Back
Publisher: Synegia Sàrl, 21, rue Glesener, L-1631 Luxembourg (Luxembourg Trade and Companies Register B187706, VAT LU28149678)
Document: Cookie Policy
Version: 1.1.0
Effective date: 10 August 2026
Last updated: 11 August 2026
Languages: French and English; in the event of any discrepancy, the French version shall prevail.
This policy explains how Synegia Sàrl ("Synegia", "we", "us") uses cookies and similar technologies when you:
www.dailyfleetpro.com (presentation and information site);It describes what a cookie is, the cookies and similar technologies we use, their purposes, duration, recipients, and how you may configure your choices.
This policy constitutes the second level of information within the meaning of the CNPD guidelines on cookies. It supplements the first level of information displayed in the cookie banner on your first visit (all UI languages).
For personal data processing carried out by Synegia as data controller, this policy should be read together with our Privacy Policy.
A cookie is a small text file placed on and/or read from your device (browser, computer, smartphone, tablet) by the server of the service you are using (a "first-party" cookie) or by a third-party server (a "third-party" cookie).
The term "cookie" also covers similar technologies: pixels, device fingerprinting, browser local storage (localStorage, sessionStorage), identifiers generated by mobile systems, and trackers embedded in application SDKs.
The placement and reading of cookies are governed by Article 5(3) of the ePrivacy Directive, transposed into Luxembourg law (Article 4(3)(e) of the Law of 30 May 2005), and by the GDPR where personal data processing is associated.
DailyFleetPro configuration (source code audit, 11 August 2026):
| Element | Production configuration |
|---|---|
| Essential cookies (auth, banner, interface) | Active — exempt from consent |
| PostHog audience measurement (EU instance) | Enabled only if production configuration provides NEXT_PUBLIC_POSTHOG_ENABLED=true and a PostHog project key |
| PostHog mode | cookieless_mode: on_reject — PostHog cookies/storage only if you accept; otherwise cookieless measurement with an identifier or privacy-preserving server-side pseudonymous hash |
| Google Analytics, Meta Pixel, Hotjar, GTM | Not integrated |
| Marketing / social networks | No trackers |
| Third-party CMP (Cookiebot, Didomi, etc.) | Not used — first-party consent banner (accept / refuse) |
| PostHog session recording | Disabled (disable_session_recording: true) |
| PostHog autocapture | Disabled |
| Marketing attribution | Transmitted in events from the URL/referrer |
| App Store / Google Play badges | External images loaded from Apple / Google; no integrated SDK or advertising pixel |
PostHog transmits product audience measurement events to our European instance (https://eu.i.posthog.com). No events are captured until you accept or refuse. If you accept, PostHog may place first-party cookies/storage and identify your account to link the web journey to the app. If you refuse, cookieless measurement with an identifier or privacy-preserving server-side pseudonymous hash is used (no identify).
Strictly necessary for the operation of the site and the provision of the features you request:
Navigation language: language is carried in the URL (/fr-FR/…, /en-US/…, etc.). We do not place a cookie or localStorage / sessionStorage entry to remember the language.
We use PostHog (PostHog Inc., European instance eu.i.posthog.com) to measure use of the website and subscription interface: pages viewed, clicks on calls to action, start of the payment flow, correlation with a logged-in account (user identifier and organisation), and where applicable linking the web journey with the mobile app.
Configuration: in accordance with PostHog documentation, cookieless_mode: on_reject is enabled. After acceptance, PostHog may place first-party cookies/storage (ph_*) and, when you are logged in, transmit your user and organisation identifiers to link the web journey to the mobile app. After refusal, PostHog stays in cookieless measurement with an identifier or privacy-preserving server-side pseudonymous hash, without identify.
Attribution: when the URL or referrer contains acquisition parameters (utm_*, gclid, fbclid), these may be included in audience measurement events.
Web / app linking: after audience-measurement consent is granted, download links generated by the website may contain the ph_distinct_id parameter. This is the browser's PostHog identifier, transmitted only to allow a potential link with the mobile application when the download flow supports it. This parameter is not added after refusal and may be sent to Apple or Google with the store URL.
What we do not do: no advertising profiling, no global click autocapture, no session recording, no resale of data to advertising networks.
None at this time.
None at this time.
