Cookie Policy

Who runs this website

The website and the GoPOS application are owned by [RAZON_SOCIAL], tax ID [NIF], registered office at [DOMICILIO_SOCIAL]. Contact address: Carrer Doctor Pi i Molist 29, 08031 Barcelona, Spain.

You can contact us at goposbcn@gmail.com or by phone at +34 667 756 999. For privacy and data protection matters specifically, the contact address is goposbcn@gmail.com.

GoPOS is SaaS point-of-sale software for mobile phone shops in Spain. The website (https://gopos.es) is the informational and commercial part. The application is the private area that customers log into with a username and password. Both are served from the same domain and share the same base document, so the third-party technologies loaded on the informational pages are also loaded inside the private area.

What cookies are

A cookie is a small text file that a website stores in your browser when you visit it. On later visits, the site can read that cookie to remember information: that you are logged in, your language, or which pages you have viewed.

Spanish and EU law does not only talk about cookies. Article 22.2 of Law 34/2002 on information society services and electronic commerce (LSSI-CE), which implements Directive 2002/58/EC, applies to any technique for storing and retrieving data on the user's terminal equipment. That includes cookies, but also browser local storage (localStorage), tracking pixels and device fingerprinting.

The general rule is simple: setting non-essential cookies requires the user's prior, informed consent. Cookies strictly necessary to provide a service that the user has expressly requested are exempt from that consent.

Cookies and equivalent technologies used on this website

The full inventory of cookies and equivalent technologies used on this website, listing each one's name, owner, purpose, duration and whether it is first-party or third-party, is set out in the following table: accessToken and refreshToken, both first-party technical cookies that are strictly necessary to keep you signed in. They are set as httpOnly and SameSite=Lax, are sent only over HTTPS in production and expire one hour after being issued. No third-party, analytics or advertising cookies are installed.

We review that inventory whenever we change the technologies used on the site, and this policy is updated accordingly. If you ever notice a discrepancy between what is declared here and what you observe in your browser, we would be grateful if you told us at goposbcn@gmail.com.

We do not use information collected through cookies or equivalent technologies to build commercial profiles about you or to make automated decisions affecting you.

Web fonts served by Google Fonts

We load no third-party analytics or advertising scripts. We do load web fonts served by Google Fonts (Google Ireland Limited). Loading them causes your browser to send that provider your IP address and technical request data, such as your browser and operating system.

Google Fonts sets no cookies on your device in that process, so the consent requirement of Article 22.2 LSSI-CE is not triggered. Even so, we tell you expressly, because that communication does disclose personal data to the provider.

This may involve an international data transfer, subject to the safeguards in Chapter V GDPR. You can review the provider's own processing in its privacy policy.

Consent and the cookie banner

A cookie banner exists to obtain the user's consent before setting non-exempt cookies. If a site performs no storage of or access to information on the user's device that requires consent, there is no consent to collect.

The Spanish Data Protection Agency's (AEPD) Guidance on the use of cookies places the duty to inform and obtain consent at the point where information is actually stored on or retrieved from the user's device beyond what is strictly necessary. Our assessment of whether a banner is called for on this site rests on our own reading of that Guidance, and we review it whenever we change the technologies used on the site.

Whenever we use cookies subject to consent, the corresponding banner will be shown before they are set, on the terms described below.

Technical server logs

Serving a web page necessarily involves a communication between your device and a server. The hosting provider, Amazon Web Services (AWS), may generate technical logs containing data such as the IP address, the date and time of the request, the page requested, the browser type and the operating system.

These logs are not cookies: nothing is stored on your device. They are generated on the server side and their purpose is to keep the service running, detect incidents and prevent abuse or attacks.

The processing of this data is explained in our Privacy Policy and is based on the legitimate interest in network and information security recognised in Regulation (EU) 2016/679 (GDPR).

If we add new cookies in the future

If we decide to add analytics, advertising, a support chat, embedded videos or any other tool that sets non-exempt cookies, we will change things before switching it on, not after.

In that case: we will update this policy with a new revision date; we will list in the cookie table each cookie's name, owner, purpose, duration and whether it is first-party or third-party; we will show a consent banner that lets you accept, reject and configure with equal ease, with no pre-ticked boxes and no cookie walls; and we will set no non-exempt cookie until you have given consent, which you will be able to withdraw at any time as easily as you gave it.

If those tools involved international data transfers, we would say so expressly, together with the applicable safeguard under Chapter V of the GDPR.

Cookies in the GoPOS application (private area)

The GoPOS web application uses two first-party cookies, both technical: "accessToken", which keeps your session authenticated, associates your requests with your user and your shop and applies your role (admin, sales, repairs, wholesale), and "refreshToken", which allows the session to be renewed without re-entering your credentials.

