Policy · Legal document

Cookies Policy

Last updated: September 10, 2026

Spanish is the legal source-of-truth for this document. In case of discrepancy between language versions, the Spanish version prevails.

1. What is a cookie?

A cookie is a small text file that a website stores in your browser to recognise you on subsequent visits, keep your session active, remember your preferences or measure use of the service.

2. Data Controller

PROMO-TIENDA, S.L. (hereinafter "PROMOTIENDA" or "the Data Controller"), with address at Avda. Paral·lel, 110, 08015 Barcelona, Tax ID B60840675. Contact: comercial@promotienda.es / +34 93 329 74 64.

3. Scope of this policy

This Cookies Policy applies to:

4. Cookies we use

4.1 Strictly necessary cookies (no consent required)

NameOwnerPurposeDuration
PROMOTIENDAFirst party (rds.digitalsignagerds.com)PHP session identifier. Keeps the user authenticated while they use the Application.Session (deleted when the browser is closed)
CSRF tokenFirst partyAnti-CSRF request token, bound to the session, used to protect actions that modify data.Session
rds_consentFirst party (.digitalsignagerds.com)Stores your answer to the cookie banner (all = accept, essential = reject). In the Application, the Configure button stores a JSON object under this same cookie holding the per-category choice.180 days

4.2 Functionality cookies

NameOwnerPurposeDuration
langFirst party (rds.digitalsignagerds.com)Remember the user's selected language (es, en, ca, fr, pt).12 months

4.3 Security cookies

NameOwnerPurposeDuration
rds_mfa_trustFirst party (rds.digitalsignagerds.com)Mark a device as "trusted" so the second authentication factor is not requested on every login.30 days

4.4 Third-party cookies

This Cookie Policy is the single document governing cookies on both of the domains listed in section 3: the corporate site www.digitalsignagerds.com and the Application rds.digitalsignagerds.com. There is no other cookie policy to refer to.

Neither the corporate site nor the Application uses Google Analytics, Google Tag Manager containers, Hotjar, Meta Pixel or equivalent analytics or profiling tools. The third parties that are involved are listed below, stating in each case which domain they act on and whether they load before or after your consent is obtained.

Third partyWhereCookies and dataPurpose, transfer and consent
Google Ads
Google Ireland Ltd. / Google LLC
ID AW-946666836
Both domains. Corporate site: every page, via /assets/gtag.js. Application: the public signup page (/register.php), which the site's calls to action point at, and the post-signup page (/tutorial.php), both via includes/analytics.inc.php. Both of those pages show the consent banner.Google cookies of the _gcl_au, _gcl_aw, _gcl_dc family (up to 90 days) and our own rds_gclid cookie (90 days) holding the ad click identifier. Your IP address as well.Measuring conversions from our advertising campaigns and linking the visit across the two domains, so that a signup that begins on the corporate site and finishes in the Application is attributed correctly. This involves an international transfer to the United States (Google LLC), covered by standard contractual clauses and the EU-US Data Privacy Framework. Consent: on the corporate site the tag does not load until you accept it; in the Application it likewise does not load on those two pages until you accept it in the consent banner that both of them show.
Calendly
Calendly LLC (United States)
Corporate site only: the “30 minutes with an engineer” band on the home page and the /contact/ page.Cookies set inside the embedded calendar by Calendly and by its providers: __cf_bm (Cloudflare, 30 minutes) and _cfuvid (Cloudflare, session), for bot protection and traffic distribution; OptanonConsent and OptanonAlertBoxClosed (OneTrust, 1 year), which record the decision you take in Calendly's own cookie notice. The frame also loads third-party resources that receive your IP address without setting cookies: js.stripe.com (Stripe, fraud prevention), www.recaptcha.net and www.gstatic.com (Google reCAPTCHA Enterprise, protecting the form against abuse), accounts.google.com (Google Identity Services: Google's identity library, which Calendly uses to offer you signing up for Calendly, or signing in to it, with a Google account; it is not part of reCAPTCHA and it loads whether or not you use that option) and notifier-configs.airbrake.io (Airbrake, Calendly's error logging), together with Calendly's own content servers (assets.calendly.com and its Amazon CloudFront delivery network) and dfp.calendly.com, which serves no content: it receives a device fingerprint generated in your browser and returns an identifier that Calendly attaches to the booking in order to prevent fraud and abuse. Also the data you provide when booking: name, email address, the other booking-form fields, time zone and IP address.Letting you book the free 30-minute call with an engineer. This involves an international transfer to the United States, covered by standard contractual clauses and the EU-US Data Privacy Framework. Consent: no request is made to Calendly until you accept cookies; if you do not accept, we offer a link that opens the calendar on Calendly's own site, so the decision stays yours. A second decision, inside the calendar: Calendly runs its own cookie notice (OneTrust) inside the frame, covering providers that are its own and not ours. If you accept the optional cookies there, Calendly additionally loads Segment, Google Tag Manager, Google Analytics, Facebook, Braze and Sprig; if you decline or do not answer, none of them loads. We neither read nor alter that decision.
Stripe
Stripe Payments Europe, Ltd. (Ireland) / Stripe, Inc. (United States)
Application only: profile and billing, screen renewal and, in the screen-management list, only when you start a payment.__stripe_mid (device identifier, about 1 year) and __stripe_sid (session identifier, about 30 minutes), set by js.stripe.com. Your IP address as well.Processing subscription payments and preventing fraud. This involves an international transfer to the United States, covered by standard contractual clauses and the EU-US Data Privacy Framework. Consent: the Stripe library loads when profile and billing and screen renewal open, and in the screen-management list only when you start a payment; in none of those cases does it wait for your cookie decision.
Google Maps
Google Ireland Ltd. / Google LLC
Both domains. Corporate site: the office map on the /contact/ page. Application: screen map, screen detail, workspace list and location editing.Google's own cookies associated with the embedded map, and your IP address.Showing the office location and placing screens and workspaces on a map. May involve an international transfer to the United States on the same terms as above. Consent: the map loads when the relevant page opens, without waiting for your cookie decision.

