Back to home

Cookie Policy

Ver en español

Last updated: 2026-05-29

This Cookie Policy explains how TOUR RADIUS uses cookies and similar technologies, in compliance with the GDPR and the Spanish LSSI. Your consent is requested for non-essential cookies.

1. What are cookies

Cookies are small text files stored on your device when you visit a website. They are used to remember preferences, improve performance, and analyse usage. Session cookies are deleted when you close the browser; persistent cookies remain for a set period.

2. Types of cookies we use

Essential storage and security: data strictly necessary for UX and consent management (for example, localStorage entries such as your consent choice under the key tour-radius-cookie-consent). When traffic is proxied through Cloudflare, it may set strictly necessary cookies or similar technologies for security (for example bot management). Aggregated measurement without analytics cookies: we count visits and certain interactions as daily totals on our server (and may use Cloudflare Web Analytics for aggregated visits); this does not use PostHog and does not require cookie consent for analytics on our configuration. Optional analytics (non-essential): enabled only after consent. We use PostHog (EU cloud, eu.i.posthog.com) for additional product analytics — page views and aggregated usage events with browser identifiers. We do not use Google Analytics or Plausible on this site.

3. Consent and control

When you first visit the site, we show a cookie banner with two choices: Accept all (enables PostHog analytics) or Essential only (no non-essential analytics). Browsing without clicking does not enable analytics. You can change your choice at any time using Manage cookies / Gestionar cookies in the site footer, which clears your stored preference (localStorage key tour-radius-cookie-consent) and shows the banner again, or by clearing site data for this domain. Your consent is stored locally and is the legal basis for any non-essential processing (GDPR Art. 6(1)(a)).

4. Third-party services and data

CDN and security (Cloudflare): requests to our domain are proxied through Cloudflare, which processes IP address, HTTP headers, and requested resources to provide CDN, DDoS protection, and WAF. Cloudflare may set strictly necessary security cookies. Aggregated visit measurement (Cloudflare Web Analytics, if enabled): Cloudflare may provide cookieless, aggregated statistics about visits to our domain; see Cloudflare's privacy documentation for details. Server-side aggregated counters: when you load pages or use certain features (for example flight or hotel outbound links), our server may increment anonymous daily totals in our database without storing your IP in those statistics. Map tiles: when the interactive map is displayed, your browser fetches tile images directly from tiles.openfreemap.org (OpenFreeMap). These requests transmit your IP address; OpenFreeMap does not set cookies or perform behavioural tracking. IP geolocation for origin suggestions: primarily via a local database on our server; if unavailable, our server may use the CF-IPCountry header from Cloudflare (country code only). We do not send your IP to external geolocation services. Optional analytics (only after consent): PostHog (PostHog Inc., EU cloud at eu.i.posthog.com) may set cookies and use local storage to recognise your browser across pages, measure page views, and record non-sensitive product events. We do not enable session replay. We do not use Google Analytics or Plausible.

5. Retention

Cookie retention periods depend on the type: session cookies expire when you close the browser; persistent cookies are set according to the purpose (e.g. consent preference may be stored for up to 12 months). PostHog cookie durations follow our PostHog project settings (often up to 365 days) until you withdraw consent or clear site data. See section 6 for the inventory.

6. Cookie and storage inventory

Strictly necessary (no analytics consent required): (A) tour-radius-cookie-consent — localStorage, this site — records your cookie choice (accepted/rejected, language, date) — until you use Manage cookies / Gestionar cookies or clear site data (target up to 12 months). (B) __cf_bm — cookie, Cloudflare — bot management — short session (about 30 minutes). (C) cf_clearance — cookie, Cloudflare — security challenge passed — duration per Cloudflare configuration (can be persistent). Analytics only after Accept all: (D) ph_* / ph_phc_*_posthog — cookie(s), PostHog (EU) — browser identifier and session for product analytics — typically up to 365 days or per project settings; exact name includes your project key. (E) PostHog localStorage keys (e.g. ph_*_posthog) — same purposes as (D) — until cleared or opt-out. We do not enable PostHog session replay. This list may be updated when providers change; non-essential items load only with consent.

7. More information

For details on how we process personal data collected via cookies, see our Privacy Policy. For identification of the data controller, see our Legal Notice.

Cookie Policy — TOUR RADIUS