Legal

Cookie & Tracking Technologies Policy

AVENIQUE COOKIE & TRACKING TECHNOLOGIES POLICY

Effective Date: July 16, 2026


1. SCOPE AND DEFINITIONS

This policy explains the cookies, software development kits (SDKs), local storage, device identifiers, device attestation signals, and similar technologies (collectively, "Tracking Technologies") used by the Avenique mobile application and the avenique.app website. It supplements our Privacy Policy and is incorporated into the Terms of Use. The third parties named in this policy appear in our Subprocessor List with the contractual safeguards that apply to them.

For the purposes of this policy:

  • "Cookies" are small text files placed on your browser or device that allow a website to recognize your browser or store preferences.
  • "SDKs" are code libraries embedded in the mobile app that enable specific functions (for example, push notification delivery) and may transmit limited data to the provider of the SDK.
  • "Local storage" refers to information stored directly on your device or browser (such as session state) rather than transmitted as a cookie.
  • "Device identifiers" are values that identify a device or a specific installation of the app, used as described below.

Position statement: Avenique is completely ad-free. We do not use Tracking Technologies for cross-context behavioral advertising, we do not sell or share (as those terms are defined under the California Consumer Privacy Act, as amended) data derived from Tracking Technologies, and we do not permit third-party advertising networks or data brokers in the app or on the website. We do not use device identifiers, attestation signals, or any other technology described in this policy to build profiles of your activity across other companies' apps or websites (sometimes called "fingerprinting").

2. TECHNOLOGIES IN THE MOBILE APP

We use a minimal set of session, security, and delivery technologies strictly to run, secure, and deliver the Service:

  • Auth Session Tokens (Supabase): Keep you securely signed in to your account. Category: Strictly necessary. Legal basis: Performance of a contract.
  • Push Notification Tokens (Firebase FCM / APNs): Deliver match alerts, real-time messages, and curated introduction notifications. Category: Functional. Legal basis: Performance of a contract, together with the operating-system-level notification permission you control on your device.
  • Device / App-Instance Identifiers: Used solely for fraud prevention, device-ban enforcement, verification integrity, and attribution of app installs. Category: Security. Legal basis: Legitimate interest in protecting the Service and its members.
  • Device Attestation (Apple App Attest / Google Play Integrity): Confirms that a request originates from a genuine, unaltered Avenique app installation before sensitive steps such as identity verification are executed. Category: Security. Legal basis: Legitimate interest.
  • Crash and Diagnostics Logging: First-party crash reports, performance telemetry, and security logs generated when the app encounters an error or a security-relevant event, used solely to debug the Service and investigate abuse. Category: Security and service integrity. Legal basis: Legitimate interest.

We do not embed advertising SDKs, third-party analytics SDKs used for marketing, or social media tracking pixels in the app.

3. TECHNOLOGIES ON THE WEBSITE (WAITLIST)

The public waitlist site at avenique.app uses:

  • Strictly Necessary Cookies and Local Storage: Required for the site to load, submit the waitlist form, balance traffic, and maintain security. Under the EU ePrivacy rules and the UK Privacy and Electronic Communications Regulations (PECR), strictly necessary technologies of this kind are exempt from the consent requirement, which is why the site does not display a cookie consent banner.
  • Cloudflare Turnstile: Used on public forms to distinguish legitimate visitors from automated abuse. Turnstile may process IP address, browser and device signals, challenge telemetry, the website hostname, and a short-lived verification token. Category: Strictly necessary security. Legal basis: Legitimate interest in preventing spam and abuse. It is not used for advertising or cross-context behavioral tracking. Cloudflare appears in our Subprocessor List.
  • No Advertising Cookies: We do not place cookies for marketing, retargeting, or advertising measurement.
  • No Third-Party Analytics Cookies: We do not share website visitor data with third-party tracking or analytics networks.

If we implement performance or analytics tools in the future, we will update this policy first and, where legally required, request your explicit opt-in consent before loading those technologies.

4. BROWSER PRIVACY SIGNALS (GPC AND DO NOT TRACK)

Because we do not sell personal information or share it for cross-context behavioral advertising, there is no sale or sharing for a Global Privacy Control (GPC) signal to opt you out of. We treat any GPC signal we receive as confirmed: visitors who send it receive the same treatment as all other visitors, which is no sale and no sharing.

Some browsers transmit "Do Not Track" (DNT) signals. There is no uniform industry standard for responding to DNT signals, and because our website does not deploy the tracking that DNT is designed to limit, our site's behavior is the same whether or not a DNT signal is present.

5. YOUR CONTROLS

  • Notification Permissions (iOS and Android): You control push notifications through your device's system settings for the Avenique app. Disabling notifications does not affect your account, but you will not receive match or introduction alerts.
  • iOS App Tracking Transparency: Avenique does not track you across other companies' apps or websites, so the app does not request App Tracking Transparency permission and will not appear in the iOS tracking permission list (Settings → Privacy & Security → Tracking). This is expected behavior for an app that does not track.
  • Android Advertising Settings: Avenique does not use the Android advertising ID for advertising. If you delete or reset your advertising ID in Settings → Google → Ads, Avenique's functionality is unaffected.
  • In-App Controls: Navigate to Settings → Privacy within the Avenique application to manage available privacy preferences once your account is active, including geolocation consent and biometric verification consent (governed by our Biometric Information Policy).
  • Website Settings: Because our waitlist site does not load optional analytics or marketing trackers, there is no separate cookie settings panel. You can manage strictly necessary storage through your browser settings; note that blocking strictly necessary storage may prevent the waitlist form from functioning.

6. JURISDICTION-SPECIFIC NOTES

  • EEA / UK: Strictly necessary technologies are used under the ePrivacy Directive and PECR consent exemptions. Any future non-essential technologies will be deployed only with prior opt-in consent. The legal bases stated in Section 2 correspond to Article 6 of the GDPR / UK GDPR as described in our Privacy Policy.
  • California and other US states: We do not sell personal information or share it for cross-context behavioral advertising, and we do not use Tracking Technologies in a manner that requires an opt-out link. Our response to GPC and DNT signals is described in Section 4.
  • Nigeria (NDPA 2023): The Tracking Technologies described in this policy process personal data under the lawful bases identified in Section 2, consistent with our obligations under the Nigeria Data Protection Act 2023 and as further described in Section 7.3 of our Privacy Policy. None of these technologies process sensitive personal data as defined in the NDPA.

7. RETENTION

Session tokens expire automatically in accordance with our authentication security policies. Push notification tokens are retained while your account is active and are invalidated when you sign out of a device or delete your account. Device identifiers retained for ban enforcement follow the banned-user retention rules in our Privacy Policy. Crash logs, performance telemetry, and security logs are retained only as long as necessary to debug platform issues and prevent abuse, after which they are permanently deleted or fully anonymized.

8. CHANGES AND CONTACT

Material changes to this policy will be announced on this page and, for registered app users, through an in-app notice before taking effect. Each version of this policy is numbered and dated so you can identify what has changed.

For any privacy-related questions or to contact our Data Protection Officer, use the contact form at the bottom of this page (choose Privacy inquiry or Data Protection Officer).

Contact us

Choose a topic and send a message. We’ll route it to the right team.