LEGAL
Cookie Policy
Last updated 3 August 2026
COOKIE POLICY
1. Introduction.
This Cookie Policy explains how ALARA AS, a company incorporated under the laws of Norway, with company registration number 937 674 686 and registered office at Enerhauggata 7, 0651 Oslo, Norway, owner of the VOYARA platform ("VOYARA", "we", "our" or "the platform"), uses cookies and similar technologies on its website, digital platform and member area.
This Policy complements and forms part of the VOYARA Privacy Policy. Any processing of personal data resulting from the use of cookies is carried out in accordance with the General Data Protection Regulation as applicable in the European Economic Area, the applicable Norwegian data protection legislation and the applicable rules on electronic communications.
Contact email: support@voyara.city.
2. What cookies are.
A cookie is a small text file that a website stores on the user's device in order to recognise the browser, remember information or measure how the service is used.
In addition to cookies in the strict sense, VOYARA uses similar technologies available in the browser, in particular local storage and session storage. These technologies do not send data automatically with every request, but they do store information on the user's device, and for that reason they are described in this Policy and treated with the same consent requirements as cookies.
Where this Policy refers to "cookies", the reference should be understood as including these similar technologies.
3. Why we use cookies.
VOYARA uses cookies and similar technologies for the following reasons:
a) To keep members signed in and to protect the security of the account and of the access granted to each edition.
b) To process payments securely and to prevent fraud during checkout.
c) To remember the language chosen by the user and the cookie choices made in the consent banner.
d) To understand, in aggregate and anonymised form, how the website and the member area are used, so that we can improve the selection, the content and the purchase experience.
VOYARA does not use cookies to build advertising profiles, does not sell data collected through cookies and does not operate advertising or retargeting cookies.
4. Categories of cookies used.
VOYARA only uses the categories described below. Categories that are not used by the platform are deliberately omitted from this Policy.
4.1 Strictly necessary.
These cookies and storage entries are required for the platform to function and cannot be disabled through the consent banner, because without them the service cannot be provided. They are used to maintain the member session, to secure forms and payments and to record the user's own cookie choices.
Legal basis: they are necessary for the provision of the service expressly requested by the user and for the performance of the contract.
4.2 Functional.
These entries remember choices made by the user, such as the interface language, so that the platform is displayed as expected on subsequent visits. They are not required for the platform to work, but they improve the experience.
Legal basis: consent, or the legitimate interest in providing a consistent experience where the choice is made actively by the user.
4.3 Analytics and performance.
These cookies and storage entries help us measure visits, sessions, pages viewed, traffic sources, approximate country, device type and conversion events such as the start of a purchase or the redemption of a benefit. They are only activated when the user accepts them in the consent banner.
VOYARA's own analytics measurement is designed to be privacy-friendly: it does not store IP addresses or email addresses, and it uses anonymous identifiers that cannot be used on their own to identify a person.
Legal basis: consent.
5. Cookies and storage currently used by the platform.
5.1 Strictly necessary.
- voyara-cookie-consent (local storage, first party, VOYARA). Stores the cookie choice made in the consent banner ("accepted" or "essential only") so that the banner is not shown again. Retention: until deleted by the user or until the choice is changed.
- Authentication tokens set by our backend and authentication provider, Supabase, in the form sb-<project>-auth-token (local storage, first party). Keep the member signed in and allow secure access to the purchased edition, the benefits and the QR codes. Retention: for the duration of the session; the token is refreshed periodically and is removed on sign-out.
- __stripe_mid and __stripe_sid (cookies set by Stripe, our payment service provider, when the checkout components are loaded). Used for fraud prevention and to secure the payment. Indicative retention: __stripe_sid, approximately 30 minutes; __stripe_mid, approximately one year. Where the purchase is completed on a payment page hosted by Stripe, Stripe may also set its own cookies on that page in accordance with its own policies.
5.2 Functional.
- voyara-lang (first-party cookie and local storage entry, VOYARA). Stores the language selected by the user (English or Spanish). Retention: cookie, up to one year; local storage entry, until deleted by the user.
