Version 1.0. Effective from the date of publication.
1. What this covers
"Cookies" here means cookies and equivalent browser storage: localStorage and sessionStorage. Portuguese and EU law (Lei 41/2004 implementing the ePrivacy Directive) treats them the same way: anything not strictly necessary to deliver a service you asked for requires your consent before it is stored.
2. What CoFunders stores
2.1 Strictly necessary, no consent required
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
| Privy session cookie | Cookie | Keeps you signed in. Without it you cannot use an account at all. | Session / until sign-out |
cofunders_locale | localStorage | Remembers whether you chose English or Portuguese. | Until cleared |
cofunders_consent | Cookie | Remembers the choice you made below, so you are not asked on every visit, and so the server can honour it too. | 1 year |
These are exempt from consent because the service does not function without them.
2.2 Attribution, consent required and asked for
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
cofunders_signup_ref | localStorage | Remembers who referred you, so that person is paid when you sign up. | Until cleared |
ref_<campaignId> | sessionStorage | Remembers that you arrived at a campaign through someone's referral link. | Until the tab closes |
aff_<campaignId> | sessionStorage | Remembers that you arrived through an affiliate link, so their commission is attributed. | Until the tab closes |
These are not strictly necessary. They exist so that a third person receives money. That is an attribution purpose, and under ePrivacy it needs consent before the value is written, not after, and not implied by continuing to browse.
If you decline, the platform works normally. The only consequence is that a referral or affiliate reward may not be attributed to whoever sent you.
2.3 We do not use
- advertising or retargeting cookies;
- cross-site tracking;
- analytics that profile you;
- social media pixels.
3. Third parties that set their own storage
Some features embed or connect to third parties which set their own cookies under their own policies. We do not control these:
| Provider | When | Their policy governs |
|---|---|---|
| Privy | Sign-in and wallet | privy.io |
| MoonPay | Card purchase, in an embedded frame | moonpay.com |
| Coinbase Pay | Card purchase, in an embedded frame | coinbase.com |
| WalletConnect | Connecting an external wallet | walletconnect.com |
Opening a card purchase means dealing with that provider directly. Their consent prompt is theirs, and appears inside their frame.
4. How to change your mind
- In the platform: Menu → Privacy and data → Cookie preferences. Withdrawing consent removes the attribution values immediately.
- In your browser: clearing site data removes everything in section 2, including the strictly necessary items, which will sign you out.
Withdrawing consent is as easy as giving it, and costs you nothing in functionality.
5. Consent record
When you accept or decline, we record which choice you made and when, so we can show we asked. That record is itself necessary to comply with GDPR Article 7(1).