Cookies
Cookie and Storage Policy
This policy explains cookies, local storage and similar storage or access technologies used by Riera Studio. Optional analytics is disabled until the visitor makes a positive choice.
Rejecting analytics does not prevent account creation, login or use of essential workspace functions. The privacy choice can be changed at any time using Cookie settings in the footer.
1. Essential storage
Riera Studio uses essential session cookies to authenticate users, protect account access, maintain the active company context and clear sessions securely on logout or account deletion. These include the signed Riera application session, active-company selection and Supabase authentication cookies where that authentication path is used.
The language preference and the privacy-choice record are stored so the site can provide the selected language and remember whether analytics was accepted or rejected. Recording the privacy choice prevents the banner from repeatedly interrupting the user and provides evidence of the current instruction.
Essential storage is used because the service cannot provide secure login, workspace isolation or the requested preference without it. It is not used for advertising.
2. Optional analytics
PostHog and Vercel Analytics are loaded only after analytics consent. Before consent, their analytics components are not activated by Riera Studio.
When accepted, Riera Studio records page paths and a product identifier to understand which areas are used. Automatic element capture, session replay and capture of form contents are disabled in the Riera Studio PostHog configuration.
Analytics data is not intentionally linked to client records, invoices, document contents or form values. Query strings are excluded from Riera Studio pageview events to reduce the risk of capturing account or callback information.
3. Current storage categories
Authentication and security — purpose: login, session validation, logout, active-company access and fraud prevention; status: essential; duration: session or the security period configured by the authentication service.
Language preference — purpose: remember the chosen interface language; status: functional and essential to the requested preference; duration: until changed or browser storage is cleared.
Privacy choice — purpose: record accept or reject, policy version and decision date; status: essential compliance record; duration: until the policy version changes or the user clears it.
PostHog analytics — purpose: consented product usage measurement; status: optional; storage: local browser storage and provider-side event records; duration: controlled through the analytics configuration and provider retention settings.
Vercel Analytics — purpose: consented aggregate website measurement; status: optional; provider processing applies only after acceptance through the Riera Studio interface.
4. Accepting, rejecting and withdrawing
The first visit presents equally accessible Accept analytics and Reject analytics choices. Essential storage remains active in either case.
A visitor can reopen Cookie settings from the footer and replace the previous choice. When analytics is rejected after previously being accepted, Riera Studio opts out of further PostHog capture and resets the active analytics identity in the browser.
Browser controls can also delete cookies and local storage, but doing so may sign the user out or reset language and privacy preferences.
5. Provider and browser processing
Hosting, security and authentication providers may process request logs or strictly necessary technical identifiers independently of the optional analytics choice where needed to deliver and secure the service.
Browser Do Not Track signals are respected by the Riera Studio PostHog configuration where supported. The consent control remains the primary method for optional analytics.
6. Changes
If a new optional category or provider is introduced, the policy version is changed and a fresh choice is requested before that optional technology is activated.
Legal operator and contact
Riera Studio is operated by Sergi Riera Félix, trading as SRF Systems, a sole trader in the United Kingdom.
Service address: United Kingdom. The full geographic address for formal service is stated on contractual order documents and is available from the contact email.
Email: RieraStudio@srfsystems.uk
