Cookie Policy
Last Updated: 20th September 2026
1. Introduction
This Cookie Policy explains how Digital Loyalty (“we,” “us,” or “our”) uses cookies and similar technologies when you visit our website at https://digitalloyalty.com or use our services. This policy should be read alongside our Privacy Policy.
Company Information:
- Company Name: Carrott LTD
- Contact Email: hello@digitalloyalty.com
2. What Are Cookies?
Cookies are small text files that are stored on your device (computer, tablet, or mobile) when you visit a website. They help the website remember your preferences and actions over time.
Types of Storage Technologies We Use
- Cookies: Small text files stored by your browser
- Local Storage: Browser storage that persists until cleared
- Session Storage: Browser storage cleared when the browser closes
3. How We Use Cookies
3.1 Essential Cookies (Strictly Necessary)
These cookies are necessary for the website to function and cannot be disabled.
| Cookie/Storage | Purpose | Duration | Provider |
|---|---|---|---|
auth_session | Maintains your authenticated session | Session | Digital Loyalty |
better_auth_* | Authentication state and tokens | Session/30 days | Better Auth |
csrf_token | Prevents cross-site request forgery | Session | Digital Loyalty |
Legal Basis: Legitimate interest (essential for service operation)
3.2 Functional Cookies
These cookies enable enhanced functionality and personalization.
| Cookie/Storage | Purpose | Duration | Provider |
|---|---|---|---|
selectedWorkspace | Remembers your selected workspace | Persistent (localStorage) | Digital Loyalty |
theme | Stores your theme preference | Persistent (localStorage) | Digital Loyalty |
i18next | Stores your language preference | Persistent (localStorage) | Digital Loyalty |
mantine-color-scheme | Stores dark/light mode preference | Persistent (localStorage) | Mantine UI |
Legal Basis: Legitimate interest (user experience) or consent where required
3.3 Third-Party Cookies
Our service integrates with third-party providers who may set their own cookies.
Payment Processing (Stripe)
| Cookie | Purpose | Duration | Provider |
|---|---|---|---|
__stripe_mid | Fraud prevention | 1 year | Stripe |
__stripe_sid | Fraud prevention | 30 minutes | Stripe |
Stripe cookies are used for payment processing and fraud detection. See Stripe’s Cookie Policy.
Customer Support (Featurebase)
Featurebase may set cookies when you interact with our in-app support widget:
| Cookie | Purpose | Duration | Provider |
|---|---|---|---|
fb_* | Session and user identification | Session / Persistent | Featurebase |
Featurebase cookies are used for support functionality and feedback collection. See Featurebase’s Privacy Policy.
Wallet Services
When generating wallet passes, Apple and Google may set cookies on their respective domains:
- Apple Wallet: Cookies on apple.com during pass installation
- Google Wallet: Cookies on google.com during pass saving
These are subject to Apple’s and Google’s respective privacy policies.
3.4 Optional Analytics
With your permission, we use Google Analytics and PostHog to measure visits, page use and conversion events. These services load only after you choose Accept analytics or enable optional analytics in Privacy settings. We disable advertising storage, Google Signals, ad personalisation, automatic PostHog capture and session recording. We do not send names, email addresses or phone numbers to these analytics services.
| Cookie/Storage | Purpose | Duration | Provider |
|---|---|---|---|
_ga, _ga_* | Distinguishes browsers and measures site use after consent | Up to 2 years | Google Analytics |
ph_*_posthog | Stores an anonymous analytics identifier after consent | Up to 180 days | PostHog |
pp-privacy-v2, pp_analytics | Remembers your privacy choice | 180 days | Digital Loyalty |
site-statistics | Remembers whether anonymous server statistics are disabled | 180 days | Digital Loyalty |
You can withdraw consent at any time through Privacy settings in the footer. Withdrawing consent removes optional analytics storage that this site can access and stops further browser analytics collection.
4. Local Storage Usage
We use browser local storage for the following purposes:
| Key | Purpose | Data Stored |
|---|---|---|
selectedWorkspace | Remember your current workspace | Workspace ID |
tanstack-query-* | Cache API responses for performance | Query cache data |
lp-attrib | First-party attribution: remember which campaign or advert brought you to our site so we can measure our own marketing (expires after 90 days; not shared with third parties) | Campaign tags from the link you arrived on (e.g. utm parameters, click ID) |
pp-privacy-v2 | Remembers your optional analytics and anonymous statistics choices | Consent decision and timestamp |
dl-analytics-consent-v1 | Compatibility value used by the site analytics adapter | Granted or denied |
Note: Local storage persists until manually cleared by the user or through browser settings.
5. How to Manage Cookies
5.1 Browser Settings
You can control cookies through your browser settings:
Chrome: Settings > Privacy and security > Cookies and other site data
Firefox: Settings > Privacy & Security > Cookies and Site Data
Safari: Preferences > Privacy > Manage Website Data
Edge: Settings > Cookies and site permissions > Cookies and site data
5.2 Blocking Cookies
If you block cookies:
- Essential features may not work properly
- You may need to log in repeatedly
- Your preferences won’t be saved
- Some payment features may be affected
5.3 Deleting Cookies
You can delete cookies at any time through your browser settings. Note that this will:
- Log you out of the platform
- Reset your preferences
- Clear cached data
5.4 Global Privacy Control
When your browser sends a Global Privacy Control signal, optional analytics and anonymous server statistics are disabled. Browser “Do Not Track” signals are not consistently implemented across browsers; use our Privacy settings to record your choice directly.
6. Cookies and Mobile Apps
If you access our service through a mobile app:
- Mobile apps use device storage instead of cookies
- Session tokens are stored securely in the device keychain
- The same data privacy principles apply
7. Wallet Pass Considerations
When you install a wallet pass:
Apple Wallet:
- Apple receives device registration information
- Push notification tokens are stored
- Pass data is synced via iCloud (if enabled)
Google Wallet:
- Google receives pass data
- Linked to your Google account
- Subject to Google’s privacy policy
These wallet providers operate independently and have their own cookie and privacy policies.
8. Updates to This Policy
We may update this Cookie Policy to reflect changes in:
- Our use of cookies
- Legal requirements
- Third-party integrations
Material changes will be notified through our website.
9. Cookie Consent
9.1 EEA/UK Users
In accordance with GDPR and the ePrivacy Directive:
- Essential cookies are set without consent (strictly necessary)
- Non-essential cookies require consent where applicable
- You can withdraw consent at any time through browser settings
9.2 Other Jurisdictions
We comply with applicable cookie laws in all jurisdictions where we operate.
10. Contact Us
For questions about our use of cookies:
Carrott LTD
- Email: hello@digitalloyalty.com
- Data Protection Officer: hello@digitalloyalty.com
- Address: Piccadilly Business Centre, Blackett Street, Manchester, M12 6AE
This Cookie Policy is effective as of 23rd January 2026.