Status: Draft — not effective
Last updated: 2026-08-09 Operator: Treaxures, operated by ESPR Creative Lab Private Limited, Aizawl, Mizoram, India
1. Scope
This Policy covers cookies and similar browser storage on the Treaxures
website at https://treaxures.com, including the invitation-only Creator
Studio and the internal admin surfaces hosted on the same domain.
The Treaxures mobile app is not a website and does not use HTTP cookies. It stores platform-standard local data on your device — authentication tokens in encrypted secure storage (iOS Keychain / Android Keystore), preferences in shared preferences, and an offline cache for downloaded guides, maps, and media. Optional diagnostics in the app are governed by the in-app consent controls described in the Privacy Policy, not by this Policy.
2. What this site actually stores
Only strictly-necessary storage is in use. Each entry below is written by a specific piece of code in this repository.
Cookies
| Name | Set by | Purpose | Lifetime | Flags |
|---|---|---|---|---|
sb-<project>-auth-token (and numbered chunks) | Supabase Auth, via the session middleware | Keeps you signed in on authenticated pages (Creator Studio, admin). Set only after you sign in. | Session / until sign-out or token expiry | HttpOnly, Secure, SameSite=Lax |
treaxures_pilot_invite | /studio/invite | Carries a Creator Studio pilot invitation token from the emailed link to the acceptance step. | 1 hour, deleted on acceptance | HttpOnly, Secure, SameSite=Lax |
treaxures_partner_invite | /studio/partner-invite | Same, for a partner-workspace invitation. | 1 hour, deleted on acceptance | HttpOnly, Secure, SameSite=Lax |
treaxures_preview_invite | /studio/preview/accept | Same, for a private guide-preview invitation. | 1 hour, deleted on acceptance | HttpOnly, Secure, SameSite=Lax |
Our hosting provider and CDN may additionally set their own strictly-necessary cookies for TLS, routing, and denial-of-service protection. Those are listed in the provider's documentation and are not used by Treaxures for tracking. The final Policy must name the provider once hosting is confirmed.
Other browser storage
| Key | Where | Purpose | Lifetime |
|---|---|---|---|
treaxures:studio:intake:<workspace> | localStorage, Creator Studio only | Recovers an in-progress intake form if the tab closes before you submit. | Until submitted or cleared |
Public pages — the home page, guide and city pages, /about, /download,
/help, /support, /experts, /methodology/walking-emissions,
/sa-biennale, the app-link landing pages under /quest/, /profile/,
/place/, /expert/, /city/, /collectible/, /nft/, /post/,
/marketplace/asset/ and /model-viewer, and these legal pages — set no
cookies and write no browser storage of their own.
3. What this site does not do
- No analytics. The website runs no analytics, product-telemetry, or session-replay script — first-party or third-party. No page-view counter is installed.
- No advertising or cross-site tracking. No advertising cookies, retargeting pixels, fingerprinting, or data brokers.
- No third-party embeds that set cookies on the public pages.
- No cookie consent banner, because nothing optional is set. A banner that asked permission for storage we do not use would be misleading. If any non-essential storage is added, a consent control ships with it and this section is rewritten first.
4. Managing browser storage
- Browser settings: every major browser lets you block, delete, or limit
cookies and site data. Blocking cookies for
treaxures.comwill sign you out of Creator Studio and break invitation links; the public pages continue to work normally. - Do Not Track / Global Privacy Control: the website sets no analytics, so there is nothing for these signals to switch off here. In the mobile app the equivalent control is the Do Not Track setting under Profile → Settings → Privacy, which suppresses analytics and performance collection.
5. Changes
This Policy is updated whenever a cookie or storage key is added, removed, or changed on the website. The "Last updated" date above reflects the most recent revision.
6. Contact
Privacy and data-protection questions: privacy@treaxures.com Data-protection contact: dpo@treaxures.com General support: support@treaxures.com (subject: "Cookie Policy")
Operator: ESPR Creative Lab Private Limited, Aizawl, Mizoram, India.
7. Required before publication
Counsel must confirm the consent position for the jurisdictions the site is served in, the disclosure of hosting/CDN cookies, and the effective date. The operator must add the registered-office address and corporate identity number to the operator block above. The draft notice on this page stays until that is done.