Cookies

What they are and which rules apply

Cookies and similar technologies (such as the browser's local storage) store or read information on your device. Article 22.2 of the Spanish LSSI-CE requires your consent, except when they are strictly necessary to provide a service you have expressly requested or to transmit a communication.

Summary

We use no analytics, advertising, profiling or tracking cookies or similar technologies, neither our own nor third-party ones. Everything we use is technical or stores a preference you choose, and is exempt from consent; that is why we show no cookie banner. The only exception is the shop remembering which distributor's website you came from, which is only stored if you accept it in the shop itself (see "Platform and shop: browser storage"). If we ever wanted to use others, we would ask for your consent first.

The diaglana.com and remote-obd.com websites

They set no cookies. They use the browser's storage, which never leaves your device, only for the contact invitation:

ecopro.lead (local storage, first-party): remembers that you already sent us the form, so the invitation is not shown again, or that you pressed "Not now", so it is not shown for 30 days. Kept until you delete it.

ecopro.lead.shown and ecopro.lead.seconds (session storage, first-party): avoid showing you the invitation more than once per visit or before you have had time to read. Deleted when you close the tab.

Platform (app.diaglana.com) and shop: cookies

All are first-party, technical and secure (__Host- prefix, HttpOnly, Secure and SameSite=Lax): no script can read them, they only travel over encrypted connections to the platform and they contain a random identifier, not your data.

__Host-ecopro-bff-base: keeps you signed in. Up to 1 hour.

__Host-ecopro-bff-aal2 and __Host-ecopro-bff-aal3: reinforced session after the second factor, for sensitive operations. Up to 15 and 5 minutes.

__Host-ecopro-login: binds the sign-in to your browser and protects against request forgery. 5 minutes.

__Host-ecopro-registration: lets you complete the sign-up of a new account. 15 minutes.

__Host-ecopro-device: remembers your trusted device, only if you choose not to sign in again on it. Up to 30 days.

Protection against cross-site request forgery (CSRF) relies on these cookies and on checking the origin of each request; it uses no additional cookies.

Sign-in service

The Diaglana identity service uses its own technical cookies while you sign in or complete sign-up (for example AUTH_SESSION_ID, KC_RESTART, KEYCLOAK_IDENTITY and KEYCLOAK_SESSION). They are needed to identify you and last as long as your sign-in session.

Platform and shop: browser storage

ecopro.locale.hint.v1 (local): the language you choose. ecopro.appearance.v1 (local): the light or dark theme you choose. ecopro.shop.cart.v1 (local): your cart, until you empty it or buy. Kept until you delete them.

Session storage: half-filled forms and the page to return to after confirming the second factor, so you don't lose your work. Deleted when you close the tab. If the platform keeps a copy of help articles in the browser to show them faster, it only contains public texts.

ecopro.shop.origin.v1 (local, first-party, only with your consent): if you reach the shop from a distributor's website (diaglana.com or remote-obd.com) and accept that we remember it, it stores the name of that website and the date it expires, so your purchase is credited to it if you buy later. It lasts 30 days and you can delete it from the shop itself ("Forget it") or from your browser. If you do not accept, nothing is stored: the origin only counts for a purchase in that same visit, and the order keeps only the website's name.

Internal administration tools may keep tasks awaiting confirmation in the browser of authorised staff; they are not used with customers.

Mobile apps

They keep your session in the phone's secure storage (Keychain on iOS, Keystore on Android) and your preferences in the app itself. They use no advertising identifiers or tracking tools.

Third-party services you choose

If you pay with Stripe, PayPal or Redsys, or sign in with Google, Apple or Facebook, those providers may use their own cookies on their pages to provide the service and prevent fraud, under their responsibility and policies. We do not control or read them.

How to delete or block them

You can view, delete or block the website's cookies and storage in your browser's privacy settings (Chrome, Firefox, Safari, Edge or another) and, in the apps, by clearing their data or uninstalling them. If you do, you will have to sign in again, the cart will be emptied and your preferences lost; if you block technical cookies, the platform cannot work.

Changes

If we change what we use, we will update this policy and its date before doing so.