Cookie policy
Last updated 19 August 2026
There is no tracking inside Twirl. Dashboards and event pages use a handful of cookies that make login and uploads work, and nothing else. Our email carries no open tracking. We measure basic traffic on our public pages only.
Na tej stronie
02Two different places, two different answers
It is worth separating these, because most cookie policies blur them and the distinction is the whole point here.
| Where you are | What runs there |
|---|---|
| The public marketing site: the homepage, pricing, comparison pages, blog, about | Basic traffic measurement, described in section 4. Plus strictly necessary cookies if you sign up or log in from these pages. |
| Inside the product: organizer dashboards, guest event pages, upload and RSVP flows | Strictly necessary cookies only. No analytics, no measurement, no tracking of any kind. We do not want to know how long someone lingered over a photograph of their own wedding. |
| Our email | Delivery and bounce reporting only. Open tracking and click tracking are off. |
03What is actually set
3.1Strictly necessary
Required for the service to work at all. Under Article 5(3) of the ePrivacy Directive, as implemented in Dutch law through the Telecommunicatiewet, these are exempt from the consent requirement because they are strictly necessary to provide a service you explicitly asked for. You cannot turn them off and still use Twirl.
| Name or type | Set by | Purpose | Duration |
|---|---|---|---|
| sb-access-token | Supabase (first party) | Keeps an organizer logged in | 1 hour, renewed automatically while you are using Twirl |
| sb-refresh-token | Supabase (first party) | Renews the login session without forcing a fresh password entry | 30 days |
| Event access session | Twirl (first party) | Records that the correct event password was entered, so a guest is not asked for it on every page | 30 days, or until the event window ends, whichever comes first |
| CSRF token | Twirl (first party) | Protects forms against cross-site request forgery | Session |
| Upload state (local storage) | Twirl (first party) | Tracks in-progress uploads so a large upload survives a page refresh | Cleared on completion |
| Display preferences (local storage) | Twirl (first party) | Remembers interface preferences such as date format and light or dark mode | Until cleared by you |
| __stripe_mid | Stripe (third party) | Fraud prevention and payment security on checkout pages | 1 year |
| __stripe_sid | Stripe (third party) | Fraud prevention within a single checkout session | 30 minutes |
3.2Analytics on the marketing site
See section 4. The specific tool, what it stores, and whether consent is required are set out there rather than here, because the answer depends on the tool and we would rather state it once and properly.
3.3Never used
- Advertising, remarketing and social media pixels.
- Cross-site behavioural profiling.
- Sentry Session Replay, which would record screen content including event media. It is off and we have no plan to enable it.
- Any analytics inside the product.
- Email open tracking and click tracking.
04Analytics on the marketing site
4.1What we are trying to learn
How many people visit, which pages they read, and roughly where they came from. That is it. We are not building profiles, we are not following anyone across the web, and we are not interested in identifying individual visitors.
4.2The tool
We use [TOOL], hosted in the EU.
It sets no cookies. It writes nothing to your device, not a cookie and not a local storage entry. It does not identify you, does not build a profile, and does not follow you to other websites. The numbers it produces are aggregate counts, not records about individuals.
That is why you have not been shown a consent banner. Consent under Article 5(3) of the ePrivacy Directive is required for storing or reading information on your device, and this tool does neither. We would rather choose a tool that does not need a banner than build a banner.
4.3What analytics never covers
Whichever branch applies, analytics runs on public marketing pages only. It does not run in organizer dashboards, on guest event pages, or in upload and RSVP flows. What happens inside your event is not measured by us.
05Email
We send transactional and lifecycle email through Brevo from hello@twirl.photos, using mail.twirl.photos as the tracking subdomain.
We have turned open tracking and click tracking off. Brevo is capable of embedding an invisible image that reports when a message is opened, and of rewriting links to report clicks. We have disabled both. We do not know whether you read our email.
What we do keep is delivery and bounce reporting, meaning whether the message reached your mail server or was rejected. That is not optional for us: if a deletion warning bounces, we need to know, because someone is about to lose their photographs without ever having been told.
This is a deliberate choice rather than a technical limitation. Reading and writing information on a device through a tracking pixel falls under the same rule as cookies, even though no cookie is involved, and the argument that open tracking is strictly necessary to deliver a payment receipt is weak. Rather than construct that argument, we turned it off.
06Consent
6.1The current position
Everything in section 3.1 is strictly necessary and exempt from consent. Whether a banner appears at all depends on the analytics decision in section 4.2. This page, linked in the site footer, satisfies the transparency obligation that applies either way.
6.2What would make a banner mandatory
- An analytics tool that stores or reads anything on the device, including a cookieless tool using local storage.
- Any advertising, remarketing or social media pixel.
- Sentry Session Replay, or any comparable recording feature.
- Stripe's script loading site-wide rather than only on checkout pages.
- Any A/B testing or personalisation tool.
6.3What the mechanism would need to look like
Minimum requirements under the GDPR and ePrivacy rules, as consistently interpreted by the EDPB and the Autoriteit Persoonsgegevens. Written down now so the requirement is not discovered late.
- Prior. Nothing non-essential is set before you act. No pre-loading of scripts "pending consent".
- Opt-in, not opt-out. No pre-ticked boxes. Continuing to scroll is not consent.
- Reject is as easy as accept. Both options on the first layer, equally prominent, with equal visual weight. No greyed out reject button, no extra click to refuse.
- Granular. Separate consent per purpose. One toggle covering everything is not valid.
- Withdrawable. A persistent way to change your mind later, at least as easy as giving consent. Usually a footer link.
- Documented. A record of what was consented to, when, and against which version of this policy.
- No cookie wall. Access to the site cannot be conditioned on accepting non-essential cookies.
07Managing cookies yourself
You can block or delete cookies in your browser settings. If you block the strictly necessary ones in section 3.1, organizer login will not work and guest event access will ask for the event password repeatedly. Nothing else on the site depends on them.
08Changes
This page is updated whenever what we use changes. The date at the top reflects the last change. Any change that introduces something requiring consent will be accompanied by a consent mechanism appearing before that thing is set, not after.
09Contact
Questions about this policy: privacy@twirl.photos.
Ciceroni VOF, KVK 76619176, Franklinstraat 161, 2562 CD Den Haag, the Netherlands.
