This Cookie Policy explains which cookies and similar technologies we use on the Outzone website (www.outzone.app), why we use them, how long they are stored and how you can manage them. It is drafted in accordance with the Swiss Federal Act on Data Protection (revFADP) and Art. 45c of the Telecommunications Act (TCA), and, where applicable to users in the European Union/EEA, with the ePrivacy Directive 2002/58/EC and the General Data Protection Regulation (EU) 2016/679 (GDPR).
This notice supplements our Privacy Policy, which you should consult for details on our processing, data recipients, cross-border transfers and your rights.
If there is any discrepancy between the Italian and English versions of this Cookie Policy, the Italian version prevails.
1. In short
- This policy concerns the website only. The Outzone mobile app uses no cookies and no advertising identifiers (such as IDFA on iOS or AAID on Android), and does not track you across third-party apps or sites. On the device the app stores session state and, only for authenticated users, a bounded local queue of actions awaiting delivery; these are not cookies.
- On the website we use a first-party cookie that stores your choice. Only after your consent, we use first-party
localStorageandsessionStoragefor aggregate statistics about interactions with events. We also use technical cookies set by Google reCAPTCHA on forms and, on payment pages hosted by Stripe, Stripe's strictly-necessary technical cookies. - We do not use third-party analytics services or marketing/profiling technologies. We do not use Google Analytics, Meta Pixel, Google Ads, advertising pixels, remarketing or advertising partners.
2. What cookies and similar technologies are
Cookies are small text files that a website saves on your device (computer, smartphone, tablet) and that the same site can read back on later visits. They are used, for example, to make the site work properly or to remember your preferences.
Similar technologies (local storage, web beacons, pixels, SDKs) perform comparable functions; where we use them, this notice applies by analogy.
Cookies can be distinguished by:
- origin: first-party cookies (set by outzone.app) or third-party cookies (set by other providers' domains, such as Google reCAPTCHA or Stripe);
- duration: session cookies (deleted when you close the browser) or persistent cookies (which remain for a defined period).
3. Cookies we use
The table below lists the cookies and technologies actually set on the Outzone website. No third-party analytics or marketing technologies are installed.
| Cookie / technology | Category | Origin | Purpose | Duration |
|---|---|---|---|---|
oz_cookie_consent | Necessary | First party (outzone.app) | Stores your cookie choice (accepted/rejected) so the notice is not shown on every visit | ~6 months (180 days) |
outzone:event-actions:* (localStorage / sessionStorage) | Analytics/statistics | First party (outzone.app) | Stores a random pseudonymous identifier, a session and a bounded queue of event interactions (view, successful share, map opening and entry into the purchase flow) | Consent only; on the next applicable visit, queue rows older than 6 days are removed; session data lasts until the tab is closed; the identifier is removed on withdrawal or on the first visit after consent expires (180 days) |
_GRECAPTCHA | Functional (anti-abuse) | Third party (Google reCAPTCHA) | Spam and bot protection for the site's forms (e.g. contact form); distinguishes humans from bots | Up to ~6 months |
rc::* (e.g. rc::a, rc::c) | Functional (anti-abuse) | Third party (Google reCAPTCHA) | Temporary technical storage used by reCAPTCHA during the anti-bot check | Session / persistent |
Stripe technical cookies (e.g. __stripe_mid, __stripe_sid) | Necessary (payments) | Third party (Stripe) | Set only on payment pages hosted by Stripe, for transaction security and fraud prevention | Session / up to ~12 months |
Stripe cookies are set when you are directed to Stripe-hosted payment pages to complete a purchase; Stripe's own notice also applies on those pages. No Stripe scripts run on the marketing website. For purchases made from the mobile app, the payment flow is handled by Stripe and does not involve cookies set by Outzone.
4. Cookie categories
| Category | Description | Consent | In use on Outzone? |
|---|---|---|---|
| Strictly necessary | Essential for the site to work and for the services you request (e.g. storing your cookie choice, securing payment pages). | Not required | Yes (oz_cookie_consent, Stripe technical cookies at checkout) |
| Functional / preferences | Improve functionality and experience (e.g. anti-abuse protection of forms). | Required for components that are not strictly necessary (e.g. reCAPTCHA) | Yes (Google reCAPTCHA) |
| Analytics / statistics | Measure aggregate interactions with events to improve the service and provide statistics to organizers. | Required (opt-in) | Yes (first-party outzone:event-actions:* technologies) |
| Marketing / profiling | Personalised advertising, remarketing, cross-site tracking. | Required (explicit opt-in) | No |
First-party statistics are not activated before consent and are not used for advertising, profiling or cross-site tracking. Refusing, withdrawing or letting consent expire prevents new records and removes the identifier, session and pending queue from the browser.
