PUNTIFY
Cookie Policy
Notice on the use of cookies and tracking technologies
pursuant to Article 122 of Legislative Decree 196/2003 and Regulation (EU) 2016/679 (GDPR)
This Cookie Policy describes the tracking technologies used on the puntify.it website and in the Puntify app (PWA). For the processing of personal data in a broader sense, please refer to the Privacy Policy.
Index
1. What Cookies Are
Cookies are small text files that websites save on the user's device (computer, smartphone, tablet) during browsing. They allow the website to remember the user's actions and preferences over time, so that they do not have to be re-entered at each visit.
In addition to traditional cookies, there are similar technologies that perform comparable functions:
- localStorage / sessionStorage — browser memory areas used to store data on the client side without automatic expiry (localStorage) or for the duration of the session only (sessionStorage);
- Service Worker cache — a cache area managed by the browser for PWAs (Progressive Web Apps) that enables offline operation;
- IndexedDB — a local browser database used by some third-party libraries.
The technologies referred to above are subject to the same rules as cookies pursuant to Article 122 of Legislative Decree 196/2003 (Privacy Code), as clarified by the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) in Measure No. 231/2021.
2. Types of Cookies Used
Technical / Necessary
Essential for the operation of the service. They do not require consent (Article 122(1) of Legislative Decree 196/2003).
Analytics
Collect aggregate information on the use of the website. They require consent if linked to individual profiling.
Functional
Store user preferences to improve the user experience (e.g. language, theme).
Puntify does not use third-party profiling or marketing cookies for the creation of advertising profiles of users. No retargeting is carried out through cookies.
3. Cookies on the puntify.it Website
The puntify.it website (showcase site) uses the following tracking technologies:
| Cookie name / key | Provider | Category | Purpose | Duration |
|---|---|---|---|---|
_ga |
Google LLC | Analytics | Distinguishes unique users in Google Analytics 4 (GA4 — ID: G-KFC8WKG9LT) |
2 years |
_ga_KFC8WKG9LT |
Google LLC | Analytics | Maintains the Google Analytics 4 session state | 2 years |
_gid |
Google LLC | Analytics | Distinguishes users for Google Analytics (daily session) | 24 hours |
| Blazor WASM cache (browser Cache API) |
Puntify | Technical | Storage of the web application's static resources (.js, .css, .wasm) for fast loading and partial offline operation | Until SW uninstallation |
| Blazor session cookie | Puntify | Technical | Management of the application state on the client side during browsing | Session |
3.1 Google Analytics 4 (GA4)
The website uses Google Analytics 4, a web analytics service provided by Google LLC. GA4 collects aggregate data on user behaviour (pages visited, session duration, traffic source, device type) through cookies and beacons.
- Property ID:
G-KFC8WKG9LT; - Anonymised IP: Google Analytics 4 does not record the full IP address of EU users by default;
- Data is processed by Google LLC (USA) — transfer covered by SCC and the EU-US Data Privacy Framework;
- Google Analytics privacy: policies.google.com/privacy;
- Google Analytics opt-out: tools.google.com/dlpage/gaoptout.
3.2 Google Fonts
The website makes connections to the Google Fonts servers (fonts.googleapis.com, fonts.gstatic.com) to load typographic fonts. Google may collect the visitor's IP address as an access log. No profiling cookies are installed.
3.3 Leaflet.js (unpkg CDN)
The website loads the Leaflet.js mapping library from the unpkg.com CDN to display the map of participating stores. The CDN may record the visitor's IP address as an access log; it does not install profiling cookies.
4. Storage in the Puntify App (PWA)
The Puntify app (app.puntify.it), available as a Progressive Web App (PWA), does not install traditional cookies but uses the following browser storage technologies:
| Key / Storage | Provider | Category | Purpose | Duration |
|---|---|---|---|---|
sb-*-auth-token(localStorage) |
Supabase Inc. | Technical | Stores the JWT session token (access token + refresh token) to keep the user authenticated without requiring a new login at each access | Until logout / token expiry (1 hour access, 7 days refresh) |
punto_active_role(localStorage) |
Puntify | Functional | Stores the active role selected by the user (Customer = 1, Merchant = 2) to display the correct dashboard at the next access | Until logout or role change |
| FCM Token (localStorage / IndexedDB — managed by Firebase SDK) |
Google LLC (Firebase) | Functional | Stores the FCM (Firebase Cloud Messaging) token required to receive push notifications. The token is registered on Puntify's servers only with the user's explicit consent to receive notifications | Until notification consent is revoked or the app is reinstalled |
puntify-app-cache-v3(Cache API — Service Worker) |
Puntify | Technical | Caching of the app's static resources (HTML, CSS, JS, images) for offline operation and fast loading. Managed by the Service Worker registered at the first launch of the app | Until Service Worker uninstallation or app version update |
puntify-app-data-cache-v3(Cache API — Service Worker) |
Puntify | Technical | Caching of API responses for displaying data in the absence of a connection (points wallet, list of stores) | Until Service Worker uninstallation or app version update |
| In-app memory cache (volatile JS memory) |
Puntify | Technical | In-memory cache (CacheService) to reduce repeated API calls during the active session. Configurable expiry (default 5 minutes). Cleared when the app is closed | Active session (max 5 min per entry) |
4.1 Firebase Cloud Messaging (FCM)
The app integrates Firebase Cloud Messaging by Google LLC for sending push notifications (e.g. points accrual confirmation, Merchant promotions). The FCM token is a technical identifier of the device/browser and:
- is generated only if the user explicitly grants permission for notifications from the browser;
- is transmitted to Puntify's servers and to Google's servers for notification routing;
- may be revoked at any time from the app's notification settings or from the browser settings;
- the Firebase SDK may use its own cookies and localStorage — App ID:
1:796763099677:web:297aba5c9002f64f7a2cf4; - Firebase / Google privacy: firebase.google.com/support/privacy.
