Cookie Policy

Last updated: March 2026

1. What Are Cookies?

Cookies are small text files stored on your device when you visit a website. They help websites remember information about your visit, such as login status and preferences.

2. Types of Cookies

By duration: session cookies (deleted when you close your browser) and persistent cookies (remain until you delete them or they expire). By purpose: strictly necessary (essential for functionality), performance/analytics, marketing/advertising, and preference cookies.

3. Cookies We Use

We use cookies in two categories: strictly necessary cookies (always active) and analytics cookies (loaded only after you accept them via our cookie banner).

Strictly necessary cookies — no consent required:

CookiePurposeExpires
Supabase Auth session tokenKeeps you logged inSession
Supabase Auth refresh tokenSession refreshConfigured timeout
CSRF protection tokensSecurity (prevents cross-site request forgery)Session end
Cookie consent preference (localStorage)Remembers your cookie choice1 year

These cookies are essential for the Platform to function. Without them, you cannot log in or use secured features. They do not track you across other websites.

Analytics cookies — only loaded if you accept:

CookieProviderPurposeExpires
_gaGoogle Analytics 4Distinguishes unique users2 years
_ga_[ID]Google Analytics 4Session measurement data2 years
GTM container (GTM-553THFWP)Google Tag ManagerTag management; loads other tagsSession

Analytics cookies help us understand how visitors use the Platform so we can improve it. They are only set after you click "Accept" in our cookie banner. You can withdraw your consent at any time by clearing your browser cookies or by using the cookie settings link in the footer.

Marketing / affiliate cookies — loaded only if you accept them:

CookieProviderPurposeExpires
am_user_sessionTravelpayouts (emrldtp.com)Affiliate link attribution — records that a booking referral originated from this siteSession / up to 30 days

The Travelpayouts script also powers some outbound booking links. It is loaded only after you accept marketing cookies in the banner.

4. Cloudflare

Cloudflare (our CDN and security provider) may set cookies for DDoS protection and security. See Cloudflare's cookie policy at cloudflare.com/cookie-policy.

5. Legal Basis

Under the ePrivacy Directive (2002/58/EC) and Article 22.2 of Spanish Law 34/2002 (LSSI-CE), strictly necessary cookies do not require consent because they are essential to provide the service you have requested. Analytics cookies (Google Analytics 4 and Google Tag Manager) are non-essential and are only loaded after your explicit consent, given through our cookie banner. You can withdraw your consent at any time.

6. How to Manage Cookies

You can manage or delete cookies via your browser settings:

  • Chrome: Settings → Privacy and Security → Cookies
  • Firefox: Preferences → Privacy & Security → Cookies
  • Safari: Preferences → Privacy → Cookies
  • Edge: Settings → Privacy → Clear browsing data

Blocking strictly necessary cookies will prevent login and core Platform functionality.

7. Future Changes

We may update this Cookie Policy from time to time to reflect changes in the tools we use or in applicable law. Material changes will be communicated by updating the "Last updated" date at the top of this page. If we introduce additional categories of cookies (for example, advertising cookies), we will update the consent banner accordingly and request your explicit consent before activating them.

8. Contact Us

Manage Your Cookie Preferences

You can withdraw your consent at any time. This will clear your saved preference and show the cookie banner again.