Legal

Cookie Policy

Effective date: March 15th. 2026 — Last updated: March 20th. 2026

This Cookie Policy explains how ooverlap uses cookies and similar technologies on its website, invite pages, and related web interfaces.

1. What are cookies and similar technologies?

Cookies are small text files stored on your browser or device when you visit a website. They can be used to keep you signed in, remember your settings, support security features, and improve website functionality.

We may also use similar browser-based technologies such as localStorage and other browser-side storage used to remember certain actions or preferences.

For simplicity, this Cookie Policy refers to these technologies collectively as "cookies" unless otherwise stated.

2. How ooverlap uses cookies

ooverlap currently uses cookies and similar technologies mainly for the following purposes:

  • enabling invite page access for guests;
  • remembering guest session details on invite pages;
  • supporting authentication for the web admin area;
  • remembering language preferences when explicitly selected;
  • supporting infrastructure-level access protection and security where applicable.

ooverlap does not currently use cookies for advertising, behavioral profiling, cross-site ad targeting, or web analytics or tracking tools such as Google Analytics, Meta Pixel, TikTok Pixel, Hotjar, FullStory, Mixpanel, Amplitude, or similar services.

3. Cookies and similar technologies we use

**A. Strictly Necessary Cookies

These cookies are required for core website functionality, security, and access control.

**sb-<project>-auth-token

  • Type: First-party cookie;
  • Purpose: Supports authenticated sessions for the web admin area;
  • Provider / Source: Supabase authentication;
  • Duration: Up to 400 days;
  • Domain: ooverlap.app.

**sb-<project>-auth-token-code-verifier

  • Type: First-party cookie;
  • Purpose: Temporary authentication cookie used during redirect-based authentication flows such as password reset flows;
  • Provider / Source: Supabase authentication;
  • Duration: Temporary — deleted after the flow is completed;
  • Domain: ooverlap.app.

**NEXT_LOCALE

  • Type: First-party cookie;
  • Purpose: Stores your language preference (English or German) so the website displays in the same language on future visits. This cookie is only set when you actively switch the language using the language selector in the navigation bar — it is never set automatically on first visit.;
  • Duration: 1 year;
  • Domain: ooverlap.app.

**B. Browser Storage Used for Functionality

Invite pages do not use cookies for guest sessions. The information below is stored in your own browser and is not transmitted to us automatically with each request.

**lwv_session_<hangoutId>

  • Type: localStorage;
  • Purpose: Stores invite-page guest details locally, such as event ID, email, name, RSVP status, submitted poll votes, and questionnaire responses, so returning visitors can be recognized without re-entering the same information. Only written after the guest actively submits the invite-page form;
  • Duration: Up to 90 days after confirmation.

**lwv_app_onboarding_shown_<hangoutId>

  • Type: sessionStorage;
  • Purpose: Remembers that the post-RSVP app introduction has already been shown, so it is not repeated during the same browsing session;
  • Duration: Cleared when the browser tab is closed.

4. Third-party services and infrastructure

**A. Vercel

ooverlap uses Vercel for hosting. Vercel Authentication is enabled. In connection with this feature, Vercel may set technically necessary authentication or access cookies. These cookies are used for access protection and are not used for advertising or analytics.

**B. Cloudflare

ooverlap uses Cloudflare for infrastructure-related services, including DNS, DDoS protection, and media delivery (media.ooverlap.app). In connection with these services, Cloudflare may set technically necessary cookies such as __cf_bm (bot management, duration approximately 30 minutes) and cf_clearance (challenge verification, duration up to 1 day). These are set by Cloudflare as a data processor for security and infrastructure purposes, and are not used for advertising or analytics.

**C. Fonts

All fonts used on ooverlap, including the custom fonts an organiser can choose for an invite page, are hosted on our own servers. Your browser does not contact Google Fonts or any other font provider, and no font-related request transmits your IP address to a third party.

**D. QR code generation

On certain pages, ooverlap may request QR codes from an external provider (api.qrserver.com). This is used only to generate QR codes and not for advertising or analytics.

**E. Static map images

Some invite pages may display a static map image from Google when location data is available for an event. Loading the image involves a request to Google servers. No Google Maps-related cookies were identified in connection with loading such static map images.

5. No analytics or advertising cookies

ooverlap does not currently use:

  • analytics cookies;
  • performance tracking cookies;
  • advertising cookies;
  • retargeting cookies;
  • social media tracking pixels;
  • session replay tools;
  • behavioral profiling technologies.

In particular, ooverlap does not currently use services such as Google Analytics, Google Tag Manager, Meta Pixel, TikTok Pixel, LinkedIn Insight Tag, PostHog, Amplitude, Mixpanel, Hotjar, FullStory, Microsoft Clarity, or Firebase Analytics for web.

If this changes in the future, this Cookie Policy will be updated accordingly and, where legally required, consent mechanisms will be implemented.

7. How to manage cookies

You can control or remove cookies and browser storage through your browser settings. Most browsers allow you to:

  • view stored cookies;
  • delete cookies;
  • block cookies entirely;
  • block cookies from particular sites.

You can also clear localStorage and other site data through your browser settings.

Please note that disabling or deleting strictly necessary cookies or browser storage may cause parts of ooverlap's website or invite pages to stop working properly.

8. Changes to this Cookie Policy

ooverlap may update this Cookie Policy from time to time to reflect changes in legal requirements, technical implementations, or service providers. The updated version will be posted on this page with a revised "Last Updated" date.

9. Contact

If you have questions about this Cookie Policy, you can contact ooverlap at:

contact@ooverlap.app

Website: ooverlap.app

Cookie Policy · ooverlap