Νομικά

Cookie Policy

The observed production cookies, local storage and network technologies—including the unresolved hosting analytics injection and the advertising features kept disabled.

Τελευταία ενημέρωση: 29 August 2026

Η παρούσα μετάφραση παρέχεται για διευκόλυνση και απαιτεί νομικό έλεγχο σε αυτήν τη γλώσσα.

1. Cookies and similar technologies

Cookies are small files stored by a website in a browser. Similar technologies include local storage, scripts, pixels and software identifiers. Spanish rules can apply to storing or accessing information on a device even when the information is not personal data. This policy covers the cookies, storage keys and analytics requests observed in a clean-browser production audit, together with application behaviour verified in the source code.

2. Responsible publisher

The responsible publisher is THE BUSINESS DOER LLC. Its remaining tax, address, registry and working privacy-contact details are visibly pending. This draft is public so that the gap is visible; it is not presented as a final disclosure.

3. Technology inventory detected

NameProvider / domainPurposeCategoryDuration / typePartyWhen activated
__cf_bmCloudflare
thebusinessdoer.com
Bot detection and protection against malicious trafficNecessary — security30 minutes of inactivity / HttpOnly cookieSet by an infrastructure provider in first-party contextInitial production response, before a consent decision
__dplLovable hosting layer
thebusinessdoer.com
Observed value matches the deployment identifier and appears to keep a visit on a consistent deployment. Exact provider documentation remains pending.Necessary — provisional classification pending confirmation24 hours observed / cookieSet by an infrastructure provider in first-party contextProduction visit, before a consent decision
session-idLovable project analytics
thebusinessdoer.com
Groups page-view analytics events into a browser sessionAnalytics — consent required30 minutes / cookieHosting provider in first-party contextCurrently injected before consent; this is an unresolved launch blocker
/~flock.js → /~api/analyticsLovable project analytics / first-party endpointSends session ID, user agent, locale, inferred country, referrer, path and full URL for a page hitAnalytics — consent requiredPer page view / script and network requestHosting providerCurrently injected before consent; not controlled by the repository CMP
the-business-doer:consentThe Business Doer / current originStores categories, policy version, decision time, expiry and decision methodNecessary — remember the privacy choice12 months / localStorageFirst partyWhen the visitor accepts, rejects or saves a selection
sb-[project-ref]-auth-tokenLovable Cloud / Supabase-compatible authenticationMaintains and refreshes an authorised editorial sessionNecessary — authenticationUntil sign-out, session expiry or browser-data removal / localStorageProvider key stored on the current originOnly after successful administrator authentication

No cf_clearance cookie was observed in this audit, so it is not listed as active; Cloudflare may set it only if a visitor completes a security challenge. Exact durations above are either technically observed or linked to provider documentation and are not inferred from generic cookie databases.

The application also emits typed in-page events through CustomEvent. Its own analytics adapter is not configured and sends nothing to a third party. That is separate from the hosting analytics injected by Lovable and described above.

4. Categories and legal basis

  • Necessary: security, deployment consistency, consent memory and authentication only where needed. These rely on providing the requested service and, for related personal-data processing, legal obligation or legitimate interest in secure operation. They are not used as permission for advertising.
  • Preferences: optional experience choices. No application service in this category is active.
  • Analytics: audience or product measurement. Consent is required. The repository adapter is inactive, but Lovable currently injects project analytics before a decision and must be disabled or properly gated at hosting level.
  • Advertising and marketing: ad delivery, personalisation or campaign measurement. The AdSense account verification meta tag and /ads.txt declaration load no Google code. Advertising and the Google script remain hard-blocked pending a certified CMP.

5. Accept, reject, configure or withdraw

On a first visit, optional categories are off. Accept all, Reject all and Configure are presented together. Scrolling, navigating, inactivity or closing settings does not signal consent. Saving a selection with every optional category off has the same technical effect as rejecting all.

The decision is stored for 12 months and can be replaced at any time. Rejecting optional categories does not block the public publication. Blocking necessary storage at browser level may sign an administrator out or cause the consent panel to reappear.

6. Technical blocking and current limitation

Google Funding Choices and its fallback have been removed. AdSense is blocked by a code-level launch gate and is not mounted globally. The account-verification meta tag and/ads.txt declaration are passive: they do not load Google code, store data or render ads. The reusable content gate blocks future third-party embeds, and the local analytics adapter checks analytics consent before transmitting to any future adapter.

The hosting platform nevertheless injects /~flock.js after the application response. It currently writes session-id and posts a page event before the repository consent panel can decide. No documented project-level disable switch was available during the audit. This draft does not call that behaviour compliant: the site owner must have Lovable disable it or provide an officially supported consent integration, then repeat the clean-browser audit.

7. Renewal and material changes

The local consent record expires after 12 months. A policy-version, purpose, category or provider change invalidates the record and asks for a new decision. A choice recorded while an optional service is absent never authorises an undisclosed provider; adding one requires a new inventory, policy-version change and renewed consent.

8. Providers, transfers and Google advertising

Lovable Cloud/Supabase-compatible services process application, authentication, database and storage requests. Lovable hosting and Cloudflare also deliver and protect the site. Their exact entities, contractual roles, processing regions, subprocessors and transfer safeguards remain to be verified: [LOVABLE CLOUD/SUPABASE AND CLOUDFLARE ENTITIES, ROLES, DPAS, REGIONS, SUBPROCESSORS AND TRANSFER SAFEGUARDS PENDING VERIFICATION]. Google authentication is contacted only when an administrator chooses “Continue with Google”.

AdSense is not active. Before any launch for visitors in the EEA, United Kingdom or Switzerland, the publisher must implement one Google-certified CMP integrated with IAB Europe TCF v2.3, publish the configured vendors and purposes, test Google’s dashboard message and verify the real cookies and requests. This first-party panel is not represented as sufficient for Google advertising, and Consent Mode would not replace valid consent.

9. Browser controls and deletion

Browsers let you inspect, block or delete cookies and site data through privacy settings. Consult the official help for Chrome, Safari, Firefox, Edge or your browser. Deleting this site’s local data removes its consent record, so the panel appears again. The application can remove its own accessible storage but cannot promise immediate deletion of HttpOnly or provider-controlled cookies; those may require expiry, provider action or browser deletion.

10. Questions

Cookie and privacy questions should be sent to [PRIVACY EMAIL ADDRESS PENDING]. A working privacy address remains a mandatory legal-completion blocker.