In accordance with Articles 12 and 13 of the GDPR and CNPD guidelines, the tables below list the cookies, local storage entries, audience measurement requests, and third-party resources used on the website and subscription interface as of the last update date.
| Name | Type | Issuer | Purpose | Category | Data collected | Recipients | Cookie / storage duration | Data retention | Transfers outside the EEA | Profiling |
|---|---|---|---|---|---|---|---|---|---|---|
dfp_access | httpOnly cookie | First-party — Synegia | Authentication: maintain logged-in session | Essential | Access JWT (technical session identifier) | Synegia (AWS EMEA) | Duration encoded in the JWT; automatic renewal before expiry | Same as cookie duration | No (EEA) | No |
dfp_refresh | httpOnly cookie | First-party — Synegia | Secure session renewal | Essential | Refresh JWT | Synegia (AWS EMEA) | Duration encoded in the JWT | Same as cookie duration | No (EEA) | No |
dfp_cookie_info_seen | localStorage | First-party — Synegia | Remember your cookie banner choice (accept / refuse) | Essential | Choice, policy version and timestamp (JSON) | Synegia only | Until the choice changes, the policy version changes, or local data are cleared | Until the choice changes, the policy version changes, or local data are cleared | No | No |
dfp_authenticated | localStorage | First-party — Synegia | Client-side "logged-in user" indicator | Essential | Boolean value | Synegia only | Until logout or local clearing | Until logout | No | No |
dfp_organization_id | localStorage | First-party — Synegia | Active organisation (dashboard, checkout) | Essential | Technical organisation identifier | Synegia only | Until logout or local clearing | Until logout | No | No |
dfp_profile_display | localStorage | First-party — Synegia | Display of name and profile photo | Essential | First name, last name, photo URL (if applicable) | Synegia only | Until logout or local clearing | Until logout | No | No |
Notes:
/api/ws-auth. This mechanism does not create an additional cookie.| Element | Type | Issuer | Purpose | Category | Data transmitted | Recipients | Duration / persistence on device | Retention | Transfers outside the EEA | Profiling |
|---|---|---|---|---|---|---|---|---|---|---|
PostHog requests (via first-party /ingest proxy, then EU instance) | Network request (+ PostHog cookies/storage if accepted) | Third party — PostHog Inc. (EU instance) | Product statistics, audience measurement, web ↔ app correlation | Audience measurement | Events listed in section 5.3; page path; URL parameters useful for attribution (utm_*, gclid, fbclid); referrer; user / organisation identifier if logged in and consent granted; ph_distinct_id on download links after consent | Synegia; PostHog Inc. (EU instance), Apple or Google when you open a store link containing this parameter | First-party PostHog cookies/storage (ph_*) only after acceptance; otherwise no PostHog storage (server cookieless hash) | Per PostHog configuration and DPA | EU instance; PostHog contractual framework | Non-advertising |
Consent: the banner offers Accept or Refuse. Acceptance enables PostHog analytics cookies and account identification. Refusal keeps cookieless measurement with an identifier or privacy-preserving server-side pseudonymous hash. Requests first go to our domain (/ingest) and are then relayed to the European PostHog instance.
| Event | Purpose | Data transmitted |
|---|---|---|
$pageview | Pages viewed | Page path, URL parameters, attribution (UTM, referrer) |
landing_cta_clicked | Clicks on marketing site CTAs | CTA identifier, destination, locale, attribution |
acquisition_source_self_reported | Self-reported acquisition source | Signup path, optional selection |
account_created | Account creation | Signup path, optional acquisition source |
checkout_started | Start of payment flow | Plan type, number of seats, organisation identifier |
identify | Correlation with a logged-in account | User identifier, email if provided by the application |
group (organization) | Correlation with an organisation | Organisation identifier |
Identification (identify / group) is sent only when you are logged in and you have accepted audience measurement. No video session recording or global interaction autocapture is enabled.
PostHog may also generate technical consent events, such as $opt_in when consent is granted. These are not additional business events.
| Resource | Type | Issuer | When | Purpose | Cookies / trackers on our domain |
|---|---|---|---|---|---|
| Stripe Checkout, Stripe customer portal, Stripe-hosted invoices | Redirect / new tab to Stripe | Stripe Payments Europe, Limited | When you initiate a payment, manage a subscription, or open an invoice | Payment, subscription management, security and fraud prevention | No Stripe cookie on dailyfleetpro.com; Stripe cookies possible on stripe.com per Stripe cookie policy |
| App Store badges | External image and outbound link | Apple | Display of application download links | Present the official App Store badge | No DailyFleetPro first-party cookie; image request to Apple domains |
| Google Play badges | External image and outbound link | Display of application download links | Present the official Google Play badge | No DailyFleetPro first-party cookie; image request to Google domains |
We do not integrate Stripe.js, YouTube/Vimeo, Google Maps, reCAPTCHA/Turnstile, chat widgets, social plugins, or advertising tag managers on our pages.
