Cookie policy
What we store in your browser, why it is strictly necessary, and why there is no consent banner.
Last updated: 6 August 2026
Review before launch. This is a starting draft written for a European SaaS that stores member names, email addresses and booking data in the EU. Fill in the bracketed details, check it against how you actually operate, and have a lawyer review it before you go live. It is not legal advice.
Short version
We use no advertising, retargeting or analytics cookies. Everything we store in your browser is strictly necessary to sign you in and keep you signed in. Under Article 5(3) of the EU ePrivacy Directive, storage that is strictly necessary to provide a service you requested does not require consent — which is why you see no consent banner. If we ever add anything non-essential, we will ask for your consent first, before it is set.
What we store
- Session token — browser local storage, set by our authentication provider Supabase. Keeps you signed in and lets the server verify who you are. Strictly necessary. Lifetime: until sign-out or token expiry (typically one hour, then renewed).
- Session refresh token — browser local storage, same provider. Renews your session so you are not signed out mid-session. Strictly necessary. Lifetime: until sign-out or inactivity expiry.
- Sign-in flow value (PKCE verifier) — short-lived browser storage used while a sign-in, email confirmation or password reset link is being completed, so the link cannot be replayed by someone else. Cleared as soon as the flow finishes.
- View preference — where you have chosen a calendar or list view, that choice may be remembered locally on your device. It contains no identifiers and never leaves your browser.
None of these are used to track you across other websites, and none are shared with advertisers.
What we do not use
- No advertising, retargeting or cross-site tracking cookies.
- No third-party analytics, heatmaps or session recording.
- No social media embeds, pixels or share buttons that set cookies.
- No fingerprinting, and no selling or sharing of device data.
If analytics, an embedded map, a video player or a payment provider is added later, this page and the consent approach must be updated first — most of those need prior consent and a banner that lets you refuse as easily as accept.
Third parties that see a request, but set no cookie
- Google Fonts — fonts are fetched from Google's servers, so your IP address is visible to Google. No cookie is set. Self-hosting the fonts removes this entirely and is recommended if you would rather avoid it; note the decision here once made.
- Supabase — receives the API requests your browser makes while signed in.
- Our hosting provider — processes standard server logs, including IP addresses, for a short period for availability and security.
How to clear it
Signing out removes the session tokens. You can also clear site data for this domain in your browser settings, or block storage for this site — note that if you block it you will not be able to stay signed in, because sign-in depends on it. What personal data sits behind your account is described in the privacy policy.
Changes to this policy
Any change to what we store is published here with an updated date above, and any new non-essential storage will be introduced only with your prior consent.
