Tu Gerente Financiero S.A.S. — Cookie Policy
Last updated: May 2026
1. What are cookies?
Cookies are small text files that websites store in the user's browser when they visit. They allow the site to remember information about the visit (such as the active session, language preferences, or browsing data), making the next visit easier and the site more useful.
Cookies are classified along two main axes:
- By duration: Session cookies are automatically deleted when the browser is closed. Persistent cookies remain on the device until they expire or the user manually deletes them.
- By origin: First-party cookies are set directly by tugerentefinanciero.app. Third-party cookies are set by external services integrated into the Platform.
2. Cookies we use
Strictly necessary cookies (consent not required)
These are essential for the basic operation of the Platform. Without them, core functions such as login and secure browsing would not work.
| Cookie | Purpose | Duration |
|---|---|---|
| __session | Authenticated user session | Session |
| __csrf | CSRF security token against request forgery attacks | Session |
| locale | User's language and country preference | 1 year |
| form_state | State of the application form in progress | Session |
| cookie_consent | Record of user's cookie preferences | 1 year |
Performance cookies (consent required)
These allow us to understand how users interact with the Platform in order to improve its performance. Information is collected in aggregate form.
| Cookie | Purpose | Duration |
|---|---|---|
| _perf_nav | Usage metrics and navigation between pages | Session |
| _perf_timing | Page and component response times | Session |
| _perf_errors | Technical error logging for diagnostics | Session |
Functionality cookies (consent required)
These store user preferences to offer a personalized experience.
| Cookie | Purpose | Duration |
|---|---|---|
| user_prefs | Saved user preferences | 1 year |
| theme | Dark/light mode preference | 1 year |
| last_page | Last page visited to resume navigation | 30 days |
Third-party cookies (consent required)
These are set by external services integrated into the Platform.
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
| AWSALB / AWSALBCORS | AWS CloudFront | Load balancing and infrastructure | 7 days |
| _GRECAPTCHA | Google reCAPTCHA | Security and bot prevention (pending activation) | 6 months |
| _analytics_* | To be determined | Behavioral analytics (future implementation) | — |
3. How do we manage consent?
- Consent banner: When accessing the Platform for the first time, an informational banner is displayed allowing the user to manage their cookie preferences.
- Granular consent: The user can accept or reject each category of cookies independently (performance, functionality, third-party).
- Revocation at any time: The user can modify or revoke their consent at any time from the Platform's cookie settings.
- Necessary cookies: Strictly necessary cookies cannot be disabled, as they are essential for the basic operation of the service.
4. How to disable cookies?
In addition to the Platform's cookie settings, you can manage cookies directly from your browser:
- Google Chrome: Settings → Privacy and security → Cookies and other site data.
- Mozilla Firefox: Options → Privacy & Security → Cookies and Site Data.
- Safari: Preferences → Privacy → Manage Website Data.
- Microsoft Edge: Settings → Cookies and site permissions → Cookies and stored data.
Warning: Disabling strictly necessary cookies may affect the operation of the service, including login, secure browsing, and the loan application process. TGF is not responsible for any degradation of the service resulting from the deactivation of essential cookies.
5. Retention period
| Cookie type | Retention period |
|---|---|
| Session cookies | Automatically deleted when the browser is closed. |
| Persistent cookies | Maximum 12 months from creation or last update. |
| Authentication cookies | 30 days (renewable with each login). |
6. International transfer
Data collected through cookies may be processed on Amazon Web Services (AWS) servers located in the United States. These transfers are carried out under international security standards, including ISO 27001 and SOC 2 certifications, and with contractual clauses that ensure an adequate level of personal data protection.
7. Country-specific provisions — Colombia
Legal framework
- Ley 1581 de 2012 — Personal Data Protection.
- Decreto 1377 de 2013 — Partial regulation.
Cookies that collect personal data are subject to Colombia's data protection regime. The legal basis for the use of non-essential cookies is the informed consent of the data subject pursuant to article 9 of Ley 1581 de 2012.
Authority
Superintendencia de Industria y Comercio (SIC).
Third-party cookies are declared in the processing activity registry with the SIC. The data subject may revoke their consent at any time without negative consequences for access to the essential service.
8. Country-specific provisions — Peru
Legal framework
- Ley 29733 — Personal Data Protection Law.
- Decreto Supremo 003-2013-JUS — Regulation.
Cookies that involve processing of personal data require prior, informed, free, and express consent pursuant to Ley 29733. Analytics and behavioral cookies are considered personal data subject to Peruvian law.
Authority
Autoridad Nacional de Proteccion de Datos Personales (ANPDP) — Ministerio de Justicia.
The data subject may exercise their ARCO rights (Access, Rectification, Cancellation, Objection) with respect to data collected through cookies.
9. Country-specific provisions — Ecuador
Legal framework
- Ley Organica de Proteccion de Datos Personales (LOPDP) — 2021.
Cookies that collect browsing data are considered personal data under the LOPDP. The legal basis for the use of non-essential cookies is the explicit consent of the user pursuant to article 7 of the LOPDP.
Authority
Autoridad de Proteccion de Datos Personales (APDP).
The user has the right to withdraw their consent at any time without retroactive effect on the processing previously carried out.
10. Country-specific provisions — Panama
Legal framework
- Ley 81 de 2019 — On Personal Data Protection.
- Decreto Ejecutivo 285 de 2021 — Regulation.
Cookies that collect identifiable user data require consent under Ley 81 de 2019. Third-party cookies are additionally subject to the privacy policies of those third parties.
Authority
Autoridad Nacional de Transparencia y Acceso a la Informacion (ANTAI).
The user may exercise their ARCO rights (Access, Rectification, Cancellation, Objection) with respect to data collected through cookies.
11. Contact
For questions, inquiries, or requests related to the use of cookies on the Platform, you may contact us through:
| Channel | Details |
|---|---|
| privacidad@tugerentefinanciero.app | |
| Response time | 5 business days |