Skip to content
Publisher
WiseWave Limited
Category
Core Legal
Effective date
Effective 2026-07-01
Last updated
Updated 2026-07-17

Cookie Policy

1. Introduction

Purpose. This Cookie Policy explains how WiseWave Limited, the operator of the Tirvea platform (the "Service"), uses cookies and similar technologies, what they do, and the choices available to you.

Our approach. We use a small number of cookies, and we keep non-essential cookies to a minimum. Today, the cookies we set are limited to those strictly necessary to provide, secure, and operate the Service and to process payments. We do not currently use analytics, advertising, or marketing cookies. If that changes, we will update this Policy and, where required, obtain your consent before setting such cookies (§23).

How to read this Policy. Cookie-specific terms are defined in §2. Data-protection terms are defined in the Privacy Policy (/legal/privacy). Where we describe a third party's cookies, we describe them to the best of our knowledge; the definitive detail of a third party's cookies is controlled by that third party.

2. Definitions

In this Policy:

  • "Cookie" - a small text file placed on your device by a website or application to store or retrieve information.
  • "Similar technologies" - technologies that perform functions comparable to cookies, including browser local storage (for example, HTML5 localStorage), pixels, and software development kits (SDKs). Where relevant, references to "cookies" include similar technologies.
  • "First-party cookie" - a cookie set by the Service under a domain we control.
  • "Third-party cookie" - a cookie set by a third party, such as a payment provider, when its technology is loaded within the Service.
  • "Session cookie" - a cookie that expires when you close your browser or after a short session.
  • "Persistent cookie" - a cookie that remains on your device until it expires or you delete it.
  • "Strictly necessary cookie" - a cookie without which the Service, or a feature you have requested, cannot function, and which is exempt from consent under ePrivacy rules.
  • "Non-essential cookie" - any cookie that is not strictly necessary (for example, analytics or marketing cookies), which requires your prior consent.

3. What Are Cookies

Purpose. This section explains the technology. Cookies are small text files stored on your device when you use a website or app. They let a service remember information - such as that you are signed in - between requests and visits. Similar technologies, such as browser local storage, achieve comparable results by storing information in your browser. Cookies may be first-party (set by us) or third-party (set by a provider whose technology runs within the Service), and may be session or persistent (§2).

4. Types of Cookies

Purpose. This section sets out the categories we recognise. We classify cookies and similar technologies into four consent categories:

  1. Strictly Necessary - required to run the Service and provide requested features (authentication, security, payment integrity). Exempt from consent.
  2. Functional - remember your choices to improve your experience (for example, preferences). Not currently set as cookies - see §10.
  3. Analytics / Performance - help us understand and improve how the Service performs. Not currently used - see §12-§13.
  4. Marketing - used to deliver or measure advertising. Not currently used - see §14.

The consent treatment of each category is described in §23 and summarised in the classification table in Output 4.

5. Why We Use Cookies

Purpose. We use cookies and similar technologies to: (a) keep you signed in and maintain your session (authentication); (b) protect the Service and your Account against fraud and abuse (security); and (c) support secure payment processing for Premium subscriptions (payment integrity). We do not use cookies to track you across other websites, and we do not currently use cookies for analytics or advertising. The Personal Data associated with these purposes is processed as described in the Privacy Policy (/legal/privacy).

6. Strictly Necessary Cookies

Purpose. These cookies are essential to provide the Service and features you request; without them the Service will not work correctly. Under ePrivacy rules they are exempt from consent, but we still explain them here for transparency.

Data categories & recipients. In this category we set:

  • Supabase authentication cookies (first-party; names beginning sb-) - keep you securely signed in. See §7 and §18.
  • tirvea_did (first-party; device/security) - a random device identifier used for security and fraud prevention. See §8.
  • Stripe payment-integrity cookies (third-party; set only during the payment/upgrade flow) - help prevent payment fraud. See §16.

Legal basis. These cookies are strictly necessary; they are exempt from consent under the ePrivacy Directive. The associated Personal Data is processed under the bases in the Privacy Policy (contract and legitimate interests) (/legal/privacy).

Retention. See §22.

Your rights. Because these cookies are essential, they cannot be switched off through a consent tool; you may still block cookies at the browser level (§25), but the Service may then not function.

7. Authentication Cookies

Purpose. To keep you securely signed in and maintain your authenticated session across pages and requests, so you do not have to re-enter your credentials on every action.

  • Cookies used. Supabase authentication cookies (first-party, names beginning sb-), set via the @supabase/ssr integration. They are HttpOnly and carry your session tokens. [Implementation verification required before publication - confirm exact cookie names, which depend on the Supabase project reference, and the token-chunking behaviour.]
  • Category. Strictly Necessary.
  • Recipient. Our authentication and database Processor, Supabase (§18), acting on our behalf.
  • Retention. For the duration of your session, with refresh handling as configured; see §22.
  • Your rights. Signing out and clearing cookies removes these; the Service cannot keep you signed in without them.

