QR Relay

Cookies & Local Storage

Incomplete policy — not final. Observed storage is documented below. Authenticated/payment browser journeys and the operator information remain incomplete. Reviewed 8 October 2026.

What the candidate application uses

This notice describes the V2.2 source audit, not an assurance that all hosting and third-party settings have been independently verified.

External requests and providers

The application loads Google Fonts, so your browser requests fonts from Google infrastructure. Supabase handles login and realtime connections. Stripe Checkout and the Customer Portal run on Stripe-hosted pages and may use their own security and payment technologies. Read-only visits to both the hosted site and qrrelay.bar observed the Cloudflare __cf_bm bot-protection cookie, with Secure, HttpOnly and SameSite=None attributes. Cloudflare documents a 30-minute inactivity lifetime. This security cookie is set by hosting infrastructure, not the QR Relay application.

No analytics, advertising or marketing tracking is imported by the audited product code. Unused component-library code is not evidence that its optional storage features run on this site.

Not yet confirmed: complete authenticated, recovery and Stripe Checkout/Portal browser journeys to identify any additional provider storage. A response-header audit alone cannot prove the complete browser inventory.

Consent assessment

The inspected app stores authentication state to deliver your requested login and your selected appearance preference. The observed hosting cookie serves bot protection. No optional advertising or analytics storage was found in the application code, so this update does not add a speculative consent banner. A full provider/browser journey audit is still required before concluding that every storage operation is exempt from consent. Any optional non-essential storage found must be blocked until the appropriate choice has been given.

Camera choices, zoom settings and diagnostic details are held in memory for the current page; the app does not persist or upload camera frames. No application sessionStorage use was found. Local storage has no built-in expiry: authentication data is refreshed or cleared by the auth client and appearance remains until changed or cleared. Browser-managed HTTP caches have their own controls.

Your controls

Change Appearance at any time using the page control. Log out before using a shared device. Browser settings let you clear site data or revoke camera permission; clearing site data may sign you out and reset preferences, but it does not delete your server account or cancel a subscription.

Technologies strictly necessary for a service you explicitly request can be exempt from prior cookie consent; other storage/access technologies normally require consent. If optional tracking is introduced, it must be assessed and an appropriate choice provided before activation. This update adds no marketing consent or tracking system. See the Privacy Policy for personal-data processing.