as easy as saying yes;
- nothing related to analytics will load until you accept;
- if your browser sends the Global Privacy Control signal, we will treat it as a refusal;
- you will be able to change your choice at any time from My account or from the footer of the public pages;
- we will update this policy with each new cookie, its purpose and its duration.
5. How to control cookies
You can see and delete cookies in your browser settings. If you delete or block the cookies in this policy, the app won't be able to keep you signed in or remember your cookie choice.
6. Changes to this policy
If we add cookies that aren't strictly necessary or change something important, we will update this policy with a new version and date, and ask you again in the cookie notice.
7. Contact
If you have questions, write to us at tripsettled.app@gmail.com. More about your data in the Privacy Policy.
Change history
| Version | Date | Change |
|---|---|---|
| 0.2.1 | 2026-10-03 | Before taking effect: the controller (Osvaldo Rodriguez, an individual) and the contact email. |
| 0.2.0 | 2026-10-03 | New strictly necessary cookie __Host-ts_signup, which protects password sign-up. More detail on ts_consent. |
| 0.1.1 | 2026-10-03 | Clarification: how long the session cookie lasts and when the session ends. |
| 0.1.0 | 2026-10-03 | First draft. |