Version 1.0 | Prepared 13 September 2026
BOATARIDE uses only cookies and similar browser technologies needed to authenticate members, protect the Service, preserve an unfinished action and provide the requested pilot functions. The MVP does not use advertising, cross-site tracking or profiling technologies.
Current position. Under the applicable EU and Italian rules, strictly necessary technical technologies do not require prior consent. They must still be explained. If analytics, advertising or optional tracking is added later, this notice and the consent design must be reviewed before activation.
1 Technologies used
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Technology Purpose Normal duration
---------------------------------- -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- ------------------------------------------------------------------------------------------
Authentication session Supabase-generated cookie or browser token, including a project-specific name beginning with sb-, used to keep a member signed in and protect member-only functions. Session or configured login duration; removed on logout where technically possible.
Authentication security state Short-lived nonce, code verifier, anti-forgery or redirect state used during email, Google or Apple login. Minutes or until the login attempt completes.
Pending form state Session storage used so a completed ride or request survives the login step and becomes linked to the authenticated account. Until publication, cancellation, expiry or a maximum of 24 hours.
Preference state Local or session storage for the selected search mode, route/date inputs or essential interface state. Session or up to 30 days where needed for a returning user.
Security and infrastructure data Vercel and the BOATARIDE server process IP address, request time and technical headers to deliver, secure and diagnose the Service. This is server processing rather than an advertising cookie. Normally no longer than 30 days unless a security incident requires longer preservation.
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
The exact project-specific authentication token name must be copied from the deployed browser storage audit into the live HTML notice before launch. Changing a token name without changing its purpose does not change the legal category.
2 No optional tracking in the MVP
- No behavioural advertising or retargeting cookies.
- No social-media tracking pixels.
- No cross-site profiling.
- No non-essential analytics SDK or cookie.
- No cookie wall and no Accept all or Reject all banner while only essential technologies are used.
Aggregated operational counts generated from database events, such as the number of published listings or contact-button clicks, are not used to profile individuals for advertising. Any future analytics tool must be reviewed separately before it is enabled.
3 External services opened by the user
When a member selects WhatsApp or email, the browser opens an external service. That provider may use its own cookies or technologies under its own privacy information. BOATARIDE does not control those external technologies and does not receive the content of the conversation.
4 Browser controls
Users can delete or block browser storage through browser settings. Blocking strictly necessary session or authentication technologies may prevent login, publication, contact access or account management from working. BOATARIDE does not make access to anonymous search conditional on accepting optional tracking because optional tracking is not used in the MVP.
5 Changes
The notice will be updated when the technical implementation or purposes change. BOATARIDE must complete a storage and cookie audit on the final production domain before launch. Optional technologies must remain disabled until the required information and consent mechanism are in place.
6 Sources
- Italian Garante cookie and tracking guidelines
- General Data Protection Regulation
- Supabase authentication documentation
- Vercel Privacy Notice