4.2 Supabase (Authentication Sessions)
The app uses Supabase Inc. as its authentication and database backend. The session tokens (JWT) are stored in localStorage and not in cookies, but are subject to the same rules for privacy purposes. These tokens:
- are strictly necessary for the operation of the authentication service;
- are automatically deleted on logout or on expiry;
- the refresh token allows automatic renewal of the session without requesting new credentials (validity 7 days);
- data is processed on Supabase servers (USA) — transfer covered by SCC under Article 46 GDPR;
- Supabase privacy: supabase.com/privacy.
4.3 Google Analytics in the App (Firebase Analytics)
The app includes the measurementId: "G-G1EZR6JL2C" in the Firebase configuration, which enables Google Analytics for measuring app usage. This functionality collects aggregate usage data (screens visited, events) and may use cookies or local storage. Data is processed by Google LLC (USA) — transfer covered by SCC and the EU-US Data Privacy Framework.
5. Third Parties and Extra-EU Transfers
Some of the technologies referred to in this policy involve the sending of data to third-party servers located outside the European Economic Area (EEA). Below is an overview:
| Provider | Country | Service | Transfer safeguards (Article 46 GDPR) |
|---|---|---|---|
| Google LLC | USA | Google Analytics 4, Firebase FCM, Google Fonts | SCC (Decision 2021/914/EU) + EU-US Data Privacy Framework |
| Supabase Inc. | USA | Authentication, database | Standard Contractual Clauses (SCC) under Article 46 GDPR |
| Cloudflare / unpkg | USA | CDN Leaflet.js, html5-qrcode | SCC + EU-US Data Privacy Framework |
The documentation relating to the safeguards for extra-EU transfers is available on request by writing to info@puntify.it.
6. Retention Period
Cookies and storage technologies are distinguished according to their duration:
- Session cookies: automatically deleted when the browser is closed;
- Persistent cookies: retained until the set expiry (e.g.
_ga2 years,_gid24 hours) or until manual deletion; - localStorage: retained without automatic expiry until manual deletion or logout;
- Service Worker cache: retained until uninstallation of the Service Worker, update of the app or manual deletion from the browser cache.
7. How to Manage Cookies
7.1 Consent banner (puntify.it website)
On first access to the puntify.it website, a banner is shown allowing you to accept or refuse the analytics cookies (Google Analytics). Technical cookies are installed automatically as they are strictly necessary for the operation of the service. Your preferences are remembered for subsequent visits.
7.2 Browser settings
You can manage, disable or delete cookies directly from your browser settings. Below are the links to the guides of the main browsers:
7.3 Google Analytics opt-out
To disable Google Analytics tracking on all websites that use it, you can install Google's official browser add-on:
Google Analytics Opt-out Add-on7.4 Clearing localStorage and the App Cache
To clear the localStorage data and the Service Worker cache of the Puntify app:
- From a desktop browser: Settings → Privacy and security → Clear browsing data → select "Cookies and other site data" and "Cached images and files";
- From mobile (Chrome): Settings → Privacy → Clear browsing data;
- From mobile (Safari): iPhone Settings → Safari → Clear History and Website Data;
- From the Puntify app: logging out automatically clears the session tokens from localStorage.
Clearing localStorage results in automatic logout from the Puntify app. It will be necessary to log in again with your email and password.
8. Changes to the Cookie Policy
Puntify reserves the right to update this Cookie Policy to comply with regulatory changes, updates to the service or changes in the technologies adopted. Changes will be published on this page with an update of the version date. In the event of substantial changes requiring new consent, the cookie consent banner will be shown again.
9. Contacts
For any questions relating to the use of cookies and tracking technologies, or to exercise the rights provided for by the GDPR (see Privacy Policy — Article 9), you may contact Puntify:
Puntify S.R.L. | puntify.it | info@puntify.it | VAT 12345678912
Cookie Policy v1.0 — March 2025 — All rights reserved
Questions about Cookies?
We are transparent about how we use tracking technologies. Contact us for any clarification.
