Cookie policy
This site uses no third-party cookies, no analytics and no advertising. Only technical cookies are set: your session cookie and, if you open a gallery protected by a PIN, one that remembers you entered it correctly. All of them are strictly necessary for you to sign in and see your photos.
Version v1.0-2026-09-01 · Last updated: 1 September 2026
1. What a cookie is
A cookie is a small file that a website stores in your browser to remember something from one page to the next. Article 22.2 of the Spanish LSSI-CE requires prior, informed consent before setting them, except for those strictly necessary to provide a service the user has expressly requested.
Besides cookies, this application may use the browser's local storage, its session storage and a service worker, which is what lets you install it on your phone and makes it open quickly. The same rules apply to them and they are described here in the same detail.
2. What is used here
All of it is first-party, technical and strictly necessary. None of it measures, profiles or advertises.
- Authentication session cookies, set by Supabase Auth with names of the form sb-…-auth-token. If the value is long it is split into several pieces (sb-…-auth-token.0, sb-…-auth-token.1), and while you are signing in one or more short-lived helper cookies are set, with names ending in -code-verifier. They keep you signed in while you use the application. They are first-party and flagged SameSite equal to Lax, and they renew themselves for as long as you keep using the application: if you never sign out, they can last up to four hundred days. They are deleted when you press «Sign out». Without them you cannot sign in or open a private gallery.
- Gallery PIN access cookie, with a name of the form acceso_galeria_ followed by that gallery's identifier. It is only set if you open a secret link protected by a PIN and enter it correctly, and it saves you from typing the PIN again while you browse that gallery. One is set for each gallery you open this way. It is first-party, flagged HttpOnly, Secure and SameSite equal to Lax, and it expires after twelve hours. It stores neither the PIN nor any personal data: its value is only a signature computed on the server. The only identifier it carries is the gallery's, in its own name.
- Language preference, taken from the address you visit (/es or /en). No cookie is stored for this.
- Local storage used by the installable application's service worker: so the app opens offline and uses less data at the arena, it keeps on your own device the app's own files (structure, styles, icons and fonts), the last sixty pages you have opened outside your account and your galleries, which may carry your name in the header and your booking reference, and up to three hundred images of the photos you have looked at or saved, in the same watermarked version you see on screen. That includes personal data about you, so it is worth knowing where it ends up: none of it is sent anywhere and it stays on your device only. Pages from your account, your galleries and the sign-in screen are never stored; the ones that are stored are deleted when you sign out, and everything else disappears when you clear this site's data in your browser or uninstall the app. The original delivery files are not kept for offline viewing: every download uses a fresh signed link, which expires after fifteen minutes.
- Two dismissal flags for the installable application's prompts, so they are not repeated on every visit. The first, binomio.pwa.instalacion.descartada, is kept in local storage and holds the date and time the install prompt was last closed: it is not shown again until a week has passed. The second, binomio.pwa.navegador-integrado.descartado, is kept in session storage, belongs to the notice shown when you open the page inside the in-app browser of an application such as Instagram, and lasts only as long as the tab. Neither holds an identifier nor any personal data.
3. What is not here
There are no third-party cookies of any kind. Specifically, none of the following is used:
- Web analytics: no Google Analytics, no alternative to it, not even the ones marketed as privacy-friendly.
- Social network tracking pixels, including Meta's, even though much of the traffic arrives from Instagram.
- Advertising, remarketing or heatmaps.
- Embedded social buttons that load resources from other domains.
- Fonts or libraries served from third-party content delivery networks: everything is served from this domain.
5. How to delete or block them
You can delete or block cookies from your browser at any time:
- Safari on iPhone or iPad: Settings, Safari, Clear History and Website Data.
- Safari on Mac: Safari, Settings, Privacy, Manage Website Data.
- Chrome: Settings, Privacy and security, Cookies and other site data.
- Firefox: Settings, Privacy & Security, Cookies and Site Data.
- Installed app: deleting it from your phone removes its data and local storage.
6. Changes to this policy
If the cookies used change, this policy is updated before the change takes effect, with a new version number and date.