Policy · Legal document

Cookies Policy

Last updated: August 29, 2026

Spanish is the legal source-of-truth for this document. In case of discrepancy between language versions, the Spanish version prevails.

1. What is a cookie?

A cookie is a small text file that a website stores in your browser to recognise you on subsequent visits, keep your session active, remember your preferences or measure use of the service.

2. Data Controller

PROMO-TIENDA, S.L. (hereinafter "PROMOTIENDA" or "the Data Controller"), with address at Avda. Paral·lel, 110, 08015 Barcelona, Tax ID B60840675. Contact: comercial@promotienda.es / +34 93 329 74 64.

3. Scope of this policy

This Cookies Policy applies to:

4. Cookies we use

4.1 Strictly necessary cookies (no consent required)

NameOwnerPurposeDuration
PROMOTIENDAFirst party (rds.digitalsignagerds.com)PHP session identifier. Keeps the user authenticated while they use the Application.Session (deleted when the browser is closed)
CSRF tokenFirst partyAnti-CSRF request token, bound to the session, used to protect actions that modify data.Session
rds_consentFirst party (.digitalsignagerds.com)Stores your answer to the cookie banner (all = accept, essential = reject). In the Application, the Configure button stores a JSON object under this same cookie holding the per-category choice.180 days

4.2 Functionality cookies

NameOwnerPurposeDuration
langFirst party (rds.digitalsignagerds.com)Remember the user's selected language (es, en, ca, fr, pt).12 months

4.3 Security cookies

NameOwnerPurposeDuration
rds_mfa_trustFirst party (rds.digitalsignagerds.com)Mark a device as "trusted" so the second authentication factor is not requested on every login.30 days

4.4 Third-party cookies

This Cookie Policy is the single document governing cookies on both of the domains listed in section 3: the corporate site www.digitalsignagerds.com and the Application rds.digitalsignagerds.com. There is no other cookie policy to refer to.

Neither the corporate site nor the Application uses Google Analytics, Google Tag Manager containers, Hotjar, Meta Pixel or equivalent analytics or profiling tools. The third parties that are involved are listed below, stating in each case which domain they act on and whether they load before or after your consent is obtained.

Third partyWhereCookies and dataPurpose, transfer and consent
Google Ads
Google Ireland Ltd. / Google LLC
ID AW-946666836
Both domains. Corporate site: every page, via /assets/gtag.js. Application: the public signup page (/register.php), which the site's calls to action point at, and the post-signup page (/tutorial.php), both via includes/analytics.inc.php. Neither of those two pages shows the consent banner.Google cookies of the _gcl_au, _gcl_aw, _gcl_dc family (up to 90 days) and our own rds_gclid cookie (90 days) holding the ad click identifier. Your IP address as well.Measuring conversions from our advertising campaigns and linking the visit across the two domains, so that a signup that begins on the corporate site and finishes in the Application is attributed correctly. This involves an international transfer to the United States (Google LLC), covered by standard contractual clauses and the EU-US Data Privacy Framework. Consent: on the corporate site the tag does not load until you accept it; in the Application, the tag loads on both of those pages without waiting for your cookie decision, and neither page asks you for one.
Calendly
Calendly LLC (United States)
Corporate site only: the “30 minutes with an engineer” band on the home page and the /contact/ page.Calendly's own cookies, set inside the embedded calendar, and the data you provide when booking: name, email address, the other booking-form fields, time zone and IP address.Letting you book the free 30-minute call with an engineer. This involves an international transfer to the United States, covered by standard contractual clauses and the EU-US Data Privacy Framework. Consent: no request is made to Calendly until you accept cookies; if you do not accept, we offer a link that opens the calendar on Calendly's own site, so the decision stays yours.
Stripe
Stripe Payments Europe, Ltd. (Ireland) / Stripe, Inc. (United States)
Application only: profile and billing, the screen-management list and screen renewal.__stripe_mid (device identifier, about 1 year) and __stripe_sid (session identifier, about 30 minutes), set by js.stripe.com. Your IP address as well.Processing subscription payments and preventing fraud. This involves an international transfer to the United States, covered by standard contractual clauses and the EU-US Data Privacy Framework. Consent: the Stripe library loads when those views open, without waiting for your cookie decision.
Google Maps
Google Ireland Ltd. / Google LLC
Both domains. Corporate site: the office map on the /contact/ page. Application: screen map, screen detail, workspace list and location editing.Google's own cookies associated with the embedded map, and your IP address.Showing the office location and placing screens and workspaces on a map. May involve an international transfer to the United States on the same terms as above. Consent: the map loads when the relevant page opens, without waiting for your cookie decision.

Consent summary. Only the corporate site's Google Ads cookies and Calendly's are loaded exclusively after you accept them: until then, no request is made to those providers from www.digitalsignagerds.com. The other cases in the table — Stripe and Google Maps in the Application, the map on the /contact/ page, and the Google Ads tag on the Application's /register.php and /tutorial.php pages — load when the relevant page opens, without waiting for your decision. If you do not want them to load, block third-party cookies in your browser before visiting those pages.

Both domains also load typefaces from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). That service sets no cookies, but it does disclose your IP address to Google.

5. Legal basis

6. Managing and withdrawing consent

On first access the Application shows a consent banner with Accept, Reject and Configure options, in line with the AEPD's Guidance on the use of cookies (July 2023). Consent can be reviewed or withdrawn at any time via the Configure cookies link in the footer.

On the corporate site www.digitalsignagerds.com the banner offers Accept and Reject with equal visual weight, and your answer is stored in the rds_consent cookie for 180 days. To change it, delete that cookie in your browser using the instructions below; the banner will appear again on your next visit.

The user may at any time:

  1. Withdraw consent from the "Cookie settings" link in the footer of the Application. On the corporate site, delete the rds_consent cookie as described above.
  2. Block or delete cookies via the browser settings. Instructions: Chrome: https://support.google.com/chrome/answer/95647Firefox: https://support.mozilla.org/kb/clear-cookies-website-dataSafari: https://support.apple.com/HT201265Edge: https://support.microsoft.com/microsoft-edge

Please note that blocking the strictly necessary cookies will prevent access to the Application.

7. Retention

Cookies are retained for the period stated in the tables above. Data derived from their use (login logs, etc.) is retained as described in the Privacy Policy.

8. User rights

As a data subject, you may exercise the rights of access, rectification, erasure, objection, restriction and portability. The procedure is described in the Privacy Policy.

9. Amendments

This policy may be updated to reflect changes in the legislation or in the cookies used. The date of the last update appears at the top of the document.

© 2026 RDS · digitalsignagerds.com Privacy · Cookies