Cookie and Device Storage Policy
This Policy explains how Rezone Group Sp. z o.o. uses cookies and similar technologies on the Crosspad website and local device storage in the Android and iOS applications.
Under Article 399 of the Polish Electronic Communications Law, storing information on or accessing information from a user's terminal equipment generally requires prior information and consent unless it is necessary to transmit a communication or provide a service expressly requested by the user. Optional consent also meets the standards of the GDPR.
1. Cookies and Similar Technologies
Cookies are small data files stored by a browser. Browser local storage, software-development-kit storage, mobile application storage, and similar mechanisms can also store or access information on a device and are subject to the same consent rules where applicable.
We distinguish between:
- Necessary storage β required to deliver a feature you request, maintain security, remember privacy choices, or transmit communications; no optional consent is required
- Personalization storage β remembers optional interface or history choices; enabled only with personalization consent where consent is legally required
- Analytics storage β measures use of the Service; the Google Analytics tag and measurement requests are enabled only with analytics consent
- Marketing storage β not currently used; any future use will require a new, specific consent before activation
2. Website Cookies We May Set
2.1 Necessary Cookies
These cookies support authentication, security, storage of privacy choices, and the entry flow you request. They cannot be disabled through our preference tool where they are strictly necessary, although you can remove them in your browser.
| Cookie | Purpose | Max Duration |
|---|---|---|
| session | Maintains authentication using a protected session token. | 30 days or until logout |
| cookie_consent | Stores consent categories and the policy version so that an outdated choice is not treated as current consent. | 1 year |
| analytics_consent | Records whether analytics consent was granted or refused. | 1 year |
| marketing_consent | Records the current marketing-storage choice; no marketing technology is currently activated. | 1 year |
| landing_visited | Remembers that the landing page was already shown so the Service can provide the requested entry flow. | 1 year |
2.2 Personalization Cookies
Where required by law, these cookies are set only after personalization consent. Refusing them does not prevent basic use of the Service, but the related preference or history may not persist.
| Cookie | Purpose | Max Duration |
|---|---|---|
| preferences | Stores optional interface preferences, such as kit presentation or other display settings. | 1 year |
| recently_played_kits | Stores a limited list of kit identifiers recently played in this browser for quick access. | 1 year |
2.3 Google Analytics Cookies
After analytics consent, Google Analytics 4 may set:
| Cookie | Purpose | Max Duration |
|---|---|---|
| _ga | Stores a pseudonymous browser identifier used to distinguish browser instances. | Up to 2 years |
| ga[CONTAINER_ID] | Maintains and counts session information for the configured Analytics property. | Up to 2 years |
Analytics data is pseudonymous and is not necessarily anonymous. We do not send your Crosspad username, account ID, or email address to Google Analytics. Further details and retention information are in the Privacy Policy Β§4.
2.4 Google Consent Mode Before Analytics Consent
The website uses the basic implementation of Google Consent Mode. When analytics consent is absent or refused:
- The Google Analytics tag is not loaded
- Google Analytics cookies are not read or written
- No Analytics consent-state or measurement request is sent to Google
If you later grant analytics consent, the tag loads and begins measurement from that point. Withdrawing consent disables future Analytics events and removes accessible Google Analytics cookies set for Crosspad. See the Privacy Policy for processing and international-transfer information.
2.5 Cloudflare Security Cookies
Cloudflare may set strictly necessary cookies when its security features are triggered:
| Cookie | Purpose | Max Duration |
|---|---|---|
| __cf_bm | Supports bot detection and protects the Service from abusive traffic. | Approximately 30 minutes of inactivity |
| cf_clearance | Records successful completion of a Cloudflare security challenge so it does not need to be repeated on every request. | Varies according to security configuration |
These cookies are set by Cloudflare only where the corresponding security feature is used. Blocking them may cause a security challenge to repeat or prevent access to protected areas.
3. Technologies We Do Not Currently Use
We do not currently use advertising cookies, social-media tracking pixels, or marketing SDKs. The preference interface may display a marketing category to record that the category is inactive or refused, but no marketing processing will be enabled on the basis of a generic future choice. If marketing technology is introduced, we will describe the provider, purpose, data, and duration and request a new specific consent before use.
4. Managing and Withdrawing Consent
4.1 Crosspad Preference Tool
On your first eligible website visit, the consent interface allows separate choices for:
- Necessary β always active where strictly necessary
- Personalization β optional browser preferences and local history
- Analytics β optional Google Analytics cookies, full measurement, and first-party kit popularity counts
- Marketing β currently inactive; a new specific consent will be required before marketing technology is introduced
You can withdraw or change an optional choice at any time using the cookie settings button at the top of this page. Withdrawal is as easy as granting consent and does not affect processing carried out lawfully before withdrawal.
4.2 Browser Controls
Most browsers allow you to inspect, block, or delete cookies and site storage. Blocking all cookies may prevent authentication, privacy-choice storage, or Cloudflare security checks. Browser controls operate separately from Crosspad's preference tool.
4.3 Google Analytics Controls
You can prevent future consent-based Analytics measurement by disabling Analytics in Crosspad's preference tool. You may also install the Google Analytics Opt-out Browser Add-on from Google. A browser's "Do Not Track" signal is not treated as a substitute for an explicit consent choice because browsers and services do not implement it consistently.
5. Browser Local Storage
The website may use browser local storage or comparable browser storage for:
- Strictly necessary security, session-flow, or temporary application data
- Optional interface preferences after personalization consent where required
- Cached application resources or data needed to provide a feature expressly requested by you
Non-essential preference data is not exempt merely because it is stored in local storage rather than a cookie. You can remove browser storage through browser settings; doing so may reset preferences or downloaded data.
6. Mobile Application Storage and Analytics Choice
The Android and iOS applications do not use browser cookies, advertising SDKs, tracking pixels, Google Analytics, or crash-reporting SDKs. They store information locally as follows:
- Necessary β authentication tokens, security state, offline audio and kit cache, and data needed to provide requested downloads or playback
- Personalization β language, interface, sound, theme, and similar optional choices
- Analytics (Kit Popularity & Play Counts) β determines whether the application sends a first-party aggregate kit-counter request with the
X-Analytics-Consentsignal - Marketing β currently inactive; no marketing SDK or local marketing identifier is used
When mobile Analytics is enabled, the server increments the relevant kit's aggregate counter without adding an account, email, advertising ID, or persistent device identifier to the counter record. Standard network and security data is still processed by Cloudflare for the request, as explained in the Privacy Policy Β§1.4. When Analytics is disabled, the counter request is not sent.
You can change optional mobile choices under Privacy & Cookies. Reset All Data, clearing application storage, or uninstalling the application removes local app data from the device but does not delete your Crosspad account or server-side User Content.
7. Changes to This Policy
We may update this Policy when technologies, providers, or legal requirements change. We will update the date above and give appropriate notice of material changes. If a new use requires consent, we will ask before activating it and will not rely on an earlier consent for an undefined future purpose.
8. Contact
The controller responsible for the technologies described here is Rezone Group Sp. z o.o., with registered address ul. Ε»elazna 51/53, 00-841 Warsaw, Poland. For questions or to exercise a privacy right, use the Contact Form, email xazu.work@gmail.com, or contact k.nowak@rezone-group.com for data-protection matters.