Cookie Policy
Last updated: 22 July 2026
This Cookie Policy describes how Dream Properties Network uses cookies and similar technologies on the platform.
1. What are cookies?
Cookies are small text files stored on a user's device by a website or application. We also use localStorage (a browser-based storage mechanism) and a service worker (a background script that enables push notification handling). All of these mechanisms are covered by this policy.
2. Cookies we use and their purpose
Strictly necessary
These are required for the platform to function correctly and cannot be disabled through our systems. Users may delete them via browser settings or by clearing localStorage, but doing so will cause the login and language preference functions to stop working correctly.
session_expiry(cookie) — stores the authentication session expiry time; duration: until sign-out;locale(cookie) — remembers the chosen interface language; duration: 1 year;cookieConsent(localStorage) — stores the consent decision so the banner is not shown on every visit; duration: 12 months or until preferences are changed;kc_token(localStorage) — holds the authentication token; duration: token lifetime;kc_refreshToken(localStorage) — holds the refresh token, enabling session renewal without re-login; duration: token lifetime.
The server does not set server-side session cookies — authentication is token-based and stored in the user's browser. These tokens may be deleted by the user by clearing localStorage in browser settings.
Analytics (require consent)
The platform uses PostHog to analyse how the service is used: which features are popular, where technical issues arise, and what requires improvement. PostHog processes data on servers located in the EU.
Upon consent, PostHog stores a pseudonymous session and account identifier in browser localStorage and a cookie, enabling activity recognition across sessions. Prior to consent, PostHog operates in memory-only mode and stores no persistent data.
Push notifications (require separate consent)
Delivering push notifications requires both a browser-level permission and a separate GDPR consent for personal data processing. By granting browser permission, the user simultaneously consents to processing of the device token for the purpose of notification delivery.
Upon consent, we register a device token and service worker, enabling delivery of notifications (new messages, application updates) even when the application is not active.
The token is generated by Firebase Cloud Messaging (Google) and identifies the device or application installation. As the token may be linked to a user account, it constitutes a pseudonymous identifier under the GDPR. Granting consent is voluntary and is not required to use the platform.
OpenStreetMap
When the platform displays a map (e.g. a property location), map tiles are fetched from OpenStreetMap Foundation servers (tile.openstreetmap.org). These servers may log the device's IP address and HTTP request metadata as standard server logs. OpenStreetMap does not set cookies or tracking identifiers in the user's browser.
3. Consent banner
The consent banner displayed on the first visit allows users to accept or decline optional cookies and adjust their preferences. No optional consents are selected by default. Analytics cookies and the push notification token are not set before the user has given consent.
4. Parties involved in processing
- PostHog — analytics (only with user consent); location: EU;
- Firebase / Google — push notification delivery; location: EU or outside EEA;
- OpenStreetMap Foundation — map tiles (HTTP logs only — no cookies); location: EU.
5. Legal basis
Strictly necessary cookies
Basis for storing and reading cookies or localStorage: the technical necessity exemption under applicable national ePrivacy law (implementing Art. 5(3) of Directive 2002/58/EC). Basis for processing personal data: performance of a contract (Art. 6(1)(b) GDPR) and legitimate interest of the Controller in securing the service (Art. 6(1)(f) GDPR).
Analytics cookies: user consent (Art. 6(1)(a) GDPR).
Push notifications: user consent (Art. 6(1)(a) GDPR).
OpenStreetMap: legitimate interest of the Controller (Art. 6(1)(f) GDPR) in presenting property locations.
6. Managing preferences
Analytics: Users may accept or decline analytics cookies via the consent banner on the first visit. The choice can be changed at any time in the cookie settings within the application.
Push notifications: Consent may be withdrawn in browser settings (Site Settings → Notifications). Withdrawal stops future notification delivery. To remove the device token from our servers, use the notification settings in the application or contact us at [TO CONFIRM — contact e-mail].
All cookies: The browser allows users to view, block, and delete cookies and clear localStorage at any time.
7. Changes
This policy may be updated if changes occur to the technologies used, providers, or legal requirements. The date of the last revision is always indicated at the top of the document.
8. Contact
[TO CONFIRM — contact e-mail]