Both are issued with the httpOnly attribute, so they cannot be read by the page's JavaScript, and with the SameSite attribute, which limits their being sent from external sites. In the production environment they are also issued with the Secure attribute, so they travel encrypted over HTTPS only.

Their lifetime is one hour from issue. They expire once that period elapses, or when you log out, at which point they are deleted from your browser.

They are strictly necessary to provide the service the user has expressly requested: without them, keeping an authenticated session is technically impossible. They are therefore exempt from the consent requirement of Article 22.2 LSSI-CE, as the AEPD's Guidance on the use of cookies recognises for user authentication or identification and security cookies.

They are not used for analytics, advertising or profiling, and are not shared with third parties for those purposes. They are issued from our own domain. Any third-party cookies or technologies that may load inside the private area, since it is served from the same document as the website, are those listed in the accessToken and refreshToken, both first-party technical cookies that are strictly necessary to keep you signed in. They are set as httpOnly and SameSite=Lax, are sent only over HTTPS in production and expire one hour after being issued. No third-party, analytics or advertising cookies are installed table.

Third-party components inside the application

For the document scanning feature used in trade-in contracts, the application loads a third-party component on demand (Asprise Scanner.js) from cdn.asprise.com. It is loaded only if you use that feature; if you do not, no request is made to that provider.

We have not exhaustively verified whether that component sets cookies or other storage on your device of its own accord. If it is confirmed that it does and that such storage is not strictly necessary, your prior consent will be obtained under Article 22.2 LSSI-CE before it is loaded.

Payments, once active, are processed through [PASARELA_PAGO], which may redirect you to a domain of its own and use its own cookies in accordance with its policy.

Other storage on your device inside the application

GoPOS is a progressive web app (PWA) and can work offline. To do so it uses browser mechanisms such as the service worker and local storage, where it keeps the application's own files and operational data pending synchronisation.

This storage falls under the same Article 22.2 LSSI-CE as cookies, and it is likewise exempt from consent: it is indispensable to deliver the offline functionality the user requested by using the application.

It is not used to track your behaviour or to build profiles. You can clear it from the site data settings in your browser, although doing so will log you out and discard any data still pending synchronisation.

Cookies and personal data

When a cookie makes it possible to identify or single out a person, the information it holds is personal data, and the GDPR and Organic Law 3/2018 on the Protection of Personal Data and guarantee of digital rights (LOPDGDD) apply to it.

In the case of the application's session cookies, the associated data is your user identifier within GoPOS. That identifier is processed on behalf of the contracting shop, which acts as data controller, under the processing agreement required by Article 28 GDPR. The lawfulness of each user's access is therefore a matter for the shop that created their account. GoPOS additionally processes this data, as controller, in order to secure access, on the basis of the legitimate interest in Article 6(1)(f) GDPR (recital 49).

The data that shops enter into GoPOS about their own customers (name, phone, ID document, address) and about devices (IMEI or serial number) is not collected through cookies. It is processed on behalf of the shop, which acts as controller, under the same data processing agreement. The list of sub-processors is [SUBENCARGADOS]. The details are in the Privacy Policy.

How to view, block or delete cookies in your browser

You can control at any time the cookies you have received from this or any other site. Every browser lets you view stored cookies, delete them, block third-party cookies or block them all, and browse in private or incognito mode.

The settings are usually found at: Google Chrome, under Settings, Privacy and security, Cookies and other site data; Mozilla Firefox, under Settings, Privacy and security, Cookies and site data; Microsoft Edge, under Settings, Cookies and site permissions; Safari, under Preferences or Settings, Privacy; and Opera, under Settings, Privacy and security. Menus change between versions, so check your browser's official help pages if you cannot find them.

Bear in mind one practical effect: if you block all cookies, you will not be able to log in to the GoPOS application, because the session cookies are technically indispensable.

Blocking third-party cookies only should not prevent you from using GoPOS's core features, since the session relies on first-party cookies alone. Note that some browsers apply broader restrictions, and that external services you may reach from the application, such as the payment gateway ([PASARELA_PAGO]), are governed by their own cookies and policies.

Changes to this policy

We may update this Cookie Policy if the technologies we use, the applicable law or the AEPD's criteria change.

Any new version will be published on this same page with its update date. If the change means starting to use cookies that require consent, you will be asked before they are set.

We recommend checking this page from time to time. The version in force is always the one published here.

Contact and complaints

If you have questions about this policy or wish to exercise your rights of access, rectification, erasure, objection, restriction or portability, write to us at goposbcn@gmail.com or goposbcn@gmail.com, or call +34 667 756 999. You can also write to us at Carrer Doctor Pi i Molist 29, 08031 Barcelona, Spain.

If you believe your request has not been handled properly, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es), C/ Jorge Juan 6, 28001 Madrid.

This policy covers only the use of cookies and equivalent technologies. General personal data processing is described in the Privacy Policy, and the conditions for using the service in the Legal Notice and the Terms and Conditions.