Browser storage

Cookies and local storage

This notice describes the browser storage used by Rovefold and the optional services controlled by your privacy choices.

Updated: August 16, 2026

1. Overview

Cookies are small values sent with web requests. Local storage and session storage keep information on your device. Rovefold uses necessary storage for security, preferences, checkout, and workspace continuity. Analytics, marketing, and marked external content are optional.

Optional services remain off until you allow the matching category or service. Accepting all, rejecting optional services, and choosing individual settings are equally available in the first notice.

2. Necessary session and security cookies

Necessary cookies support a feature you requested or protect the service. They cannot be disabled in the privacy panel, but you can remove them in your browser; doing so may stop account, checkout, or workspace features from working.

Cookie/categoryPurposeTypical durationWhy it is used
rovefold_consentStores the consent revision, language, categories, services, and timestamps.182 days for necessary-only choices; up to 365 days for other choicesRemembers and proves your privacy choice
XSRF-TOKENProtects state-changing requests against cross-site request forgery.Session or server-configured lifetimeStrictly necessary for security
Store session cookieKeeps you signed in and associates requests with the server-side session.Session or server-configured lifetimeStrictly necessary for account features
rovefold_localeKeeps your selected interface language.Up to one yearUser-requested language preference
Local development Store URL cookieSelects a test Store API only on the local development server.Up to one year in local developmentDevelopment only; not intended for production

3. Optional services

The consent panel separates analytics, marketing, and external content. Google services use Consent Mode v2 in Basic mode: Google Tag Manager is not requested before the relevant consent. Meta and external content use explicit application-controlled gates.

Category/servicePossible storagePurposeCurrent state
Analytics · Google Analytics_ga, _gidAggregate product and visit measurementOff without consent or GTM configuration
Marketing · Google Ads_gcl_*Campaign and conversion attributionOff without consent or GTM configuration
Marketing · Meta Pixel_fbp, _fbcCampaign attribution through an explicit adapterOff without consent or a Meta Pixel ID
External content · YouTube/widgetsProvider-dependent cookies or storageLoads a marked third-party embedOff until one-time or persistent permission

No GTM Container ID or Meta Pixel ID is currently configured, so those adapters stay inert even if a user grants permission.

4. Local storage

These product keys remain necessary because they preserve a choice or work initiated by you.

Key/categoryStored informationRemoval
rovefold:origin-country-codeSelected origin or citizenship country code.When changed, removed, or browser storage is cleared.
checkout_cartSelected product, price, currency, and related checkout choices.After checkout, manual removal, or browser storage clearing.
Workspace editor keysEditor mode, current step, revision, and queued workspace operations.As the workflow changes or browser storage is cleared.
Local development Store URLA developer-selected backend address on localhost.When reset or browser storage is cleared.

5. Session storage

Session storage normally ends with the browser tab or session.

Key/categoryStored informationRemoval
checkout_confirmation_snapshotShort-lived order confirmation details shown after checkout.When the browser tab/session ends or storage is cleared.
checkout_resume_authorizationSingle-use marker allowing checkout to resume after sign-in.After checkout resumes, sign-in is cancelled, or the browser session ends.
support_impersonation_sessionTemporary support-session context and authorization data.When the support session or browser session ends.
Workspace review and UI stateShort-lived state that avoids losing a current view or repeating a prompt.When the browser tab/session ends or storage is cleared.
Sentry smoke-test markerPrevents an explicitly enabled production smoke test from repeating.When the session ends; used only when configured.

6. Error monitoring

Sentry error monitoring can be enabled for service reliability without default personal information. The integration removes query strings, share tokens, request bodies, headers, cookies, email addresses, and authentication values, and identifies a signed-in user only by internal numeric ID.

Sentry is treated as necessary operational security and reliability processing, not as analytics or marketing. Performance tracing is disabled by default. The final privacy policy must still identify the verified production setup, retention, processing location, and international-transfer safeguard.

7. Your choices

Use the button below, the footer, your account menu, or the trip workspace menu to reopen privacy settings. Withdrawing consent updates provider signals, clears declared optional cookies, and may reload the page to stop an already loaded provider.

You can also clear browser cookies, local storage, and session storage. This may sign you out, empty the cart, remove preferences, discard queued edits, or interrupt a support or confirmation flow.

Questions can be sent to support@rovefold.com.