8. Security Cookies

Purpose. To protect the Service and your Account against fraud, abuse, and unauthorised access.

  • Cookies used. tirvea_did - a first-party, HttpOnly, SameSite=Lax cookie containing a random identifier (UUID) that we issue. It supports a privacy-safe notion of device identity: we deliberately do not use device fingerprinting (no canvas, fonts, audio, or screen-metric probing, and no third-party fingerprinting libraries). Only a salted hash of the identifier is stored server-side; the raw identifier is not persisted. Clearing the cookie simply makes the device appear new, which at most prompts an extra verification step.
  • Category. Strictly Necessary (security/fraud prevention).
  • Legal basis. Exempt from consent as strictly necessary; associated processing relies on legitimate interests in security and fraud prevention (see Privacy Policy §26 and §30, /legal/privacy).
  • Recipient. Our security function; no third party receives the raw identifier.
  • Retention. Up to 12 months (persistent); see §22.
  • Your rights. You may clear this cookie at the browser level (§25); doing so does not lock you out.

9. Session Cookies

Purpose. To maintain short-lived state for the duration of a browsing session - for example, keeping your authenticated session active and supporting secure payment interactions while you complete them.

  • Cookies used. Session-scoped elements of the Supabase authentication cookies (§7) and Stripe's short-lived session cookie during checkout (__stripe_sid, §16).
  • Category. Strictly Necessary.
  • Retention. These expire when the session ends or after a short period (see §22).
  • Your rights. As for strictly necessary cookies (§6).

10. Preference Cookies

Purpose. To remember choices that personalise your experience, such as your appearance (theme) setting.

  • What we actually do. We do not currently store your preferences in a cookie. Your appearance (theme) preference is stored in your browser's local storage under the key tirvea:appearance, and, when you are signed in, your appearance setting is also saved to your Account so it follows you across devices. Local storage is a "similar technology"; it is first-party, is used only to remember your own preference, and is not used to track you.
  • Category. Functional.
  • Legal basis. As a first-party preference you set, stored to deliver a feature you use; where consent is required for storing information on your device for non-essential purposes, we treat this as functional and manage it consistently with §23. [Legal review required before publication - confirm the ePrivacy treatment of first-party functional local storage under Irish DPC guidance.]
  • Retention. Persists until you change the setting or clear your browser storage.
  • Your rights. Change the setting in the Service, or clear your browser's local storage (§25).

11. Language Cookies

Purpose. To remember a language preference where multiple languages are offered.

  • What we actually do. The Service is currently provided in English only. We do not set a language cookie. If we introduce additional languages, we may store a language preference (as a functional cookie or similar technology) and will update this Policy accordingly.
  • Category. Functional (not currently used).
  • Your rights. Not applicable while the Service is English-only.

12. Analytics Cookies

Purpose. Analytics cookies would help us understand how the Service is used so we can improve it.

  • What we actually do. We do not currently use analytics cookies, and the current codebase does not integrate any third-party analytics service. If we introduce analytics in future, non-essential analytics cookies will be set only with your prior consent (§23), and this Policy and the classification table will be updated first.
  • Category. Analytics (not currently used).
  • Legal basis (if introduced). Consent (GDPR Art. 6(1)(a); ePrivacy).
  • Your rights. Not applicable today; if introduced, you will be able to accept or decline via Cookie Preferences (§26).

13. Performance Cookies

Purpose. Performance cookies would measure and improve the reliability and speed of the Service.

  • What we actually do. We do not currently use performance cookies. Any future performance cookies that are non-essential will be treated as analytics for consent purposes (§12) and set only with consent.
  • Category. Performance (not currently used).

14. Marketing Cookies

Purpose. Marketing cookies would be used to deliver or measure advertising.

  • What we actually do. We do not use marketing or advertising cookies, and we do not integrate advertising or social-media tracking pixels (for example, we do not use a Meta Pixel or similar). We do not sell your Personal Data (see Privacy Policy §34, /legal/privacy). If we ever introduce marketing cookies, they will be set only with your prior consent.
  • Category. Marketing (not currently used).

15. Third-Party Cookies

Purpose. This section explains cookies associated with third parties whose technology runs within the Service.

  • Stripe - when you use the payment/upgrade flow, Stripe's client-side library is loaded and may set Stripe cookies for fraud prevention and secure checkout (§16).
  • AWS - used for Photo Verification (Face Liveness and Rekognition); this operates as processing within AWS's environment rather than by setting advertising cookies on our domain (§17).
  • Supabase - provides our authentication cookies; because they are set under our domain to run the Service, we treat them as first-party strictly necessary cookies (§18).

