TuployTuploy

Cookies Policy

Effective date: April 13, 2026 · Last updated: April 13, 2026

This Cookies Policy explains how ALIADO EXTERNO, SLU (company ID L-719104-A, registered office at Passatge Arnaldeta de Caboet, 11 Ed. La Torre 2-1, AD700 Escaldes-Engordany, Andorra), operator of Tuploy ("Tuploy", "we"), uses cookies and similar technologies when you visit tuploy.com or use the Tuploy dashboard.

It should be read together with the Privacy Policy.

1. What is a cookie?

A cookie is a small text file that a website stores on your device (computer, phone, tablet) when you visit it. Cookies allow a website to recognize your device, remember your preferences and measure how the site is used.

Cookies can be:

  • Session cookies — deleted when you close your browser.
  • Persistent cookies — remain on your device for a defined period or until you delete them.
  • First-party cookies — set by the domain you are visiting (tuploy.com).
  • Third-party cookies — set by a different domain (e.g. an analytics or OAuth provider).

We also use similar technologies such as localStorage, sessionStorage and IndexedDB in the browser, which fall under the same rules as cookies for the purposes of this Policy.

2. Who this Policy applies to

This Policy applies to all visitors of tuploy.com and of any subdomain we operate directly for the Platform (e.g. the dashboard). It does not apply to cookies set by applications that customers deploy through Tuploy on their own subdomains — those applications are controlled by the customer and have their own cookie policies.

3. Why we use cookies

Tuploy uses strictly necessary (essential) cookies only. We do not use analytics, advertising, cross-site tracking, marketing or profiling cookies, and we do not load third-party tags on our site. Because we only use essential cookies, no prior consent is required under ePrivacy / LQPD and no consent banner is displayed.

3.1 Strictly necessary (essential)

Needed for the website and dashboard to function:

  • Session management and authentication (NextAuth session cookies).
  • CSRF protection.
  • Load balancer routing and security.

Legal basis: contract performance (LQPD Art. 6 / GDPR Art. 6(1)(b)) and legitimate interest in securing the service (Art. 6(1)(f)). These cookies cannot be disabled without impairing the service, and under ePrivacy they are exempt from the consent requirement.

3.2 Third-party authentication

If you sign in with Discord or Google, those providers may set their own cookies on their own domains during the OAuth flow. Those cookies are not set by Tuploy and are governed by the respective provider's policy:

4. Retention

Cookies are retained only for as long as necessary for their purpose — from the duration of your session (session cookies) to a few months (persistent cookies). Exact retention periods are listed in section 8.

5. Sharing of cookie data

Data collected through cookies is processed in line with our Privacy Policy. Andorra benefits from an EU adequacy decision (Decision 2010/625/EU); where data is processed outside the EU/EEA or Andorra, transfers are covered by the safeguards described in section 7 of the Privacy Policy.

6. How to control cookies

Because Tuploy only sets strictly necessary cookies, there is no consent banner or "cookie settings" panel. You can still remove or block our essential cookies through your browser, but doing so will prevent the dashboard from working correctly.

Most browsers let you see, delete and block cookies. Refer to your browser's documentation:

Disabling strictly necessary cookies may cause the dashboard to stop working correctly.

7. Changes to this Policy

We may update this Policy from time to time to reflect changes in technology, regulation, or the way we operate the Platform. Material changes will be communicated through a banner or email. The "Last updated" date at the top of this Policy reflects the latest revision.

8. Cookies we use

Cookie nameTypePurposeFirst / third-partyDuration
authjs.session-tokenEssentialAuthenticates your session in the dashboard (Auth.js)First-partySession
authjs.csrf-tokenEssentialCSRF protection for authentication flowsFirst-partySession
authjs.callback-urlEssentialPost-login redirect handlingFirst-partySession
__Host-authjs.csrf-tokenEssentialSecure CSRF cookie variant over HTTPSFirst-partySession
__Secure-authjs.session-tokenEssentialSecure session cookie variant over HTTPSFirst-partySession

9. Contact

For any question about this Cookies Policy write to privacy@tuploy.com.