5.3 Analytics and performance (only after acceptance).
- voyara-analytics-session (session storage, first party, VOYARA). Anonymous per-tab identifier used to group page views into a single visit. Retention: deleted when the browser tab is closed.
- voyara-analytics-visitor (local storage, first party, VOYARA). Anonymous identifier used only to distinguish returning visits in aggregate statistics. It is created only if the user accepts analytics cookies and is deleted if the user later chooses essential cookies only. Retention: until deleted by the user or until consent is withdrawn.
- Google Analytics 4 cookies, where this tool is activated for the platform: _ga (indicative retention, up to two years) and _ga_<container-id> (indicative retention, up to two years). Used to measure visits and sessions in aggregate form, with IP anonymisation enabled and advertising signals disabled.
- Microsoft Clarity cookies, where this tool is activated for the platform: _clck (indicative retention, up to one year) and _clsk (indicative retention, approximately one day). Used to understand how pages are used in aggregate form.
Google Analytics 4 and Microsoft Clarity are loaded only after the user has accepted cookies in the banner and only where the corresponding measurement identifier has been configured by VOYARA. If they are not activated, no such cookies are set.
Cookie names, identifiers and retention periods indicated for third-party services are provided for information purposes and may be updated by the relevant provider.
6. Third-party cookies.
VOYARA relies on the following third-party providers that may set cookies or store information on the user's device:
a) Stripe Payments Europe, Ltd. and its group companies, as payment service provider, for the secure processing of payments and the prevention of fraud.
b) Supabase, as provider of the database and authentication infrastructure used to maintain the member session.
c) Google Ireland Limited (Google Analytics 4) and Microsoft Ireland Operations Limited (Microsoft Clarity), as analytics providers, where these tools are activated and only after acceptance.
These providers process information as described in their own privacy and cookie policies. Some of them may transfer data outside the European Economic Area, in which case the transfer is carried out on the basis of the safeguards described in the VOYARA Privacy Policy.
7. How long cookies remain on the device.
Cookies and storage entries may be:
a) Session-based, deleted when the browser or the tab is closed, as is the case with the analytics session identifier.
b) Persistent, remaining on the device for the retention period indicated in section 5, or until the user deletes them or withdraws consent.
The retention periods indicated are maximum indicative periods. Cookies are not kept for longer than is necessary for the purpose for which they were set.
8. How to manage or disable cookies.
8.1 Through the VOYARA cookie banner.
When first visiting the platform, the user is shown a banner allowing them to accept cookies or to continue with essential cookies only. Analytics and performance tools are not loaded until the user accepts.
The choice can be changed at any time through the "Cookie settings" link in the footer of the website. If the user changes their choice to essential cookies only, the persistent anonymous analytics identifier is deleted and third-party analytics tools are no longer loaded on subsequent visits.
8.2 Through the browser.
The user may also configure their browser to block or delete cookies and to clear local and session storage. These settings are usually found in the privacy or security section of the browser, and equivalent options are available in Google Chrome, Safari, Mozilla Firefox, Microsoft Edge and other common browsers.
Blocking or deleting strictly necessary cookies and storage entries may prevent the user from signing in, from completing a purchase or from accessing the benefits of the edition purchased.
9. Consent and withdrawal of consent.
Consent to non-essential cookies is voluntary, specific and may be withdrawn at any time, without this affecting access to content that does not depend on such cookies. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
10. Updates to this Cookie Policy.
VOYARA may update this Cookie Policy in order to reflect changes to the platform, to the providers used or to applicable legislation. The current version is always published on this page, together with the date of the last update. Where the changes are material, the consent banner may be shown again so that the user can review their choices.
11. Contact.
Any question relating to this Cookie Policy, or any request in relation to personal data processed through cookies, may be sent to support@voyara.city.
Further information on the processing of personal data, the rights of the data subject and international transfers is available in the VOYARA Privacy Policy.
