Legal
Cookie Policy
How Spafindo uses cookies — only the strictly necessary ones needed to run the platform.
This text should be reviewed by a qualified Spanish lawyer before launch. The company's Tax ID and Companies Register data are shown as pending because the company was recently incorporated.
Last updated: 5 August 2026
1. Who we are
This Cookie Policy applies to the website and booking platform operated by PRIVA SPA, S.L. (sociedad unipersonal), trading as "Spafindo" ("we", "us"), with registered office at Paseo Jesús Santos Rein 2, Edificio Ofisol, 2º-A, Fuengirola (Málaga), Spain; NIF/CIF pending, registration in progress at the Registro Mercantil de Málaga. Contact: info@spafindo.com (contact address pending). Spafindo is a marketplace intermediary connecting guests with independent spa and sauna venues in Spain; payments are processed by a licensed Payment Service Provider (Stripe).
2. What are cookies?
Cookies are small text files that a website stores on your device (computer, tablet or smartphone) when you visit. They let a site recognise your device, keep you signed in and understand how the platform is used. Similar technologies such as local storage can store information in the same way; in this policy we refer to them all as "cookies". This policy follows the AEPD Guia sobre el uso de cookies (2023) and Article 22.2 of Law 34/2002 (LSSI-CE).
3. Consent
Because Spafindo uses only strictly necessary cookies, no prior consent is required under Article 22.2 of Law 34/2002 (LSSI-CE), and the site does not show a cookie-consent banner. There is no "accept all" or "reject all" prompt, and no cookie settings panel to configure, because there is nothing non-essential to accept or reject: we do not install analytics, marketing or advertising cookies.
4. Cookies we use
We use only strictly necessary cookies — the small number required to keep the platform secure and working. We do not use preference, analytics, marketing or advertising cookies.
- Strictly necessary. Keep you signed in and the platform secure — for example the Supabase authentication session cookie, together with security and CSRF protection and secure checkout via our payment service provider. Lawful basis: Art. 22.2 LSSI exemption (no consent required). Retention: for the duration of your session, up to 12 months.
5. Third-party cookies and processors
A small number of strictly necessary cookies may be set by trusted third parties acting as data processors, namely our payment service provider (Stripe) during secure checkout and our hosting and content-delivery providers. We do not use third-party analytics, marketing or advertising cookies. Where a provider is located outside the EEA, transfers are protected by appropriate safeguards such as the EU Standard Contractual Clauses. Each provider operates under its own privacy and cookie policies.
6. Managing cookies in your browser
Since we use only strictly necessary cookies, there is nothing to switch off on the platform itself. Most browsers still let you block or delete cookies from their settings (Chrome, Firefox, Safari, Edge). Disabling strictly necessary cookies may stop parts of the booking flow, including signing in, from working. Consult your browser's help pages for step-by-step instructions.
7. Changes to this policy
We may update this Cookie Policy to reflect changes in technology, the providers we use or applicable law. The "last updated" date shows the latest revision. If we ever introduce non-essential cookies, we will update this policy and put an appropriate consent mechanism in place beforehand.
Related: Privacy · Terms · Legal notice