TAKSURTAKSUR

Cookie Policy

Last updated: 26 August 2026 · Version 1.0

Scope of this policy

This Cookie Policy describes the cookies and similar technologies that TAKSUR Unipessoal Lda. ("TAKSUR", "we" or "our") actually uses on https://taksur.pt, the SaaS platform, the Marketplace and related digital services.

The latest version is always at https://taksur.pt/cookies (and the localized routes /en/cookies, /fr/cookies, /es/cookies and /it/cookies). It does not replace the Privacy Policy at https://taksur.pt/politicas.

The inventory below comes from an audit of the code and production HTTP headers. It does not describe generic cookies, advertising, pixels or analytics tools that TAKSUR does not run.

1. Who we are

The website and platform are operated by:

TAKSUR Unipessoal Lda.NIF: 519576268Avenida do Atlântico, N.º 16, 2.011990-019 Parque das NaçõesLisboa, PortugalWebsite: https://taksur.ptPrivacy and legal matters: legal@taksur.pt

2. What cookies and similar technologies are

Cookies are small files a website may store on a device. Similar technologies include local storage (localStorage and sessionStorage), session identifiers and the web-app cache service worker.

Cookies set by the website owner (TAKSUR Unipessoal Lda.) are first-party cookies. Cookies set by others are third-party cookies. Third parties only set cookies through this website when a service of theirs is actually loaded. TAKSUR does not load third parties for advertising or audience analytics.

In some cases, cookies or local storage may constitute personal data, or become personal data if combined with other information — for example the authenticated session token.

TAKSUR also uses local storage. Most of the authenticated session is not an HTTP cookie: the official Supabase client stores the session token in localStorage.

3. Why TAKSUR uses them

We use cookies and local storage to:

  • make the website and platform work;
  • remember language and theme;
  • keep the session after login;
  • complete sign-up and capture a referral code;
  • remember sidebar state and list filters in the authenticated area;
  • record your consent choice;
  • improve loading of static assets through the service worker.

4. Categories

  • Strictly necessary — required for the service, language, theme, session, API security and remembering the cookie choice. They cannot be refused in the banner.
  • Preferences / functionality — improve the in-app experience (for example the sidebar). The app still works without them, but saved state is lost.
  • Analytics — TAKSUR does not currently load analytics tools on the website.
  • Marketing / advertising — TAKSUR does not currently load marketing cookies, pixels or scripts on the website.

5. HTTP cookies actually found

On the taksur.pt domain, hosting is Vercel. Production headers for the homepage and /cookies do not send Set-Cookie and do not show Cloudflare (there is no CF-RAY). TAKSUR does not set the __cf_bm cookie on taksur.pt.

sidebar_state

  • Provider: TAKSUR (sidebar component in the authenticated application).
  • Domain: taksur.pt (first-party cookie).
  • Purpose: remember whether the sidebar is open or collapsed.
  • Duration: 7 days; path=/.
  • Category: in-app preference / functionality. Not marketing.

__cf_bm

  • Real provider: Cloudflare (Bot Management), on Supabase infrastructure — not a TAKSUR product and not a taksur.pt cookie.
  • Domain: supabase.co.
  • Purpose: distinguish automated traffic from human requests on HTTP calls to the API.
  • Duration: about 30 minutes.
  • Observed attributes: HttpOnly; Secure; SameSite=None; Path=/.
  • Category: infrastructure security. TAKSUR does not configure it and the banner cannot turn it off.

6. Local storage actually used

Website and taksur.pt origin

  • taksur.language — interface language; necessary; kept until the user changes it or clears storage.
  • taksur.theme — light, dark or system theme; necessary; kept until change or clearance.
  • taksur.onboarding.professional_type — profile chosen at sign-up, so the flow can resume after email confirmation.
  • taksur.onboarding.referral_code — referral code captured before sign-up.
  • taksur.cookie-consent — policy version, date and accepted or refused categories; strictly necessary to remember the choice.

Login and authenticated application

  • Supabase client session key (typically sb-…-auth-token) — session JSON Web Token; necessary to stay signed in.
  • taksur_mfa_email_session, taksur_mfa_sms_session and taksur_mfa_otp_auto_sent (sessionStorage) — two-factor step during login.
  • taksur.contracts.lastSearch, taksur.vehicles.lastSearch, taksur.drivers.lastSearch, taksur.bookings.lastSearch, taksur.marketplace.ads.lastSearch and equivalent finance keys — last list filter in the application.
  • taksur.journey.onboarding.dismissed.v1 — whether the internal onboarding dialog was dismissed.
  • taksur.seo.monitoring.logs — local log only in the Master area; it does not leave the browser and is not a public tracker.

