Cookies

COOKIE POLICY

Y3S Platform (y3s.app)

Provider: UOwn Corporation s.r.o.   |   Effective Date: 01.01.2026   |   Last Updated: 06.03.2026

Legal Framework

This Cookie Policy is issued in compliance with:

  • Directive 2002/58/EC (ePrivacy Directive), Article 5(3)
  • Regulation (EU) 2016/679 (GDPR), Articles 6 and 7
  • Czech Act No. 127/2005 Sb. (Electronic Communications Act), § 89(3)

1. About This Cookie Policy

This Cookie Policy explains what cookies are and how UOwn Corporation s.r.o. ("we," "us," or "Provider") uses them on the Y3S Platform (https://www.y3s.app). You should read this policy to understand the types of cookies we use, the information we collect using cookies, and how to control your cookie preferences.

For further information on how we use, store, and protect your personal data, please see our Privacy Policy.

2. What Are Cookies?

Cookies are small text files that are stored on your device (computer, tablet, or mobile phone) when you visit a website. They are widely used to make websites work more efficiently and to provide information to website owners.

We also use Local Storage (HTML5), which allows data to be stored locally on your browser to support the Platform's functionality (e.g., saving your trading dashboard layout, chart settings, or language preferences). For the purposes of this policy, the term "cookies" refers to both cookies and Local Storage.

3. How We Use Cookies

We use cookies and Local Storage exclusively for the following purposes:

Authenticate you and keep you logged in while you use the Platform (via JWT tokens).

Remember your preferences (such as language, chart settings, or dashboard layout).

Ensure the security and proper functioning of the Platform.

We do NOT use any cookies for analytics, advertising, tracking, or marketing purposes.

4. Types of Cookies We Use

4.1 Strictly Necessary Cookies

These cookies are essential for the operation of our Platform. They enable core functionality such as authentication and security. The Platform cannot function properly without these cookies. These cookies do not require your consent under Article 5(3) of the ePrivacy Directive.

Cookie NamePurposeProviderDuration
authSessionDetects whether the user is logged in (boolean flag true/false). Used by Next.js middleware. Does not contain any sensitive data.Y3S (1st party)7 days
y3s-languageStores the user's language preference (en/cs/sk/de/hu).Y3S (1st party)1 year

4.2 Temporary / Development Cookies

The following cookies are used only during specific operational modes (development, maintenance) and are not present during normal production use:

Cookie NamePurposeProviderDuration
devAccessDev environment access key (development only).Y3S (1st party)30 days
constructionGateAccess during "under construction" mode (temporary).Y3S (1st party)7 days
maintenanceAccessAccess during maintenance mode (temporary).Y3S (1st party)1 day

4.3 Analytical / Marketing Cookies

We currently do NOT use any analytical, performance, marketing, or targeting cookies on our Platform. No third-party tracking scripts (such as Google Analytics, Facebook Pixel, or Google Ads) are integrated.

5. Local Storage

In addition to cookies, we use your browser's Local Storage to save your preferences and improve your user experience. The following data is stored locally on your device and is never transmitted to third parties:

KeyPurposeData Type
accessToken / refreshTokenJWT authentication tokens.String
userProfile of the logged-in user.JSON
y3s-languageLanguage preference (backup to cookie).String
dashboard-layout / visibility / hero-*Dashboard card arrangement and visibility settings.JSON
tv-chart-state-{symbol}TradingView chart state per asset.JSON
chart-drawingsUser's drawings on trading charts.JSON
trading-favoritesFavorite trading pairs.JSON
indicator-favoritesFavorite chart indicators.JSON
notificationSettingsNotification preferences.JSON
lesson-{id}Video lesson progress (seconds watched).Number
onboardingCompletedWhether user completed the onboarding flow.Boolean
bottomPanelHeightHeight of the bottom trading panel.Number
position-locksLocked positions (protection against accidental closure).JSON

All Local Storage data is stored exclusively on your device and is not shared with any third party.

Authentication tokens (accessToken, refreshToken) and sensitive user profile data (user) are automatically cleared from your Local Storage when you actively log out of the Platform, ensuring your session remains secure.

6. Cookie Consent

Our Platform uses exclusively strictly necessary and functional cookies that are essential for the provision of the service. In accordance with Article 5(3) of the ePrivacy Directive and Recital 66 thereof, consent is not required for cookies that are strictly necessary for the provision of an information society service explicitly requested by the user.

Therefore, we do not display a cookie consent banner. However, you can manage cookies through your browser settings (see Section 7 below).

7. How to Manage Cookies in Your Browser

You can set your browser to refuse all or some cookies. However, if you disable strictly necessary cookies, the Platform will not function properly and you may be unable to log in.

Google Chrome: chrome://settings/cookies

Mozilla Firefox: about:preferences#privacy

Safari: Preferences > Privacy

Microsoft Edge: edge://settings/privacy

8. Third-Party Services

The following third-party services are integrated into our Platform. Unless stated otherwise below, these services operate server-side only and do not set cookies on your device:

Stripe: Payment processing. We use Stripe to process payments securely. While payment data is tokenized and handled securely, Stripe may set strictly necessary security cookies (such as __stripe_mid and __stripe_sid) or use local storage on your device when you interact with the checkout process. These are used exclusively for fraud prevention, risk detection, and security purposes. Because they are strictly necessary for the secure processing of your requested payment, they do not require consent under Article 5(3) of the ePrivacy Directive.

Brevo (Sendinblue): Transactional emails and SMS notifications. Server-side only.

Supabase: File storage. Server-side only.

HyperLiquid: Market data via WebSocket. Server-side only.

Google Fonts: DM Sans and Bebas Neue typefaces. Self-hosted via next/font – no external requests are made to Google servers, and no cookies are set.

9. Right to Lodge a Complaint

If you believe that our use of cookies violates applicable data protection laws, you have the right to lodge a complaint with a supervisory authority. The competent authority for the Provider is:

Úřad pro ochranu osobních údajů (ÚOOÚ)

Address: Pplk. Sochora 27, 170 00 Praha 7, Czech Republic

Website: www.uoou.cz

Email: posta@uoou.gov.cz

You may also lodge a complaint with the supervisory authority in the EU/EEA Member State of your habitual residence or place of work. For a full overview of your data subject rights (including the right of access, rectification, erasure, restriction, portability, and objection), please see our Privacy Policy at https://www.y3s.app/legal/privacy.

10. Updates to This Policy

We may update this Cookie Policy from time to time. When we make changes, we will update the "Last Updated" date at the top of this page.

11. Contact

If you have any questions about our use of cookies, please contact us at:

UOwn Corporation s.r.o.

Vojtěšská 211/6, Nové Město, 110 00 Prague, Czech Republic

Email: legal@y3s.app

Updated on: 06.03.2026

Effective from: 01.01.2026