We do not permit third parties to set advertising or cross-site tracking cookies through the Service.

16. Stripe Cookies

Purpose. To enable secure payment processing and payment-fraud prevention for Premium subscriptions.

  • When set. Only when you enter the payment/upgrade flow, at which point Stripe's client library (js.stripe.com) is loaded. Stripe is not loaded on ordinary browsing of the Service.
  • Cookies (set by Stripe). Typically __stripe_mid (a persistent identifier used for fraud prevention, generally lasting about one year) and __stripe_sid (a short-lived session identifier, generally about 30 minutes). [Implementation verification required before publication - confirm the exact Stripe cookies, names, and durations against Stripe's current cookie documentation at build time.]
  • Category. Strictly Necessary (payment integrity / fraud prevention).
  • Recipient. Stripe, acting as our payment Processor and, for certain functions, as an independent controller (see Privacy Policy §36, /legal/privacy).
  • Retention. As set by Stripe (see §22).
  • Your rights. These support secure payment; blocking them may prevent you from subscribing.

17. AWS Services

Purpose. To perform Photo Verification - confirming you match your profile photographs - using AWS Face Liveness and AWS Rekognition.

  • What we actually do. AWS is engaged as our Processor for Photo Verification (see Privacy Policy §35 and the Photo Verification Policy, /legal/photo-verification). This is biometric processing carried out within AWS's environment during the verification flow; it is not an advertising or cross-site tracking technology. We are not aware that this flow sets advertising cookies on your device. [Implementation verification required before publication - confirm whether the AWS Amplify liveness component sets any first-party browser storage or cookies during a verification session, and, if so, classify and disclose them here.]
  • Category. Strictly Necessary (only for the verification you request), with the biometric aspects governed by explicit consent under the Biometric Information Policy (/legal/biometric-data).
  • Your rights. Biometric processing is consent-based and withdrawable (see Privacy Policy §12 and §28, /legal/privacy).

18. Supabase

Purpose. To provide authentication and backend infrastructure for the Service.

  • What we actually do. Supabase is our authentication and database Processor (see Privacy Policy §37, /legal/privacy). The authentication cookies described in §7 are provided through the Supabase integration and are set under our domain to keep you signed in; we therefore treat them as first-party, strictly necessary cookies.
  • Category. Strictly Necessary (authentication).
  • Recipient. Supabase, acting as our Processor under written data-processing terms.
  • Retention. See §22.
  • Your rights. As for authentication cookies (§7).

19. Cloudflare

Purpose. This section addresses content-delivery / security-proxy cookies.

  • What we actually do. We do not currently use Cloudflare, and the current codebase does not integrate Cloudflare or a Cloudflare Turnstile/anti-bot cookie. If we adopt a CDN or edge-security provider that sets strictly necessary security cookies, we will update this Policy to disclose them. [Implementation verification required before publication - confirm the production hosting/CDN stack and disclose any strictly necessary infrastructure cookies it sets.]

20. Google Analytics

Purpose. This section addresses third-party analytics.

  • What we actually do. We do not use Google Analytics, Google Tag Manager, or any equivalent third-party analytics service. No such integration exists in the current codebase. If we introduce analytics in future, it will be disclosed here and, being non-essential, will be set only with your prior consent (§12 and §23).

21. Other Third Parties

Purpose. This section confirms the absence of other trackers.

  • What we actually do. Beyond Stripe (payments, §16), AWS (verification, §17), and Supabase (authentication, §18), we do not integrate other third-party cookie-setting services, and in particular we do not use social-media pixels, session-replay tools (such as Hotjar), product-analytics SDKs (such as PostHog, Mixpanel, or Amplitude), or advertising networks. This statement reflects the current codebase and will be updated before any such technology is introduced.

Purpose. This section states how long cookies last. Durations for third-party cookies are controlled by the relevant third party and are given as our best current understanding.

Cookie / technologyPartyTypeTypical duration
sb-* (Supabase auth)First-partySession + refreshSession, with token refresh as configured
tirvea_did (device/security)First-partyPersistentUp to 12 months
tirvea:appearance (theme, local storage)First-partyPersistent (local storage)Until changed or cleared
__stripe_mid (Stripe fraud)Third-party (Stripe)Persistent~12 months (set by Stripe)
__stripe_sid (Stripe session)Third-party (Stripe)Session~30 minutes (set by Stripe)

[Implementation verification required before publication - confirm the exact Supabase session/refresh lifetimes and Stripe cookie durations at build time.]

Purpose. This section explains our consent model.

