Ga naar de inhoud
EU-gemaakt
Legal

Cookie and Storage Policy

Effective 27 July 2026 · Version 2.5 · Part of our Privacy Policy

This page explains the cookies and browser storage QRCandy uses on qrcandy.co, how we classify each one, and how to change your choices. QRCandy uses no advertising, retargeting, or cross-site behavioural tracking, and never sells personal data.

Manage your choices

You can change your consent at any time. Open the settings below, or use the “Cookie settings” link in the site footer on any page. Strictly-necessary storage always runs because the site cannot work without it; everything optional stays off until you allow it.

What each category does

Strictly necessary — always on

Needed for sign-in, your cart, checkout, the language and currency you pick, security, and remembering your cookie choice. This category also covers error and security monitoring (Sentry): it sets no cookies, stores nothing on your device, and collects no IP address or account identifiers — it only helps us detect and fix faults, which is why we treat it as an essential safeguard rather than analytics.

Analytics — off until you allow it

We use Cloudflare Web Analytics, a cookieless tool that measures aggregate page views and performance so we can improve the site. It sets no cookies and stores no identifier on your device, and when this category is off it does not load at all.

Everything we store

qrcandy:consent · local storage

Remember your cookie choices so we don't ask again on every visit.

Duration
12 months, then we re-ask; removed when you clear browser data
Category
Necessary

qrc_locale and qrc_currency · first-party cookies

Remember the language and presentment currency you select.

Duration
1 year
Category
Necessary

sidebar_state · first-party cookie

Remember whether the authenticated dashboard sidebar is open.

Duration
7 days
Category
Necessary

Supabase authentication token · local storage

Keep an authenticated account signed in and refresh its session securely.

Duration
Until sign-out, session invalidation/expiry, or browser data is cleared
Category
Necessary

qrcandy:cart, product drafts, brand settings, and QR call-to-action · local storage

Keep the cart and customer-requested design work across pages and return visits.

Duration
Until removed, replaced, account data takes over, or browser data is cleared
Category
Necessary

qrcandy:checkout:address, :email, and :attempt · local storage

Prefill checkout and safely reconcile/retry the current Stripe checkout attempt.

Duration
Until edited, successful checkout removes the attempt, or browser data is cleared
Category
Necessary

qrcandy:help-dismissed:* · local storage

Remember that you dismissed a one-time help note.

Duration
Until browser data is cleared
Category
Necessary

qrcandy:referral · local storage

Remember a followed or applied referral/discount code and its capture time for checkout attribution.

Duration
30 days by default; the configured code window may be 1–365 days; removal at expiry or when you clear the code
Category
Necessary

Cloudflare Web Analytics · no cookie

Cookieless, aggregate measurement of page views and performance to improve the site. Loads only if you allow the Analytics category.

Duration
No identifier is stored on your device
Category
Analytics

Payments and third parties

Payments are handled on Stripe's own hosted checkout pages. Any Stripe cookies used for checkout, fraud prevention, security, and performance are set on Stripe's domain under Stripe's own notices, not on qrcandy.co. Clearing your browser's site data removes the first-party items above, which also signs you out and clears saved carts, drafts, and preferences.

For the full picture of how we handle personal data, see our Privacy Policy and Terms of Service.