Atlas Legal
Cookie Policy
Last updated 2 August 2026
1. What Are Cookies?
Cookies are small text files that are placed on your computer or mobile device when you visit a website. They are widely used to make websites work more efficiently, provide a better user experience, and give website owners information about how the site is being used.
This Cookie Policy explains how Atlas Group Technologies Ltd ("we", "our", "us") uses cookies and similar technologies on our website and mobile application (the "Platform").
2. Types of Cookies We Use
Strictly Necessary Cookies
These cookies are essential for the Platform to function properly. They enable core functionality such as security, account access, and remembering your preferences. You cannot opt out of these cookies.
| Cookie Name | Purpose | Duration |
|---|---|---|
| sb-auth-token | User authentication | Session |
| cookie-consent | Stores your cookie preferences | 1 year |
| atlas_session_id | Session identification | Session |
| competition_progress | Tracks competition entry progress (question state, selected tickets) | Session |
Functional Cookies
These cookies enable enhanced functionality and personalisation, such as remembering your preferences, language settings, and recently viewed venues.
| Cookie Name | Purpose | Duration |
|---|---|---|
| theme | Stores dark/light mode preference | 1 year |
| recently_viewed | Recently viewed venues | 30 days |
| location_preference | Preferred location settings | 30 days |
Analytics Cookies
These cookies help us understand how visitors interact with our Platform by collecting and reporting information anonymously. This helps us improve our services.
| Provider | Purpose | Duration |
|---|---|---|
| Internal Analytics | Page views, feature usage | Session |
Marketing Cookies
These cookies are used to track visitors across websites to display relevant advertisements. We currently do not use third-party marketing cookies, but may do so in the future with your consent.
3. Third-Party Cookies & Storage
Some cookies, local storage entries or device identifiers on our Platform are set by third-party services. We only load these once the relevant consent category is enabled (necessary services excepted):
- Stripe (necessary): Secure payment processing for subscriptions, event tickets, gift vouchers and competitions. Sets fraud-prevention cookies on Stripe-hosted checkout pages
- Lovable Cloud / Supabase (necessary): Authentication session token and database access
- Google Sign-In (necessary, only if you choose Google): OAuth authentication
- Cloudflare Turnstile (necessary): Privacy-friendly CAPTCHA on signup and password reset — no cookies, no fingerprinting
- Twilio (necessary): SMS delivery for OTP, manager alerts and booking confirmations, and voice telephony for Trinity Line. No browser cookies. Trinity Line calls reach a venue over the telephone network, so no cookies or browser storage are involved at all — see section 4B of the Privacy Policy for how call data is handled
- ElevenLabs (functional, on-demand): Trinity AI voice and text concierge sessions in the app, and the voice layer of the Trinity Line telephone agent. In the browser it is loaded only when you open Trinity and accept the consent gate; on a phone call no browser technology is used. elevenlabs.io/privacy
- Lovable AI Gateway (functional): Routes Atlas-side AI calls to Google Gemini and OpenAI for content generation, allergen suggestions, sentiment analysis and matchmaking. No browser cookies
- Pushwoosh (functional + marketing): Web push subscription, device HWID and notification analytics. Only initialised after you grant browser push permission
- Mapbox (analytics): Map tiles, geocoding and venue map rendering. Mapbox sets a session-level telemetry cookie used for traffic analysis
- LiveKit (functional, on-demand): Real-time WebRTC audio/video for "Go Live" broadcasts. Loaded only when you open or join a live room
- Mux (functional): Video playback and viewing analytics for venue media
- Blockfrost (via Atlas proxy) (necessary, wallet only): Cardano on-chain queries and transaction submission. Requests are proxied through our edge function so your IP is not shared with Blockfrost
- UTXOS.dev (necessary, wallet only): Loaded inside an isolated iframe at signing time; never has access to your Atlas session cookie
- CoinGecko (necessary, tax export only): Historical ADA/BTC GBP prices fetched server-side when you generate a wallet tax export. No user identifiers are sent
These third parties have their own privacy policies and cookie practices. Each is listed in our Subprocessors register with the applicable Data Processing Agreement.
4. Managing Your Cookie Preferences
4.1 Through Our Platform
When you first visit our Platform, you will see a cookie consent banner allowing you to accept or customise your cookie preferences. You can change your preferences at any time by clicking the "Cookie Settings" link in the footer of our website.
4.2 Through Your Browser
Most web browsers allow you to control cookies through their settings. Common browser cookie settings:
Please note that disabling certain cookies may affect the functionality of our Platform.
4.3 Re-Consent and Policy Updates
In line with PECR guidance, your stored cookie consent automatically expires after 12 months, and is also reset whenever we materially change the vendor list or processing purposes (we then publish a new policy version). When either condition is met, the cookie banner is shown again and all non-essential cookies remain disabled until you make a fresh choice. The current policy version is reflected in the "Last updated" date above.
5. Similar Technologies
In addition to cookies, we may use other similar technologies:
- Local Storage: Used to store data locally on your device for improved performance
- Session Storage: Temporary storage that is cleared when you close your browser
- Email Tracking Pixels: Venue marketing emails sent through the Platform may contain small transparent images (tracking pixels) that notify us when an email is opened. This data is used by venues to measure campaign effectiveness (open rates, engagement). You can prevent tracking pixels from loading by disabling remote images in your email client
- Email Click Tracking: Links in venue campaign emails may be routed through our tracking system to record click-through rates. This data is visible to the sending venue via their analytics dashboard
Email tracking pixels and click tracking are only present in marketing emails sent to users who have explicitly opted in to receive venue communications. The lawful basis for this processing is consent under PECR Regulation 6 and Article 6(1)(a) of UK GDPR. You may withdraw consent at any time by unsubscribing from venue emails.
Native app (Capacitor WebView). Inside the Atlas iOS and Android apps, "cookies", local storage and session storage are persisted by the system WebView (WKWebView on iOS, Chromium-based WebView on Android). These stores survive app updates but are cleared when you uninstall the app, sign out, or use Profile → Settings → Privacy & Security → Clear offline data. The app does not use any third-party advertising or cross-app tracking SDKs.
6. Legal Basis
Under the Privacy and Electronic Communications Regulations 2003 (PECR) and UK GDPR, we are required to obtain your consent before placing non-essential cookies on your device. Strictly necessary cookies do not require consent as they are essential for the Platform to function.
7. Changes to This Policy
We may update this Cookie Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Cookie Policy on this page and updating the "Last updated" date.
8. Contact Us
If you have any questions about our use of cookies, please contact us:
Atlas Group Technologies Ltd
Email: support@atlasfoodanddrink.com
Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