5. Legal basis and the Switzerland vs EU difference
The applicable approach depends on your country, but we apply a single EU-grade standard that satisfies both regimes.
- Switzerland (revFADP + Art. 45c TCA): Swiss law does not impose an "EU-style" consent banner for ordinary cookies; the baseline model is transparency and the ability to refuse (opt-out). However, under the FDPIC/EDÖB guidelines (2025 version), higher-risk processing (cross-site tracking, third-party advertising, location data) is expected to require explicit consent (opt-in). Strictly-necessary cookies require no consent.
- European Union/EEA (ePrivacy + GDPR): prior consent (opt-in) is required before storing or reading any non-strictly-necessary cookie; strictly-necessary cookies are exempt but must still be disclosed.
Because we serve users in both Switzerland and the EU/EEA, we apply the stricter (EU) standard: a single EU-grade approach also satisfies the Swiss expectations. In practice, components that are not strictly necessary (such as reCAPTCHA) are treated as subject to consent.
6. Managing consent and preferences
On your first visit we show a short notice (banner) that lets you accept or reject non-strictly-necessary technologies, including first-party statistics. Your choice is stored in the first-party oz_cookie_consent cookie for about 6 months; the next time the site opens after expiry, the notice is shown again and local analytics data is removed. Strictly-necessary cookies always remain active to keep the site working.
You can reopen the panel at any time through “Manage cookies” in the site footer to change or withdraw your choice. You can also manage or delete cookies directly in your browser. The steps vary by browser; see the official pages:
- Google Chrome — support.google.com/chrome
- Mozilla Firefox — support.mozilla.org
- Apple Safari — support.apple.com
- Microsoft Edge — support.microsoft.com
Disabling certain cookies may limit some site functions (for example, submitting a form protected by reCAPTCHA). Withdrawing consent does not affect the lawfulness of processing carried out beforehand.
7. Third-party cookies and links to their policies
Some cookies are set by third-party providers, who operate under their own notices. We encourage you to review them:
- Google reCAPTCHA (Google Ireland Ltd / Google LLC) — spam protection for forms: policies.google.com/privacy
- Stripe (Stripe Payments Europe Ltd, IE; Stripe, Inc., US) — hosted payment pages: stripe.com/privacy
These providers may process data collected via their cookies outside Switzerland and the EU (in particular in the United States). In such cases transfers are supported by appropriate safeguards (the EU-U.S. and Swiss-U.S. Data Privacy Framework certification, where available, or Standard Contractual Clauses with the Swiss addendum). Details on recipients, destination countries and safeguards are in the Privacy Policy.
8. Mobile app: no cookies, no advertising identifiers
The Outzone mobile app uses no cookies and no device advertising identifiers (IDFA on iOS, AAID on Android), and does not track you for advertising across third-party apps or sites. On the device it stores session state and a bounded local queue of actions that have not yet been delivered. The queue exists only for authenticated users, drops rows after six days, and is deleted on logout, account switching or account deletion; it is excluded from backups and may be evicted by the operating system. These are app-storage mechanisms, not cookies or advertising identifiers. The app's location features are described in the Privacy Policy (geolocation is separate from cookies).
9. Changes to this Cookie Policy
We may update this Cookie Policy in case of legal, technological or organizational changes — for example if we introduce new cookies or new providers in the future. The last-updated date is shown at the top. We encourage you to review it periodically.
10. Contact
For any question about this Cookie Policy or the processing of your data:
- Email: info@outzone.app
- Address: Outzone Sagl, Via Grumo 31, 6929 Gravesano, Ticino, Switzerland
For more on your rights and the supervisory authority (in Switzerland the FDPIC/EDÖB; in the EU/EEA the competent authority), see the Privacy Policy.
Outzone Sagl · Via Grumo 31, 6929 Gravesano, Ticino, Switzerland · CHE-251.077.155 (Commercial Register of the Canton of Ticino) info@outzone.app · www.outzone.app