Consent summary. The Google Ads cookies — on both domains — and Calendly's are loaded exclusively after you accept them: until then, no request is made to those providers, neither from www.digitalsignagerds.com nor from the Application's /register.php and /tutorial.php pages. The other cases in the table — Stripe and Google Maps in the Application, and the map on the /contact/ page — load when the relevant page opens, or when you start a payment in the case of the screen-management list, without waiting for your decision. If you do not want them to load, block third-party cookies in your browser before visiting those pages.

Both domains also load typefaces from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). That service sets no cookies, but it does disclose your IP address to Google.

Date of measurement. The cookie names, retention periods and third-party resources listed in this section 4.4 are the ones measured on 10 September 2026. For Calendly the measurement was taken inside the calendar embedded in our pages, which is the context this section describes: opening that same calendar directly on Calendly's site — for instance through the link we offer you if you do not accept cookies — is a context of Calendly's own, in which more of its cookies are set. The result also depends on how your browser treats third-party cookies. We repeat this measurement each time we revise the document.

5. Legal basis

6. Managing and withdrawing consent

On first access the Application shows a consent banner with Accept, Reject and Configure options, in line with the AEPD's Guidance on the use of cookies (July 2023). Consent can be reviewed or withdrawn at any time via the Configure cookies link in the footer.

On the corporate site www.digitalsignagerds.com the banner offers Accept and Reject with equal visual weight, and your answer is stored in the rds_consent cookie for 180 days. To change it, delete that cookie in your browser using the instructions below; the banner will appear again on your next visit.

The user may at any time:

  1. Withdraw consent from the "Cookie settings" link in the footer of the Application. On the corporate site, delete the rds_consent cookie as described above.
  2. Block or delete cookies via the browser settings. Instructions: Chrome: https://support.google.com/chrome/answer/95647 — Firefox: https://support.mozilla.org/kb/clear-cookies-website-data — Safari: https://support.apple.com/HT201265 — Edge: https://support.microsoft.com/microsoft-edge

Please note that blocking the strictly necessary cookies will prevent access to the Application.

7. Retention

Cookies are retained for the period stated in the tables above. Data derived from their use (login logs, etc.) is retained as described in the Privacy Policy.

8. User rights

As a data subject, you may exercise the rights of access, rectification, erasure, objection, restriction and portability. The procedure is described in the Privacy Policy.

9. Amendments

This policy may be updated to reflect changes in the legislation or in the cookies used. The date of the last update appears at the top of the document.

© 2026 RDS · digitalsignagerds.com Privacy · Cookies