Treaxures
Legal

Cookie Policy

Last updated

Draft — pending legal review. This document has not yet been reviewed by Indian-jurisdiction counsel and is not in effect. Content is subject to change before publication.

Status: Draft — not effective

Last updated: 2026-08-09 Operator: Treaxures, operated by ESPR Creative Lab Private Limited, Aizawl, Mizoram, India

1. Scope

This Policy covers cookies and similar browser storage on the Treaxures website at https://treaxures.com, including the invitation-only Creator Studio and the internal admin surfaces hosted on the same domain.

The Treaxures mobile app is not a website and does not use HTTP cookies. It stores platform-standard local data on your device — authentication tokens in encrypted secure storage (iOS Keychain / Android Keystore), preferences in shared preferences, and an offline cache for downloaded guides, maps, and media. Optional diagnostics in the app are governed by the in-app consent controls described in the Privacy Policy, not by this Policy.

2. What this site actually stores

Only strictly-necessary storage is in use. Each entry below is written by a specific piece of code in this repository.

Cookies

NameSet byPurposeLifetimeFlags
sb-<project>-auth-token (and numbered chunks)Supabase Auth, via the session middlewareKeeps you signed in on authenticated pages (Creator Studio, admin). Set only after you sign in.Session / until sign-out or token expiryHttpOnly, Secure, SameSite=Lax
treaxures_pilot_invite/studio/inviteCarries a Creator Studio pilot invitation token from the emailed link to the acceptance step.1 hour, deleted on acceptanceHttpOnly, Secure, SameSite=Lax
treaxures_partner_invite/studio/partner-inviteSame, for a partner-workspace invitation.1 hour, deleted on acceptanceHttpOnly, Secure, SameSite=Lax
treaxures_preview_invite/studio/preview/acceptSame, for a private guide-preview invitation.1 hour, deleted on acceptanceHttpOnly, Secure, SameSite=Lax

Our hosting provider and CDN may additionally set their own strictly-necessary cookies for TLS, routing, and denial-of-service protection. Those are listed in the provider's documentation and are not used by Treaxures for tracking. The final Policy must name the provider once hosting is confirmed.

Other browser storage

KeyWherePurposeLifetime
treaxures:studio:intake:<workspace>localStorage, Creator Studio onlyRecovers an in-progress intake form if the tab closes before you submit.Until submitted or cleared

Public pages — the home page, guide and city pages, /about, /download, /help, /support, /experts, /methodology/walking-emissions, /sa-biennale, the app-link landing pages under /quest/, /profile/, /place/, /expert/, /city/, /collectible/, /nft/, /post/, /marketplace/asset/ and /model-viewer, and these legal pages — set no cookies and write no browser storage of their own.

3. What this site does not do

  • No analytics. The website runs no analytics, product-telemetry, or session-replay script — first-party or third-party. No page-view counter is installed.
  • No advertising or cross-site tracking. No advertising cookies, retargeting pixels, fingerprinting, or data brokers.
  • No third-party embeds that set cookies on the public pages.
  • No cookie consent banner, because nothing optional is set. A banner that asked permission for storage we do not use would be misleading. If any non-essential storage is added, a consent control ships with it and this section is rewritten first.

4. Managing browser storage

  • Browser settings: every major browser lets you block, delete, or limit cookies and site data. Blocking cookies for treaxures.com will sign you out of Creator Studio and break invitation links; the public pages continue to work normally.
  • Do Not Track / Global Privacy Control: the website sets no analytics, so there is nothing for these signals to switch off here. In the mobile app the equivalent control is the Do Not Track setting under Profile → Settings → Privacy, which suppresses analytics and performance collection.

5. Changes

This Policy is updated whenever a cookie or storage key is added, removed, or changed on the website. The "Last updated" date above reflects the most recent revision.

6. Contact

Privacy and data-protection questions: privacy@treaxures.com Data-protection contact: dpo@treaxures.com General support: support@treaxures.com (subject: "Cookie Policy")

Operator: ESPR Creative Lab Private Limited, Aizawl, Mizoram, India.

7. Required before publication

Counsel must confirm the consent position for the jurisdictions the site is served in, the disclosure of hosting/CDN cookies, and the effective date. The operator must add the registered-office address and corporate identity number to the operator block above. The draft notice on this page stays until that is done.