Effective August 9, 2026 · Version 2026-08-09-v11

Cookie and browser-storage notice

Only what the
service needs.

This notice covers cookies, session storage, local storage, and similar technologies used on Kinvoria.

Our approach

We use only storage that is necessary to provide a feature you request, keep an account secure, or recover an in-progress form or checkout. We do not use advertising cookies, cross-site tracking, or optional analytics cookies.

Because the storage listed below is necessary for the requested service, it is not controlled by an advertising-consent banner. If we introduce optional analytics, personalization, or advertising technology, it will remain off until any consent required by law is obtained.

ItemTechnologyPurposeDuration
Secure session cookieFirst-party HttpOnly cookieKeeps an organizer or contributor signed in, protects the account session, and preserves a safe return path during Google sign-in.Removed at sign-out; otherwise expires after up to 14 days of inactivity and no later than 30 days after the session began.
Contribution sign-in recoverySession storageTemporarily keeps the private invitation token in the same browser tab while Google sign-in completes. The token is not placed in the Google or server return-path request.Removed immediately after the Google return, expires after 15 minutes, and normally clears when the browser tab session ends.
Guest contribution duplicate preventionFirst-party local storageWhen you open a private contribution invitation while signed out, your browser generates a high-entropy random token and sends it only to Kinvoria to check guest duplicate status. If you continue as a guest, the same token accompanies submission. The server combines it with the project ID and stores only a project-scoped SHA-256 digest to discourage another contribution from that browser token to the project without using one stable server-side value across projects. If you choose Google instead, the token is ignored for that signed-in submission. It is not a MAC address, hardware identifier, or browser fingerprint.Persists across visits until you clear Kinvoria site data or browser storage. Kinvoria does not periodically refresh it. If necessary storage is unavailable, guest contribution is disabled and Google sign-in remains available.
Create-flow recoverySession storageKeeps the organizer’s in-progress occasion, recipient, birthday display age, prompt, deadline, email, confirmation state, and any active affiliate code from the creation URL in the same browser tab while a requested Google sign-in completes. The code is used only to preserve referral attribution, is not sent to Google, and is not a 30-day cookie or cross-site identifier. This storage does not contain a recipient’s or project subject’s full date of birth.Cleared after successful recovery or account deletion, and normally when the browser tab session ends.
Checkout recoverySession and local storageKeeps project and order identifiers plus a timestamp so an organizer can safely resume a pending one-time checkout without paying twice.Recovery records are valid for up to 7 days and are removed after completion, cancellation, account deletion, or browser-data clearing.

Provider technology

When an organizer or contributor chooses Google sign-in, or an organizer opens Paddle checkout, that provider may use its own cookies or storage under its notice. Those provider features load only when you request them. Review the Google Privacy Policy and Paddle Privacy Notice.

You can block or clear cookies and site data in your browser. Blocking necessary storage may prevent sign-in, guest contribution, form recovery, or checkout recovery. Clearing storage resets the guest duplicate-prevention token and can allow another guest submission from that browser; private browsing or changing browsers or devices has the same limitation. Clearing storage does not cancel an order or delete server-side account, project, contribution, or digest data; use the account or contribution controls or Contact us for those requests.