Cookie and browser storage policy

Updated: · Version: 2026-09-25-v2

Türkçe sürüm ↗

Service provider

DOĞA PET GROOMING · PatiPilot

Provider and contact details ↗

Scope

This policy explains cookies, localStorage and sessionStorage on patipilot.com and kuafor.patipilot.com. Analytics and marketing choices are separate and initially off; continuing to browse does not enable them.

Salon application sessions and preferences

kuafor.patipilot.com stores Supabase authentication-session information in localStorage to keep you signed in; validity and refresh follow the authentication service’s session rules. The language preference uses patipilot_language_v1 without an automatic expiry. Interface preferences or dismissed-announcement information may also remain in the browser. These do not grant marketing consent. Sign out after using a shared device; clearing site data may remove sessions and preferences. Session persistence is disabled for the separate anonymous client used by the public booking form.

Application demonstrations and attribution records

In demo mode, sample customer, appointment, price and interface records may be stored in the browser until site data is cleared or the demo is reset. Demo profile, temporary access and page-recovery records are scoped to the tab/session. When an attribution context created with website permission is passed to the application, it is held under the patipilot_growth_context_v1 sessionStorage key; the client applies a maximum 30-day validity and removes it after successful account attribution or invalidation. This is not the deletion period for all server records.

Necessary preferences

pp-consent stores analytics/marketing choices in your browser’s localStorage; the application does not set an automatic expiry, so it may remain until browser data is cleared or the preference is changed. The pp-language cookie stores your explicitly selected language for up to one year. These records do not independently grant analytics or marketing permission.

Optional analytics and duration

With analytics permission, limited campaign/referral-source data and supported page views may be measured. pp-context and pp-context-expiry sessionStorage records hold an attribution context with a validity period returned by the server; it is not used after the browser session ends or the context expires. Before permission, an incoming referral token is held temporarily in memory rather than browser storage. With permission, the context may be passed to a signup link; these records are not claimed to be anonymous.

Form security and source information

The enquiry form uses Cloudflare Turnstile to verify against automated abuse and may transmit necessary technical information to that provider. The form cannot be submitted without valid verification; email contact is available. Limited source/campaign information accompanying the form may be included in its enquiry record even when analytics is off, to assess that enquiry.

Marketing and changing choices

Advertising tools, Meta Pixel and Google Analytics are not currently active. The marketing choice is separate from analytics and from optional product emails on the enquiry form. Use Cookie preferences to change your choices or select Essential only. Turning analytics off clears the local attribution context and requests revocation of an existing server context; this does not mean every earlier server record is immediately deleted.

Browser settings and providers

You can clear cookies and stored data through browser settings; language and preference choices may then be requested again. Hosting and security providers may process their own technical records internationally. See the Privacy notice and relevant EU/EEA, UK or Türkiye notice for processing, recipients, retention and request channels.

EU/EEA: ePrivacy and GDPR

In the EU/EEA, storing information on or accessing information from a device is governed by Article 5(3) of the ePrivacy Directive and national implementing rules, alongside the GDPR where personal data is involved. The rules can cover localStorage and similar tools, not only items named cookies. Prior consent is required unless a valid exception applies, such as transmission of a communication or a strictly necessary technical function for a service expressly requested by the user. PatiPilot keeps optional analytics and marketing off initially. Refusing them does not prevent you from asking about the service; email contact is also available.

United Kingdom: PECR and ICO guidance

In the UK, PECR regulation 6 and Schedule A1 apply, together with the UK GDPR where personal data is involved. The ICO is the regulator explaining these rules. Its updated 2026 guidance includes narrowly conditioned exceptions for statistical purposes and appearance preferences as well as necessary communication/service functions. These do not permit all analytics or advertising tracking without consent; some require clear information and a simple, free way to object. PatiPilot does not use these narrow exceptions to enable optional analytics or marketing automatically. Select Essential only or withdraw permission through Cookie preferences.

Contact

Support, privacy and legal requests: support@patipilot.com.

ICO guidance on cookies and similar technologies ↗