Cookie and Storage Policy
Effective 27 July 2026 · Version 2.5 · Part of our Privacy Policy
This page explains the cookies and browser storage QRCandy uses on qrcandy.co, how we classify each one, and how to change your choices. QRCandy uses no advertising, retargeting, or cross-site behavioural tracking, and never sells personal data.
Manage your choices
You can change your consent at any time. Open the settings below, or use the “Cookie settings” link in the site footer on any page. Strictly-necessary storage always runs because the site cannot work without it; everything optional stays off until you allow it.
What each category does
Strictly necessary — always on
Needed for sign-in, your cart, checkout, the language and currency you pick, security, and remembering your cookie choice. This category also covers error and security monitoring (Sentry): it sets no cookies, stores nothing on your device, and collects no IP address or account identifiers — it only helps us detect and fix faults, which is why we treat it as an essential safeguard rather than analytics.
Analytics — off until you allow it
We use Cloudflare Web Analytics, a cookieless tool that measures aggregate page views and performance so we can improve the site. It sets no cookies and stores no identifier on your device, and when this category is off it does not load at all.
Everything we store
qrcandy:consent · local storage
Remember your cookie choices so we don't ask again on every visit.
- Duration
- 12 months, then we re-ask; removed when you clear browser data
- Category
- Necessary
qrc_locale and qrc_currency · first-party cookies
Remember the language and presentment currency you select.
- Duration
- 1 year
- Category
- Necessary
sidebar_state · first-party cookie
Remember whether the authenticated dashboard sidebar is open.
- Duration
- 7 days
- Category
- Necessary
Supabase authentication token · local storage
Keep an authenticated account signed in and refresh its session securely.
- Duration
- Until sign-out, session invalidation/expiry, or browser data is cleared
- Category
- Necessary
qrcandy:cart, product drafts, brand settings, and QR call-to-action · local storage
Keep the cart and customer-requested design work across pages and return visits.
- Duration
- Until removed, replaced, account data takes over, or browser data is cleared
- Category
- Necessary
qrcandy:checkout:address, :email, and :attempt · local storage
Prefill checkout and safely reconcile/retry the current Stripe checkout attempt.
- Duration
- Until edited, successful checkout removes the attempt, or browser data is cleared
- Category
- Necessary
qrcandy:help-dismissed:* · local storage
Remember that you dismissed a one-time help note.
- Duration
- Until browser data is cleared
- Category
- Necessary
qrcandy:referral · local storage
Remember a followed or applied referral/discount code and its capture time for checkout attribution.
- Duration
- 30 days by default; the configured code window may be 1–365 days; removal at expiry or when you clear the code
- Category
- Necessary
Cloudflare Web Analytics · no cookie
Cookieless, aggregate measurement of page views and performance to improve the site. Loads only if you allow the Analytics category.
- Duration
- No identifier is stored on your device
- Category
- Analytics
Payments and third parties
Payments are handled on Stripe's own hosted checkout pages. Any Stripe cookies used for checkout, fraud prevention, security, and performance are set on Stripe's domain under Stripe's own notices, not on qrcandy.co. Clearing your browser's site data removes the first-party items above, which also signs you out and clears saved carts, drafts, and preferences.
For the full picture of how we handle personal data, see our Privacy Policy and Terms of Service.