Consent categories. We recognise four categories (§4): Strictly Necessary (no consent required), Functional, Analytics/Performance, and Marketing. Non-essential categories are set only with your prior, specific, informed, and freely given consent, in line with GDPR and ePrivacy rules and Irish Data Protection Commission guidance.

Current position. Today we set only Strictly Necessary cookies (§6). Because we do not currently set non-essential cookies, no consent is presently required to set cookies; we nonetheless provide this Policy and a Cookie Preferences page (§26) for transparency and future control.

Consent design (for when non-essential cookies are introduced). Our consent model is designed to provide:

  • a consent notice presented before any non-essential cookie is set, with clear accept / reject / manage options and no pre-ticked boxes;
  • granular control per category (Functional, Analytics, Marketing);
  • consent logging - a record of the choice made, the categories, and the version;
  • versioning - a cookie Consent Version so that material changes can trigger a renewed consent request;
  • renewal - re-seeking consent at appropriate intervals (for example, periodically or on material change); and
  • easy withdrawal at any time (§27).

[Implementation verification required before publication - the consent-management interface / banner and the Cookie Preferences controls are being finalised; confirm the live implementation, the logging store, and the cookie Consent-Version wiring before publishing any statement that non-essential cookies are gated by a live consent tool.]

24. Managing Cookies

Purpose. This section explains how you can control cookies. You can manage cookies in two ways: (a) through your browser controls (§25), which apply to all cookies including strictly necessary ones; and (b), once available, through our Cookie Preferences page (§26), which lets you accept or decline non-essential categories. Because we currently set only strictly necessary cookies, browser controls are the primary mechanism today.

25. Browser Controls

Purpose. This section describes device-level controls. Most browsers let you view, block, and delete cookies and clear local storage through their settings. You can set your browser to refuse some or all cookies, or to alert you when a site tries to set one. Blocking strictly necessary cookies (authentication, security, payment) will prevent parts of the Service from working - for example, you may be unable to stay signed in or complete a subscription. Clearing the tirvea:appearance local-storage key will reset your theme preference. Browser controls are provided by your browser vendor, not by us.

Purpose. This section describes our in-Service control. Our Cookie Preferences page (/legal/cookie-preferences) is the place to review and change your choices for non-essential cookies. Essential cookies are always on because the Service cannot function without them. [Implementation verification required before publication - the Cookie Preferences controls are being finalised; confirm the live tool before linking it as an operative control.]

Purpose. This section explains withdrawal. Where you have consented to non-essential cookies, you may withdraw that consent at any time, as easily as you gave it, through Cookie Preferences (§26) or by clearing cookies in your browser (§25). Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and does not affect strictly necessary cookies. For withdrawal of biometric consent (a separate matter), see the Biometric Information Policy (/legal/biometric-data) and Privacy Policy §28 (/legal/privacy).

28. Do Not Track

Purpose. This section explains our position on Do Not Track. There is no common industry standard for how to respond to browser "Do Not Track" (DNT) or Global Privacy Control (GPC) signals. Because we do not use tracking, analytics, or advertising cookies, we do not track you across sites regardless of any such signal. If we introduce non-essential cookies in future, we will describe how we treat DNT/GPC signals at that time. [Legal review required before publication - confirm whether any GPC handling is required for the launch jurisdictions.]

29. International Transfers

Purpose. This section addresses transfers of data associated with cookies. Some cookie-related data may be processed by our providers (for example, Stripe for payment cookies). Where this involves a transfer of Personal Data outside the EEA, an appropriate transfer mechanism under Chapter V of the GDPR applies, as described in the Privacy Policy §39 (/legal/privacy). We do not repeat that analysis here. [Legal review required before publication - confirm transfer mechanisms for any provider whose cookies process Personal Data outside the EEA.]

30. Updates

Purpose. This section explains changes. We may update this Cookie Policy to reflect changes to the cookies we use, the Service, or the law - in particular before we introduce any new category of non-essential cookie. We will update the "Last Updated" date and, where a change is material (for example, introducing analytics or marketing cookies), we will seek renewed consent where required and may increment the cookie Consent Version. Continued use of the Service after an update, where permitted by law, indicates awareness of the updated Policy.

31. Contact Information

Purpose. This section tells you how to reach us.

  • Entity: WiseWave Limited (Company Number 762171)
  • Registered office: 39 Cooley Park, Dundalk, Co. Louth, A91 AP2V, Ireland
  • Email: info@tirvea.com

For how we process Personal Data associated with cookies, and for your data-subject rights, see the Privacy Policy (/legal/privacy) and GDPR & Your Rights (/legal/gdpr). To change non-essential cookie choices, use Cookie Preferences (/legal/cookie-preferences).


Version history

  • v1.02026-07-01Initial version.