Last updated: 28 September 2026
Cookie Policy — tindra.gallery
- Applies to:
- tindra.gallery, including host pages, guest event pages (tindra.gallery/e/…), the photo-book and print flows.
- Controller:
- ReadyLive Technologies, Copenhagen, Denmark (CVR 35622594) — support@tindra.gallery
This policy explains what cookies and similar technologies Tindra uses, why, and how you control them. It supplements our Privacy Policy (/privacy).
1. What we mean by “cookies”
“Cookies” here covers small text files placed on your device by a website, and similar technologies that store or read information on your device: browser storage (localStorage and sessionStorage) and tags loaded from third parties. EU ePrivacy rules and North American privacy laws treat these alike, so we do too.
We group them into three categories:
- Strictly necessary — needed for Tindra to work. No consent is required; you cannot switch them off, but you can delete them.
- Functional / preferences — remember choices you make (language, clock format, editor settings, tips you dismissed). Set only because of something you did, and never shared.
- Advertising and measurement — set by Google so we can see whether our Google Ads lead to events being created. Off by default in the EU/EEA, UK and Switzerland until you accept.
Tindra sets no first-party cookies of its own; everything we store is browser storage. We do not use analytics cookies, social-media pixels, chat widgets or any other tracking.
2. Strictly necessary
| Name | Type | Set by | Purpose | Lifetime |
|---|---|---|---|---|
sb-…-auth-token | localStorage | Supabase (our hosting/database provider, EU) | Keeps a host signed in. | Until sign-out |
tindra.consent | localStorage | Tindra | Remembers your cookie choice and the version of this notice you saw. | 12 months (we ask again after that) |
tindra.analytics.optout | localStorage | Tindra | If present, the Google Ads tag is never loaded — set when you use “Do Not Sell or Share” or your browser sends a Global Privacy Control signal. | Until cleared |
tindra.lang | localStorage | Tindra | The language you chose for the site. | Until cleared |
tindra.guest.device | localStorage | Tindra | A random identifier created on a guest’s device so the guest can see, edit and delete their own uploads to an event. It is not linked to a name unless the guest enters one. | Until cleared |
tindra.guest.name | localStorage | Tindra | The display name a guest typed, so they do not have to type it again. | Until cleared |
tindra.mine.<event> | localStorage | Tindra | Which uploads on an event belong to this guest’s device. | Until cleared |
tindra:invite:<event> | localStorage | Tindra | A guest’s invitation/RSVP token, so the invitation page keeps working after a refresh. | Until cleared |
tindra:wizard-basket:…, wizard draft (per host) | localStorage | Tindra | Your unfinished event set-up and basket, so nothing is lost if you close the tab. | Until the event is saved, the basket is emptied, or you sign out |
tindra.book.backup:<book> | localStorage | Tindra | A local safety copy of your photo-book edits. | Until cleared |
tindra.artwork.consent | sessionStorage | Tindra | Records that you confirmed you have the rights to an artwork you uploaded. | Until tab closes |
tindra.conv.<event> | localStorage | Tindra | Ensures an event activation is reported to Google at most once (only matters if you accepted advertising cookies). | Until cleared |
3. Functional / preferences
Stored in your browser’s localStorage, read only by Tindra on your own device, never transmitted to us or anyone else.
| Name | Purpose | Lifetime |
|---|---|---|
tindra.clock | 12- or 24-hour clock | Until cleared |
tindra:studio-bg, tindra.book.canvasBg:<host> | Background colour behind the designer canvas | Until cleared |
tindra.editor.hint.<host>, tindra.book.welcome:<host>, tindra.book.drag-hint, tindra-designer-laptop-recommendation-dismissed | Tips and welcome messages you have already seen | Until cleared |
tindra.library.recent | Recently used artwork in the designer | Until cleared |
Activation celebration, tindra:delivered:<order>, tindra:parcel-dismissed | Notices and celebrations you have already seen or dismissed | Until cleared |
tindra.wall.view | Photo-wall display settings on a big screen (spacing, background, scrolling, whether names are shown) | Until cleared |
4. Advertising and measurement (Google Ads)
We advertise on Google Search. To know whether those ads work, we use the Google Ads tag (Google Ireland Ltd for EEA/UK/CH users; Google LLC, USA, elsewhere).
