Cookie Policy
This policy explains which cookies Palco uses, what they do, and how you can control them.
One thing is worth saying up front: public event pages use no analytics or advertising cookies. Neither ours nor anyone else's. That is why no consent request appears when you open an event page — there would be nothing to authorise.
1. What cookies are
Cookies are small text files a site stores on your device through the browser. They let a site remember things between requests — that you are signed in, which language you chose — without asking again on every page.
They do not damage your device and, on their own, do not reveal who you are.
2. Which cookies we use
A. Strictly necessary
These are the only ones we set without consent, under Article 5 of Portuguese Law 41/2004: without them the service you asked for does not work.
palco_sessao,palco_sessao_afiliado,palco_admin— keep the session of anyone signed in to the organiser dashboard, the affiliate area or administration. They only exist after sign-in, and last for the session or its validity period.palco_idioma— remembers the language you picked in the selector, so the page is not served in the wrong one again. Written only when you use the selector. Lasts one year.palco_tema— remembers the light or dark theme preference for the dashboard. Does not exist on public pages.palco_comprador— keeps you signed in to the buyer account you opened through the link sent by email. Only exists after you sign in.palco_visitante— a random identifier, tied to no name or address, used only so the same tap on an event's "Hype" button is not counted twice. Created at the moment you press that button, never merely by opening a page. Lasts one year.palco_onde— remembers the municipality you chose to order the home page by, when you correct the estimate we show you. Only created when you make that choice. Lasts six months.
B. Local storage, on your device
These are not cookies and are never sent to us in any request. They are values your browser keeps on your own device, and they only leave it if your browser uses them to draw the page.
palco.vistos— the list of the last events you opened, kept so we can show you "Recently viewed" on the home page. With no session signed in, it stays on your device and nowhere else: when you open the home page it is your browser that asks us for those events' details, without telling us who you are. It holds at most twelve addresses and is cleared by clearing this site's data in your browser.
palco.dica-perto— a mark that we have already shown you, once, the bubble suggesting you look at what is on near you. It holds the value "1" and nothing else; it exists only so we do not show you the same hint on every visit.
When you are signed in to a buyer account, that list is also kept in your account — this is what lets you see on your computer what you opened on your phone. We keep only the event and the date you last opened it, at most twelve, and only while you have an account: deleting the account deletes the list. The event organiser cannot see it, not even the count. If you would rather not have this history, browse without signing in.
C. Payment processor cookies
When you reach the payment step, Stripe loads its own components and may set its own cookies, needed for processing and fraud detection. Those cookies belong to Stripe and are governed by Stripe's privacy policy. Without them, paying securely by card is not possible.
D. Analytics and advertising
We use none. No Google Analytics, no social network pixels, no third-party audience measurement cookies.
About affiliate links. A sale is attributed to an affiliate from the code travelling in the page address (?ref=), read on the server at the moment of purchase. No cookie is used for it — which also means nothing is left on your device just because you opened a promotion link.
3. How to control them
You can block or delete cookies in your browser settings. Every current browser lets you do this per site.
Bear in mind that blocking strictly necessary cookies breaks the signed-in areas: you will not stay authenticated in the organiser dashboard or the door app. Public event pages keep working — including buying — except for the payment step, which depends on Stripe's components.
4. Changes to this policy
If we ever add a technology that requires consent, this policy is updated first, and a proper consent request appears — with a real choice, and with refusing made as easy as accepting.