Cookie and Local Storage Notice
Effective: 28 August 2026Version: 1.1
On this page
This notice covers everything we store on your device or read back from it. The governing rule is Article 5(3) of the ePrivacy Directive as transposed into Hungarian law, which applies not only to cookies but to any information stored on terminal equipment - including browser local storage. That is why the list below contains several items most cookie notices leave out.
The In short summaries are informational and are there to help you follow the section. The full text always prevails legally.
This document is available in Hungarian and English. In case of any discrepancy, the Hungarian version prevails.
1. Strictly necessary items
Without the items below, sign-in, security or an operation already in progress would break. The consent requirement does not extend to them; the duty to inform does.
| Item | Where stored | Purpose | Lifetime |
|---|---|---|---|
| Sign-in session (sb-…-auth-token, split into .0, .1 parts where needed) | Cookie | Keeps you signed in and refreshes the session securely (Supabase Auth). The cookie is sent only to the Service's own server. | Until the authentication token expires or you sign out |
| Wedding check cache (w_ok) | Cookie | Avoids a database query on every page load. | 15 minutes |
| Active client (active_wedding) | Cookie | Planner accounts only: which client the planner is currently viewing. | Until the session ends |
| Cookie decision record | Local storage | Your choice and the moment you made it. Never sent to the server. This is what lets us honour and evidence the decision. | 12 months, then we ask again |
| Interface preferences | Local storage | Whether you dismissed an information bar, and on the guest photo upload page a random identifier that lets an uploader delete the photo they just added. | Until you clear it |
| Landing animation position | Local storage | Where the landing page demo animation had reached, so it does not restart on return. A single number of seconds that never leaves the browser. | Until you clear it |
| Selected plan (wcp_pending_plan) | Local storage | If you start a subscription but need to register first, we keep the plan name and resume checkout after sign-in. | Until checkout starts |
| Budget calculator result (wcp_pending_budget) | Local storage | The values from the public calculator (guest count, total, currency) so we can carry them into your wedding profile if you register. The data leaves the browser only if you register and the transfer actually happens. | 7 days |
- ItemSign-in session (sb-…-auth-token, split into .0, .1 parts where needed)Where storedCookiePurposeKeeps you signed in and refreshes the session securely (Supabase Auth). The cookie is sent only to the Service's own server.LifetimeUntil the authentication token expires or you sign out
- ItemWedding check cache (w_ok)Where storedCookiePurposeAvoids a database query on every page load.Lifetime15 minutes
- ItemActive client (active_wedding)Where storedCookiePurposePlanner accounts only: which client the planner is currently viewing.LifetimeUntil the session ends
- ItemCookie decision recordWhere storedLocal storagePurposeYour choice and the moment you made it. Never sent to the server. This is what lets us honour and evidence the decision.Lifetime12 months, then we ask again
- ItemInterface preferencesWhere storedLocal storagePurposeWhether you dismissed an information bar, and on the guest photo upload page a random identifier that lets an uploader delete the photo they just added.LifetimeUntil you clear it
- ItemLanding animation positionWhere storedLocal storagePurposeWhere the landing page demo animation had reached, so it does not restart on return. A single number of seconds that never leaves the browser.LifetimeUntil you clear it
- ItemSelected plan (wcp_pending_plan)Where storedLocal storagePurposeIf you start a subscription but need to register first, we keep the plan name and resume checkout after sign-in.LifetimeUntil checkout starts
- ItemBudget calculator result (wcp_pending_budget)Where storedLocal storagePurposeThe values from the public calculator (guest count, total, currency) so we can carry them into your wedding profile if you register. The data leaves the browser only if you register and the transfer actually happens.Lifetime7 days
2. Statistics (consent required)
PostHog measures which features people use and where they get stuck. This informs product development, not advertising.
Until consent is given, the library loads in a mode that writes nothing to your device and sends nothing on its own. In that state only errors that break the Service are reported, without any persistent identifier, on the legitimate interest of keeping the Service functional. After consent it stores an identifier that lets a returning visit be recognised.
PostHog runs in identified mode only: it does not track anonymous visitors, and records only in-app events of signed-in users. Details are on the subprocessor list.
3. Marketing measurement (consent required)
| Tool | What it measures | Without consent |
|---|---|---|
| Google Analytics 4 | Where visitors come from (organic search, ads, referring sites) and which pages they open. | Does not load. The Service uses Google Consent Mode v2. |
| Meta advertising pixel | Effectiveness of Facebook and Instagram ads (for example whether a visitor from an ad created an account) and retargeting. | Does not load, and no request reaches Meta. |
- ToolGoogle Analytics 4What it measuresWhere visitors come from (organic search, ads, referring sites) and which pages they open.Without consentDoes not load. The Service uses Google Consent Mode v2.
- ToolMeta advertising pixelWhat it measuresEffectiveness of Facebook and Instagram ads (for example whether a visitor from an ad created an account) and retargeting.Without consentDoes not load, and no request reaches Meta.
Pages whose URL carries an invitation or upload token (guest page, RSVP, guest photo upload, shared link) are excluded from measurement, and page titles are transmitted with the token stripped. This matters because the token is itself personal-data-like: it identifies the guest it belongs to.
4. Your choice and withdrawal
On the consent bar both buttons appear side by side with equal weight: there is no highlighted Accept and hidden reject. Until you decide, no non-essential tool loads.
Consent can be withdrawn at any time through the Cookie settings link in the footer, and while signed in through the privacy card on the Settings page. Article 7(3) GDPR requires withdrawal to be as easy as giving consent, which is why it is reachable from inside the app and not only from the public footer.
Withdrawal takes effect immediately: the page reloads so that already-loaded measurement scripts stop, and cookies set on the apex domain are removed.
5. Browser settings and automated signals
Every mainstream browser lets you restrict or delete cookies. If you also block the strictly necessary items, sign-in and saving will not work - that is a consequence of the setting, not a fault.
The Service currently does not act on automated browser signals (Do Not Track, Global Privacy Control), because consent is collected per category through an explicit decision and nothing non-essential runs before that decision. If this changes, this section will be updated.
If we introduce a new measurement tool in the future, consent is requested again immediately and this notice is updated before the tool goes live.