MCPInvoice from your AI
Factuarea

Legal

Cookie policy

What factuarea.com and app.factuarea.com store in your browser, who stores it, why and for how long.

Last updated:

In short

The public website uses one language cookie and one local preference. If you accept, Vercel measures visits and performance without setting analytics cookies. The application stores the session and preferences needed to work. There is no advertising or cross-site tracking.

1What cookies are

A cookie is a very small text file that a website stores in your browser and can read again later. They are used for very different things: remembering a preference, keeping a session signed in, counting how many people visit a page, or following a person from one site to another in order to show them ads.

The law treats cookies and any other way of storing or reading information on the visitor's device, such as the browser's local storage, in the same way. When this page says "cookies", it means all of them.

2What the public website stores

factuarea.com sets one first-party technical cookie.

Name
NEXT_LOCALE
Owner
Factuarea. It is a first-party cookie: no third party is involved.
Type
Technical, user interface personalisation.
Purpose
To store the language (Spanish, English or Catalan) you are browsing in. With the site's current configuration the language is decided by the page address (/, /en, /ca), so this cookie does not by itself change what you see.
Duration
The browser session: it is deleted when you close it.
When it is set
When you switch language with the selector in the header, or when the language shown does not match the one your browser declares. If they match, nothing is set.
What it contains
A two-letter code: es, en or ca. Nothing else. It identifies no one and is not sent anywhere.

It is set by the site's internationalisation library, next-intl, from our own domain. The public website sets no other cookie.

Besides that cookie, the site keeps ONE note in the browser's local storage. It is not a cookie (it is never sent to the server with each request) but it is information stored on your device, so it is declared here all the same:

factuarea.consentimiento-cookies
Remembers whether you accepted or declined optional cookies, so you are not asked again. It contains «aceptadas» or «rechazadas». It stays until you clear your browser data.

It stores a decision you have just made and nothing else: no identifier, no trace of where you have browsed.

3What it does not set

As of the date of this policy, this site uses none of the following:

  • Analytics or audience measurement cookies. Vercel Web Analytics and Speed Insights measure visits and performance without setting this type of cookie and are enabled only after acceptance.
  • Advertising, profiling or cross-site tracking cookies.
  • Social network cookies, nor buttons that set them.
  • Live chat, maps, embedded videos or any other content served by third parties.
  • Local storage for measurement, profiling or identification. The only thing stored is the note in the previous section, which remembers a decision of yours.

Typefaces are served from factuarea.com. If you accept measurement, the site sends Vercel the requests needed for Web Analytics and Speed Insights; it loads no other external measurement resources.

4What the cookie notice does

Article 22.2 of Spanish Law 34/2002 (LSSI) requires consent before storing information on a visitor's device, unless that information is strictly necessary to provide a service the person has requested.

The language cookie and the note in section 2 fall under that exception: they store interface preferences you have just expressed (switching language and answering this very question) and serve no other purpose. The Spanish Data Protection Agency's cookie guidance lists that case among the exempt ones.

The notice at the bottom lets you accept or reject optional measurement by Vercel Web Analytics and Speed Insights. These tools set no analytics cookies and store no identifiers in the browser, but they load only after acceptance. If you reject or make no choice, they remain disabled and the site works just the same.

5Inventory for app.factuarea.com

This policy covers both factuarea.com in its three languages and the private area at app.factuarea.com.

The current production configuration authenticates the application with a token in browser storage. Session cookies described as conditional are set only if that authentication mode or the corresponding feature is enabled.

Application cookies

oauth_state
First-party, technical, secure and httpOnly cookie containing a random anti-CSRF value during Google sign-in. It is created only when that flow begins and expires after 10 minutes or when the flow finishes.
factuarea_session / XSRF-TOKEN
First-party technical authentication and CSRF protection cookies. They are used only if cookie authentication is enabled; the first is httpOnly and lasts no more than 30 days, while the second validates change requests. They are not active in the current token-based configuration.
fa_session_hint
Optional first-party technical cookie with the value ‘1’, allowing the website to know a session exists and show ‘Go to my account’. It contains no identity or credentials, lasts 7 days and is disabled by default.

Application local and session storage

auth-storage
Stores the access token, opaque user and business identifiers, role, authentication state and the ‘keep me signed in’ preference. It does not store name, email or phone number. It stays in localStorage if keep me signed in is selected; otherwise it uses sessionStorage and disappears when the tab closes. It is removed on sign-out.
company-store / feature-store
Store the active business (identifier, name, logo and plan), enabled features and account terminology. They are updated when changing business and removed on sign-out or when browser data is cleared.
ai_chat_conversation_id / action_confirmation_*
Store the AI conversation identifier and action-confirmation status to preserve continuity and avoid repetition. They are removed when the conversation is reset, on sign-out where applicable or when browser data is cleared; full messages are not currently persisted by this flow.
theme, language, assistant-store, onboarding-storage, LIST_COLUMNS_*, LIST_COLUMN_SIZING_*, table:hiddenColumns:*, document-columns, sidebar_config and equivalent keys
Appearance, language, assistant panel, onboarding, column, sizing, notice and view preferences. They are not automatically sent to the server and remain until changed, reset or browser data is cleared.
selectedPlan / integration_oauth_state_* / onboarding-wizard-dismissed
Temporary data for the selected plan, the state and provider of an OAuth connection and postponing the initial assistant. It stays in sessionStorage until the flow completes, the tab closes or browser data is cleared.

Local markers for public-link confirmations, limits or interface notices may also exist. Their keys include public-link-confirmed-*, limit_warnings_shown and login-redesign-notice-dismissed; they store only the described decision or state and remain until reset or deleted.

6What happens if cookies are added later

If another measurement, advertising, chat or external-content tool is added later, the data it processes and whether it stores information in the browser will be reviewed first.

If it uses optional cookies or storage, this page will first be updated with its name, owner, purpose and duration; an accept or reject choice will then be offered, and it will be set only after acceptance.

Rejecting them will not leave any part of the site broken, and accepting and rejecting will cost the same: one tap.

7How to see, block and delete cookies

You do not have to take this page's word for it: you can check what is stored at any time. In most browsers the developer tools open with F12 and cookies are under the storage section.

To delete them or stop them being stored:

  • Chrome: Settings → Privacy and security → Third-party cookies and site data.
  • Firefox: Settings → Privacy & Security → Cookies and Site Data.
  • Safari: Settings → Privacy → Manage Website Data.
  • Edge: Settings → Cookies and site permissions → Cookies and site data.

Blocking or deleting the language cookie does not break the public website. Deleting application storage signs you out or resets preferences; blocking it may prevent the application from working correctly.

8Controller and contact

The party responsible for this website and for the cookies it sets is José Luis Caravaca Carretero, owner of Factuarea, DNI/NIF 20182019L.

Owner
José Luis Caravaca Carretero
Spanish ID / tax ID (DNI/NIF)
20182019L
Address
Cuesta de los Mesones 17, 2C · 14840 Castro del Río

It is the same inbox for privacy, legal matters and support. If what you want to know is which personal data are processed and on what legal basis, that is in the privacy policy.

Related documents

9Changes to this policy

This page is reviewed whenever what the site stores in your browser changes, and it is updated before the change goes live, not after.

The date in the heading is that of the last review. No email notices are sent when it changes: that date is the reference.