Last updated: April 29, 2026
1. What cookies are
A cookie is a small text file a site stores on your browser when you visit it. They make the site work, remember your preferences, or measure how it's used.
Along with cookies, similar technologies (browser localStorage, sessionStorage, technical-only fingerprinting) serve similar purposes and follow this same policy.
2. Cardreen's stance
Cardreen uses as few cookies as possible. Specifically:
- Zero advertising cookies. No Facebook Pixel, Google Ads, TikTok Pixel, or similar.
- Zero third-party analytics in the MVP. We don't use Google Analytics. If we ever add it, we'll tell you first and ask for explicit consent.
- Only strictly technical cookies to keep your session and store your preferences.
3. Cookies we do use
| Cookie | Type | Purpose | Duration | Source |
|---|---|---|---|---|
| cardreen_access | Essential | JWT access token to keep you logged in | 15 minutes (rotating) | Cardreen (1st party) |
| cardreen_refresh | Essential | Session refresh token (rotates each use) | 30 days | Cardreen (1st party) |
| cardreen_csrf | Essential | Protection against CSRF attacks | Session | Cardreen (1st party) |
| cardreen_locale | Preference | Chosen language (es / en) | 1 year | Cardreen (1st party) |
| cardreen_theme | Preference | Visual theme (light / dark / auto) | 1 year | Cardreen (1st party) |
| cardreen_cookie_consent | Essential | Remember your cookie choice | 1 year | Cardreen (1st party) |
Essential cookies don't require consent — they're needed for the service to work (keep session, prevent CSRF). Blocking them breaks login.
Preference cookies activate only when you change language or theme inside the app.
4. Third-party cookies
These cookies are set by external services when they appear in Cardreen:
| Service | When it appears | Purpose | Provider's policy | |---|---|---|---| | Mercado Pago | Only on the payment screen, during checkout | Secure payment processing | mercadopago.com/privacy | | Stripe (Phase 2) | Only on the payment screen | International payment processing | stripe.com/privacy |
We don't control the cookies these processors install; check their policies. Cardreen never receives your full card data.
5. Cookies on public mini-landings
When someone visits a user's public mini-landing (the page shown after scanning a QR), Cardreen installs only:
cardreen_csrf— so the lead-capture form is CSRF-safe.cardreen_locale— if the visitor switches language.
No tracking cookies, no trackers on mini-landings. A user's mini-landing is deliberately lightweight and privacy-first.
6. How to manage your cookies
6.1 Consent banner
On your first visit to Cardreen we show a banner with three options:
- Accept all: enables all cookies (essential + preference).
- Reject optional: only essential cookies activate.
- Customize: choose category by category.
Your choice is stored for 1 year in the cardreen_cookie_consent cookie. You can change it anytime from the site footer → "Cookie settings".
6.2 Browser-level blocking
You can also block or delete cookies from your browser:
- Chrome: Settings → Privacy and security → Cookies and other data.
- Firefox: Preferences → Privacy and security → Cookies.
- Safari: Preferences → Privacy → Manage website data.
- Edge: Settings → Cookies and site permissions.
⚠️ If you block essential cookies, you won't be able to log in to Cardreen.
7. Changes to this policy
If we change which cookies we use, we'll update this page and notify you via the banner the next time you visit.
8. Contact
- Privacy and cookies: privacidad@cardreen.com
- More detail on how we handle your data: see Privacy Policy.
Cardreen — Menos papel, más oportunidades. / Less paper, more opportunities.