7. Strictly necessary cookies and storage

Required for the service: language, theme, authenticated session, MFA verification, consent memory, the cache service worker, and the __cf_bm infrastructure cookie on supabase.co. Without these, the website, login or API connection may not work correctly.

The banner does not present these technologies as optional, because refusing them would prevent the service from being provided.

8. Preferences and functionality

The sidebar_state cookie and lastSearch keys improve use of the authenticated application. They are not used for advertising. Clearing browser storage restores the defaults.

9. Analytics

TAKSUR does not load Google Analytics, Google Tag Manager, Vercel Analytics, Sentry, Microsoft Clarity, Hotjar or other analytics tools on the public website.

The banner includes an Analytics category in case a tool is added later. Until then, accepting or refusing this category does not load any analytics script. Any future tool will load only after the applicable consent, and this policy will be updated.

10. Marketing and advertising

TAKSUR does not load Meta Pixel, remarketing pixels, behavioural advertising, marketing web beacons or advertising fingerprinting on the website.

The Marketing category in the banner is recorded, but it currently activates no script. TAKSUR does not use web beacons, tracking pixels, clear gifs, Flash cookies or Local Shared Objects, and does not serve targeted advertising or advertising opt-out networks.

11. Service worker and other similar technologies

In production, TAKSUR registers a service worker (taksur-static-v1) on the whole origin to cache static assets. Authentication, API and Supabase requests are not served from that cache. It is not a tracking tool.

We do not use IndexedDB on the website.

12. Third parties actually involved

Vercel hosts taksur.pt. This audit did not observe a first-party Vercel cookie in the homepage headers.

Supabase (doztgyfkjpfpzrbskfxi.supabase.co) provides authentication, data and API. The browser talks to that domain. The __cf_bm cookie may be set on supabase.co by Cloudflare, as described in section 5.

Google Fonts is loaded from fonts.googleapis.com and fonts.gstatic.com for website typography. It is a third-party request needed for visual presentation. This audit did not confirm cookie names on those Google domains, so we do not invent them.

Google Maps JavaScript may load when an integration key exists: on the public tracking page /t/{token} and in authenticated address flows. It supports map functionality, not marketing. Cookies Google may set on those domains were not confirmed in this audit and are not listed by name.

Stripe, Twilio and email sending operate on the server (functions and APIs). There is no Stripe.js, SMS SDK or pixel from those providers on the public website. Pages hosted by those providers (for example a Stripe Checkout page) follow their policies, not this one.

The Termly cookie-policy embed is not configured and the Termly script is not loaded.

13. What this policy does not claim

TAKSUR does not claim to use technologies that the code and production do not run, including targeted advertising, remarketing, GTM, GA, marketing email pixels, Flash, web beacons, or a third-party preference centre. TAKSUR’s cookie preference centre is the banner and panel on this origin, described below.

14. How to accept, refuse or customise

On first visit, TAKSUR shows a cookie preference centre (the banner) with three equivalent actions:

  • Accept all — stores consent for Analytics and Marketing (today with no associated scripts) and hides the banner.
  • Reject optional — refuses Analytics and Marketing; strictly necessary technologies remain active.
  • Customise — lets you switch Analytics and Marketing on or off individually.

The choice is stored in localStorage under taksur.cookie-consent, with the policy version, the date and the categories. We do not store extra identifying data for this purpose.

15. How to change or withdraw consent

You can reopen the cookie preference centre in the website footer, or via the button on the /cookies page. You can accept again, refuse again or change categories.

When you withdraw consent for an optional category, TAKSUR no longer treats it as authorised. Because no optional scripts run today, withdrawal does not unload analytics or marketing tools — those tools are not loaded.

If this policy’s consent version changes, the banner may be shown again.

16. Browser controls

The browser can block or delete cookies and clear local storage. See the help menu in Chrome, Firefox, Safari, Microsoft Edge, Opera or the successor to Internet Explorer. That may end the session, reset language and theme, and show the banner again. Refusing optional cookies in TAKSUR’s preference centre does not currently restrict areas of the website, because there are no analytics or marketing scripts to turn off.

17. Website, platform and mobile apps

This policy covers https://taksur.pt and the web application on the same origin, including login and the authenticated dashboard.

The iOS and Android apps use the same web product in a WebView where applicable. This audit found no native analytics or advertising SDKs. WebView cookies are not the same as native operating-system cookies. If mobile apps later have their own tracking, that will be described in a specific policy — it is not assumed here.

18. Updates and contact

TAKSUR may update this policy when the technical inventory changes. The current version will be at https://taksur.pt/cookies.

This policy should be read together with applicable law. TAKSUR intends to operate in Portugal and may provide services in other countries; this page does not invent specific local duties. For questions, contact legal@taksur.pt.

Requests about cookies and privacy: legal@taksur.pt.