What it does when you accept: Google sets cookies on tindra.gallery (for example _gcl_au and _gcl_aw, roughly 90 days) that let it recognise that you arrived via one of our ads and later activated an event. We also send Google a one-way hashed version of your email address at that moment (“enhanced conversions”) so it can match the activation to the ad click more reliably. Google may also use this data to improve ad targeting across its network. Full details: policies.google.com/technologies/ads.
What it does if you decline, or before you choose: the tag runs in “consent denied” mode. It sets no cookies and stores nothing on your device. Google may receive a cookieless, non-identifying ping that a page was viewed, used only for aggregate modelling. If your browser sends a Global Privacy Control (GPC) signal, or you use the “Do Not Sell or Share” link, the tag is not loaded at all.
Where it runs: the public website, host pages and the photo-book/print flows. It is never loaded on guest event pages (tindra.gallery/e/…). Guests of an event are never tracked by Google, and guests are never shown a cookie banner.
The legal basis in the EU/EEA/UK is your consent (ePrivacy Directive art. 5(3) as implemented locally, and GDPR art. 6(1)(a)). You can withdraw it at any time — see section 7.
5. Other third parties that receive your IP address
These services set no cookies and store nothing on your device, but your browser contacts them directly, which discloses your IP address and basic browser information:
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — delivers the typefaces used on the site and in card designs. Google states it does not use these requests for profiling. We are working towards self-hosting the fonts to remove this transfer.
- Google Identity Services (accounts.google.com) — loaded only if a host clicks “Import from Google Contacts”. Google may set its own cookies on google.com during that sign-in, under Google’s cookie policy. Nothing is loaded unless you use the feature.
- Supabase (EU region, Frankfurt) — our application backend, including photo storage. It is a processor acting on our instructions, not an independent third party.
When you pay for an event, extension, photo book, printed invitations or QR cards you are redirected to Stripe’s checkout pages. Any cookies there are set on Stripe’s own domain under Stripe’s cookie policy (stripe.com/cookies-policy/legal). Printing is fulfilled by Gelato, which is contacted only by our servers, never by your browser.
6. International transfers
Google may process data in the United States. For EEA/UK/Swiss users this relies on the EU–US Data Privacy Framework (Google LLC is certified) and, as a fallback, Standard Contractual Clauses. Supabase data, including photos, stays in the EU.
7. Your choices
- Cookie banner — on your first visit from the EU/EEA, UK or Switzerland you are asked to accept or decline advertising cookies. Nothing non-essential is set until you choose.
- Cookie settings — the “Cookie settings” link in the footer reopens the banner so you can change or withdraw your choice at any time. Withdrawal takes effect immediately; cookies already set by Google are deleted on your next page load where technically possible, and otherwise expire on their own.
- Do Not Sell or Share My Personal Information (US) — Google Ads cookies may count as a “sale” or “sharing” under Californian and similar US state laws. Use the “Do Not Sell or Share” link in the footer, or turn on Global Privacy Control in your browser; we honour both and switch the tag off. We do not knowingly sell or share personal information of anyone under 16.
- Guests — nothing on a guest page needs consent. A guest can remove their device identifier and name by clearing site data for tindra.gallery in their browser; uploads can be deleted from the event page itself.
- Browser controls — you can block or delete cookies and site data in your browser settings. Blocking strictly necessary storage will sign hosts out and stop guests from managing their own uploads.
- Google opt-outs — adssettings.google.com and tools.google.com/dlpage/gaoptout.
8. Retention
Storage entries live for the periods in the tables above. The consent record (tindra.consent) is kept so we can prove what you agreed to, and we re-ask after 12 months or whenever this notice materially changes. Conversion data held by Google is subject to Google’s retention (typically up to 26 months for ads data).
9. Changes to this policy
We will update this page when we add or remove a cookie or service and change the “last updated” date. If a change introduces new non-essential cookies, the banner will ask for your consent again.
10. Contact
ReadyLive Technologies, Copenhagen, Denmark — support@tindra.gallery. EU/EEA residents can also complain to Datatilsynet (datatilsynet.dk) or their local supervisory authority.