Cookie Policy
Last updated: 18 August 2026
This page lists everything TOTE stores in your browser, what it is used for and how long it lasts. Most of it is cookies, which are small text files kept on your device; section 3 also covers the other browser storage we rely on, which the law treats the same way. For the wider picture of how we handle personal data, see our Privacy Policy.
1. Necessary cookies
These cookies are required for the platform to work — they keep you signed in, protect forms and remember your interface choices. They are always active and cannot be switched off.
| Cookie | Purpose | Duration |
|---|---|---|
.AspNetCore.Identity.Application |
Authenticated session (keeps you signed in) | Session / persistent if "remember me" |
.AspNetCore.Antiforgery.* |
CSRF protection on form submissions | Session |
Tote.Locale |
Remembers the chosen language (PT / EN) | 12 months |
Tote.Theme |
Remembers the chosen theme (light / dark) | 12 months |
Tote.CookieConsent |
Records your cookie preferences | 12 months |
2. Analytics cookies
These cookies are set only if you accept analytics. They help us understand how the platform is used so we can improve it. They are first-party performance cookies — we do not use them for advertising and we do not share the data with advertising networks.
| Cookie | Set by | Purpose | Duration |
|---|---|---|---|
ai_user |
Microsoft Application Insights | Distinguishes returning visitors using a random, anonymous identifier | 1 year |
ai_session |
Microsoft Application Insights | Groups actions within a single browsing session | 30 minutes of inactivity |
Application Insights is a Microsoft Azure service; the telemetry it collects is stored in Microsoft data centres in the European Union under Microsoft's data-processing terms.
3. Third-party cookies
TOTE does not load any advertising, social-media or profiling cookies. Two third parties do store something in your browser on our behalf, and both are functional:
- Stripe (our payment processor) may set functional cookies needed to complete a transaction securely; these are governed by Stripe's Privacy Policy.
- Google Firebase (push notifications): if you are signed in and you allow
browser notifications, we register a service worker that loads Firebase scripts from
gstatic.comand keeps your push token in the browser's IndexedDB storage. We treat this as necessary storage and not as analytics, because it is only created after you ask for notifications and it goes away when you withdraw that permission. It is governed by Google's Privacy Policy.
Our address search runs on our own servers rather than in your browser, so it stores nothing on your device.
4. Managing your preferences
You chose your preferences when you first visited. You can change or withdraw your consent at any time — either with the button below or via the "Cookie settings" link in the footer of any page. Withdrawing analytics consent removes the Application Insights cookies from your browser. Necessary cookies cannot be disabled. You can also delete cookies directly in your browser settings at any time.