Back

Cookie Policy

The one choice we ask you to make

The first time you visit, a banner asks whether we can use analytics (PostHog, hosted in the EU) to understand how HapHood is used. If you accept, the analytics script loads and stores a random identifier (cookie and localStorage entries with names starting ph_, kept for up to a year) so two screens viewed by the same device count as one visitor. If you decline — the site banner's "Necessary Only", the app banner's "Reject", or simply ignoring the banner — the analytics script is never even downloaded: nothing is stored beyond the essentials below, and no analytics cookie exists on your device.

If you accept, analytics may also record how a screen was used — a "session replay" of taps, scrolling, and technical logs, kept for 30 days — to help us find and fix problems, and events carry a coarse, city-level location derived from your IP address. Analytics is never linked to your name or email, doesn't follow you around the web, and isn't used for advertising. HapHood has no third-party ad cookies at all.

Essential storage

These are required for the Service to function, so they don't need a consent choice:

On the website (haphood.com)

  • haphood-cookie-consent — remembers the consent choice you made, so we don't ask again (kept until you clear or reset it).
  • hh-theme — remembers whether you prefer light or dark mode (kept until you clear it).

In the app (app.haphood.com and mobile)

  • Sign-in tokens — issued by our authentication provider (Logto) and stored on your device so you stay signed in (kept until you sign out). In the mobile apps these live in the app's private, sandboxed storage.
  • Offline cache — a short-lived copy (up to 24 hours) of your reservations, redemption codes, and history, kept locally so your QR code still works at the counter if your connection drops. It's cleared when you sign out or delete your account.
  • Preferences and app state — your consent choice, theme, customer/business mode, which business and branch you last had selected, onboarding and tour progress, deals you've already seen, an unsent feedback draft, and a referral code you followed (kept until it's applied to your account).
  • App shell cache — the web app caches its own code (a standard "service worker") so it opens fast and works offline.

Set by providers inside their own flows

  • Logto — sets its own session cookies on its hosted sign-in pages to run the login securely (they last for the sign-in session).
  • Stripe — sets its own cookies (such as __stripe_mid, kept for about a year) inside the card form on the billing page (shops only) for secure payment handling and fraud prevention. These are part of making the payment work, not tracking.

Optional analytics storage

Only if you accepted analytics: PostHog stores a randomly generated identifier (in a cookie and localStorage, names starting with ph_, kept for up to a year) so that two screens viewed by the same device count as one visitor rather than two. We've kept it restrained: no automatic capture of every click, no advertising use, and no linking to your account identity. Consent-gated session replay (described above) is kept for 30 days. Data goes to PostHog's EU servers.

Changing your mind

Withdrawing consent should be as easy as giving it. On the website, use this button — it erases your consent choice and any analytics cookies, and the banner will ask again on your next visit:

In the app, clearing the app's stored data (or the browser's site data for app.haphood.com) does the same. You can also block cookies entirely in your browser settings; the essentials above may make parts of the Service not work without their storage, but the site itself will still load.

Changes

If we add or change what we store — especially anything that would need your consent — we'll update this page and, where consent is needed, ask you first. Questions: support@haphood.com.