neuroplugin
Sign in
Legal

Cookie Policy

Last updated · 2026-07-18

This Cookie Policy describes the cookies and similar technologies used on neuroplugin.com, in line with the GDPR, the ePrivacy Directive 2002/58/EC as implemented in Spain, and the Cookie Guide published by the Spanish Data Protection Agency (AEPD) in its current revision.

For information on how we process personal data in general, see the Privacy Policy.

1. What a cookie is

A cookie is a small text file that a website places on your device through your browser. Cookies are used to remember preferences, authenticate users, measure usage, and — only with your prior consent — to deliver targeted content. The same legal regime applies to other equivalent techniques (local storage, pixels, SDKs).

2. Cookies we use

We split cookies into the four AEPD categories. Only strictly necessary cookies are set without consent; everything else is loaded only after you accept the corresponding category in the consent banner.

CategoryPurposeLegal basisExamples
Strictly necessarySite availability, security, language preference, consent recordLegitimate interest / contractual necessity (Art. 22.2 LSSI-CE)Session ID, CSRF token, locale, consent record
AnalyticsFirst-party page, product-tour, conversion and bounded campaign-source events so we can improve the site and compare aggregate acquisition channelsConsentRandom browser-session ID and events stored in our own site database
FunctionalRemember UI preferences across visits (theme, sidebar collapse)ConsentUI preferences
MarketingCurrently NOT used. Reserved for future remarketing or advertising audiences; aggregate first-party campaign measurement is part of Analytics.Consentn/a today

We do not load third-party social media or advertising tags by default. The site does not embed Facebook Pixel, Google Ads tags, or TikTok pixels without prior consent.

When analytics consent is granted, we record the page path, event type, relevant product slug, interface placement or tour step, optional order value, the hostname of an external referrer, and a random identifier that lasts only for the browser session. The first consented page in an exact, source-tracked campaign journey may also record four bounded labels — campaign source, medium, name and content. Before a visitor decides, only an exact registered combination of those labels may remain in volatile page memory for at most 30 minutes and one same-locale client-side page change. That temporary value creates no analytics session ID, cookie, local or session storage entry, analytics network request or analytics database event. Rejection, expiry, a second page change or leaving the shared layout discards it. The recorded event path is the page where analytics consent became active; it is not proof of the original landing page. We do not store the complete URL query string, names, email addresses, license keys, full referrer URLs, or advertising identifiers in the analytics event table. The analytics data is used for aggregate traffic, acquisition and conversion reporting and is not used for cross-site profiling.

3. Consent banner and granular control

A consent banner is shown on the first visit. You can Accept all cookies of every category, Reject all non-essential cookies, or Customize by category. Your choice is stored in a strictly-necessary “consent record” cookie for up to 24 months, after which the banner is shown again. You can revisit your preferences at any time via the persistent “Cookies” link in the site footer.

4. Retention

Cookie typeMaximum lifespan
Session IDUntil the browser is closed
Consent record24 months
Locale preference12 months
Analytics browser-session ID (with consent)Until the browser session ends
First-party analytics events (with consent)14 months maximum
Functional (with consent)12 months

5. How to disable cookies

Most browsers let you block or delete cookies through their settings:

Note that blocking strictly necessary cookies may prevent the Site from working correctly.

6. Third-country transfers

The current first-party analytics collector writes to our own site database and does not send analytics events to a third-party analytics provider. If we later use another processor that involves a transfer of personal data outside the European Economic Area, that transfer will be covered by an adequacy decision or Standard Contractual Clauses and this policy will be updated, as described in the Privacy Policy.

7. Module-side note: cookies in merchants' stores

When a merchant installs a Neuroplugin module (such as NP Rewards Pro), the module may set technical cookies on the merchant's storefront (for example, to remember a referral code from a sponsor's share link until the referee's first order). These cookies are set on the merchant's domain, not on neuroplugin.com, and are part of the merchant's own cookie disclosure to their end customers.

8. Updates

We may update this Cookie Policy as the site evolves or as guidance from the AEPD changes. The “Last updated” date at the top of the page reflects the most recent revision.

9. Contact

For any cookie-related question or to exercise your rights, contact us via the channel listed in the Privacy Policy.