Trackers and SDKs in the mobile application are described in the Privacy Policy. The public website does not place mobile SDKs.
| Category | Legal basis |
|---|---|
| Essential cookies (ePrivacy) | Article 4(3)(e) of the Law of 30 May 2005 — consent exemption |
| Data associated with essential cookies (GDPR) | Article 6(1)(b) (performance of contract / service requested) and 6(1)(f) (legitimate interest: security, site operation) |
| PostHog audience measurement (analytics cookies + identify) | Article 6(1)(a) GDPR (consent) when you accept via the banner |
| PostHog audience measurement (cookieless mode after refusal) | Legal basis to be confirmed and documented through a legitimate-interest assessment under Article 6(1)(f) GDPR before this processing is implemented; measurement with an identifier or pseudonymous hash, without identify or analytics cookies |
| Apple / Google resources for download badges | Article 6(1)(f) GDPR (legitimate interest: present official application download links) |
| Stripe Checkout, customer portal and hosted invoices | Article 6(1)(b) GDPR (performance of contract / payment requested) and, for payment security, 6(1)(f) GDPR; Stripe cookies subject to Stripe's policy on its own domains |
You may refuse or withdraw consent via the banner, or contact [email protected] (see section 10).
On your first visit (or while consent is pending), a banner appears at the bottom of the screen. It informs you that:
Actions offered:
identify;dfp_cookie_info_seen) and in PostHog.In accordance with CNPD guidelines, you may reopen the banner at any time via:
These actions clear the dfp_cookie_info_seen record, reset the PostHog choice, and redisplay the banner.
The banner does not reappear automatically after a fixed period. It reappears in the event of a material change to this policy, if you use "Cookie settings", or if you clear local data in your browser.
Via the browser — Settings menu › Privacy › Cookies: deletion or blocking. Blocking essential cookies (dfp_access, dfp_refresh) prevents login and payment.
PostHog audience measurement — use Accept / Refuse via the banner, or contact [email protected]. Blocking requests to /ingest (first-party proxy) or to the European PostHog instance prevents analytics event collection without affecting essential cookies.
Via our interface — "Cookie settings" (footer or this page) reopens the banner.
Complete DailyFleetPro clearing — delete "site data" for dailyfleetpro.com in your browser. This clears the localStorage entries listed in section 5.1, removes DailyFleetPro session cookies in the browser, and will cause the banner to reappear.
Apple / Google resources — blocking external Apple / Google images or domains in your browser may prevent correct display of download badges, without affecting access to the site.
Mobile device — for the native application, see system settings (iOS: Privacy; Android: Privacy / Ads).
| Recipient | Role | Transfers outside the EEA |
|---|---|---|
| Synegia Sàrl | Data controller | No |
| Amazon Web Services EMEA SARL | Hosting infrastructure | No (EEA) |
| Stripe Payments Europe, Limited | Payment, customer portal, hosted invoices | Possible per Stripe; SCC / adequacy |
PostHog Inc. (EU instance eu.i.posthog.com) | Product audience measurement (consent, or cookieless if refused) | EU instance; PostHog contractual framework (DPA) |
| Apple | Display of App Store badges and outbound link to the App Store | Possible per Apple |
| Display of Google Play badges and outbound link to Google Play | Possible per Google |
Full list: subprocessors. No third-party CMP is used.
For personal data processed via essential cookies (e.g. first name and last name in dfp_profile_display), via PostHog audience measurement, or via payment / download journeys, you have the rights described in our Privacy Policy: [email protected].
You may in particular request access, rectification, erasure, restriction of processing, withdraw consent (via the banner), and object to any cookieless audience measurement implemented on the basis of legitimate interest.
Complaint: CNPD, 15, Boulevard du Jazz, L-4370 Belvaux, Luxembourg — www.cnpd.lu.
Version published at the stable URL: www.dailyfleetpro.com/en-US/legal/cookie-policy.
In the event of a change to the PostHog configuration, addition of marketing tools, a third-party CMP, advertising pixels, or any new placement / reading of non-essential trackers on your device, this policy will be updated before the relevant production deployment.
Synegia Sàrl — 21, rue Glesener, L-1631 Luxembourg
Data protection: [email protected]
Support: [email protected]
The French version shall prevail.
DailyFleetPro
Legal information
Language: