Browser storage
Cookies and local storage
This notice describes the browser storage used by Rovefold and the optional services controlled by your privacy choices.
Updated: September 3, 2026
1. Overview
Cookies are small values sent with web requests. Local storage and session storage keep information on your device. Rovefold uses necessary storage for security, preferences, checkout, and workspace continuity. Analytics, marketing, and marked external content are optional.
Optional services remain off until you allow the matching category or service. Accepting all, rejecting optional services, and choosing individual settings are equally available in the first notice.
2. Necessary session and security cookies
Necessary cookies support a feature you requested or protect the service. They cannot be disabled in the privacy panel, but you can remove them in your browser; doing so may stop account, checkout, or workspace features from working.
| Cookie/category | Purpose | Typical duration | Why it is used |
|---|---|---|---|
rovefold_consent | Stores the consent revision, language, categories, services, and timestamps. | 182 days for necessary-only choices; up to 365 days for other choices | Remembers and proves your privacy choice |
XSRF-TOKEN | Protects state-changing requests against cross-site request forgery. | Session or server-configured lifetime | Strictly necessary for security |
Store session cookie | Keeps you signed in and associates requests with the server-side session. | Session or server-configured lifetime | Strictly necessary for account features |
Local development Store URL cookie | Selects a test Store API only on the local development server. | Up to one year in local development | Development only; not intended for production |
3. Optional services
The consent panel separates analytics, marketing, and external content. Google services use Consent Mode v2 in Basic mode: Google Tag Manager is not requested before the relevant consent. Meta and external content use explicit application-controlled gates.
| Category/service | Possible storage | Purpose | Current state |
|---|---|---|---|
| Analytics delivery · Google Tag Manager | No visitor cookie by itself | Loads the reviewed GA4 configuration after analytics consent | Active only after Analytics consent |
| Analytics · Google Analytics 4 | _ga (up to 2 years); _ga_Q6ER9L7PN5 (up to 2 years) | Distinguishes consented visits and preserves GA4 session state | Active only after Analytics consent; removed after withdrawal and reload |
| Marketing · Google Ads | _gcl_* | Campaign and conversion attribution | Not configured; no Google Ads tag is published |
| Marketing · Meta Pixel | _fbp, _fbc | Campaign attribution through an explicit adapter | Off without consent or a Meta Pixel ID |
| External content · YouTube/widgets | Provider-dependent cookies or storage | Loads a marked third-party embed | Off until one-time or persistent permission |
Google Tag Manager and Google Analytics 4 are configured for production under Consent Mode v2 Basic. Google Ads tags and a Meta Pixel ID are not configured, so marketing integrations remain inert.
4. Local storage
These product keys remain necessary because they preserve a choice or work initiated by you.
| Key/category | Stored information | Removal |
|---|---|---|
rovefold:origin-country-code | Selected origin or citizenship country code. | When changed, removed, or browser storage is cleared. |
checkout_cart | Selected product, price, currency, and related checkout choices. | After checkout, manual removal, or browser storage clearing. |
Workspace editor keys | Editor mode, current step, revision, and queued workspace operations. | As the workflow changes or browser storage is cleared. |
Local development Store URL | A developer-selected backend address on localhost. | When reset or browser storage is cleared. |
5. Session storage
Session storage normally ends with the browser tab or session.
| Key/category | Stored information | Removal |
|---|---|---|
checkout_confirmation_snapshot | Short-lived order confirmation details shown after checkout. | When the browser tab/session ends or storage is cleared. |
checkout_resume_authorization | Single-use marker allowing checkout to resume after sign-in. | After checkout resumes, sign-in is cancelled, or the browser session ends. |
support_impersonation_session | Temporary support-session context and authorization data. | When the support session or browser session ends. |
Workspace review and UI state | Short-lived state that avoids losing a current view or repeating a prompt. | When the browser tab/session ends or storage is cleared. |
Sentry smoke-test marker | Prevents an explicitly enabled production smoke test from repeating. | When the session ends; used only when configured. |
6. Error monitoring
Sentry error monitoring can be enabled for service reliability without default personal information. The integration removes query strings, share tokens, request bodies, headers, cookies, email addresses, and authentication values, and identifies a signed-in user only by internal numeric ID.
Sentry is treated as necessary operational security and reliability processing, not as analytics or marketing. In production, Rovefold sends error events and currently samples 10% of performance transactions to Sentry’s European Union data region. Events are kept only for the event-retention period provided by the active Sentry plan and are then removed under Sentry’s retention lifecycle. If a Sentry subprocessor handles data outside the EEA, the transfer relies on an applicable adequacy decision or Standard Contractual Clauses under the Sentry Data Processing Addendum.
7. Your choices
Use the button below, the footer, your account menu, or the trip workspace menu to reopen privacy settings. Withdrawing consent updates provider signals, clears declared optional cookies, and may reload the page to stop an already loaded provider.
You can also clear browser cookies, local storage, and session storage. This may sign you out, empty the cart, remove preferences, discard queued edits, or interrupt a support or confirmation flow.
Questions can be sent to support@rovefold.com.