Cookie and local storage policy
This is an English translation for convenience. The Spanish version prevails if there is any discrepancy.
1. Owner and scope
The site owner is TAX FACTORY, S.L., Spanish tax number B67123612. Questions: guillem@taxfactory.es. This policy supplements the privacy policy.
Cookies are files a site may store in a browser. Similar technologies include localStorage, sessionStorage, technical identifiers, scripts and third-party requests.
2. Current position
The technical review dated 3 August 2026 found no active analytics, advertising, remarketing or tracking pixels. The site therefore does not display a general cookie banner. If non-essential technology requiring prior consent is added, it will be blocked until a clear accept, reject and preference mechanism is available.
3. Functional browser storage
Language preference
- Key:
taxfactory:locale. - Technology:
localStorage. - Purpose: remember the selected Spanish or English locale.
- Value: only
esoren. - Duration: until changed or site data is deleted.
Contracting draft
- Key:
taxfactory:contracting-wizard-draft:v1. - Technology:
sessionStorage, limited to the tab where contracting starts. - Purpose: temporarily retain the contracting draft so entered details can be recovered if the form is closed and reopened in that tab.
- Content: plan, customer profile, payroll-pack selection, and identity, tax and contact details entered in the form. It does not store legal acceptances, payment or security tokens, Checkout URLs, or signature credentials or links.
- Duration: no more than four hours; it also disappears when the tab is closed or its data is deleted.
Stripe Checkout resumption
- Key:
taxfactory:contracting-checkout-handoff:v1. - Technology:
sessionStorage, limited to the same tab that started contracting. - Purpose: resume the same payment attempt after returning from Stripe Checkout, without creating another payment session or capacity reservation.
- Content: the exact request identifier, canonical contracting payload without the Turnstile token, server-authorized tax breakdown, local return path and timestamp. It does not store the Stripe Checkout URL, payment or security data or tokens, bootstrap codes, access tokens, credentials, or signature links.
- Duration: no more than thirty minutes. It is removed when expired or invalid, when a new attempt is started or edited, or after the payment result is authenticated.
Temporary contracting access
- Prefixes:
taxfactory:contracting-bootstrap:v1:andtaxfactory:contracting-access:v1:. - Technology:
sessionStorage. - Purpose: first keep the bootstrap code inside the tab so its exchange can be retried after a connection interruption, then retain the final temporary status and portal credentials. Stripe receives only that bootstrap code in the URL fragment; the page stores it before removing it from the address and removes it after confirming the final credentials.
- Content: contract identifier, temporary random bootstrap code and temporary random final credentials, not the contract document.
- Duration: the tab session or until invalidated; the bootstrap code expires within 24 hours. The server never stores raw codes or tokens: it stores the code digest and an AES-GCM encrypted envelope so the same pair can be recovered during exchange.
4. External services
CARTO office map
The map uses Leaflet and tiles from basemaps.cartocdn.com, with OpenStreetMap and CARTO attribution. CARTO may receive IP, browser, device, referrer and timestamps. One spot check found no Set-Cookie header, which does not guarantee future provider behavior. See CARTO Privacy.
Cloudflare Turnstile
Forms use Turnstile to prevent abuse. Cloudflare may process IP, browser, device and technical signals. The reviewed configuration does not enable cf_clearance pre-clearance, but this must be checked again after integration changes. See Cloudflare Privacy.
Stripe and e-Signature.eu
Stripe is loaded when the user proceeds to secure payment and applies its own technologies on its domain. e-Signature.eu is involved after payment when the signatory enters its environment to verify their identity and complete the advanced electronic signature. Their own policies and the relevant contracts apply.
5. Browser controls and changes
Browser privacy settings can block or delete cookies and storage. Blocking local storage, session storage, Turnstile or third-party resources may prevent language memory, status access, form submission or map display.
TaxFactory will review this policy when code, providers or purposes change. Contact: guillem@taxfactory.es.