Legal
Cookie notice
- Effective
- [Effective date](not yet configured)
- Draft last edited
- Status
- Not in force
DRAFT — pending counsel review
This document is a complete working draft written by the product team. It has not been reviewed by a qualified lawyer, it is not yet in force, and it is published here so it can be reviewed in context. Do not rely on it. Every value marked “not yet configured” is a fact the operator must supply before this page can take effect; they are all listed at the foot of the page.
We use browser storage to sign you in, one entry to remember your appearance, one to remember your cookie choice, and — only with your consent — one to measure usage on our own servers. There is no advertising, no retargeting, no cross-site tracking and no third-party analytics on this site.
Section 1
What this notice covers
This notice explains the cookies and similar technologies — local storage and session storage included — used on this website. It takes effect on [Effective date](not yet configured) and sits alongside the privacy notice, which explains how the resulting personal data is handled.
Section 2
What we do not use
Stated first, because it is the shorter and more useful list:
- no advertising or retargeting cookies;
- no cross-site tracking or data-broker pixels;
- no social-network embeds that set third-party cookies;
- no third-party analytics script of any kind;
- no sign-in cookie: sign-in uses browser storage, described below;
- no fingerprinting used to identify you across sites or to work around a refused consent.
The service is funded by subscriptions, so there is no advertising business to feed with this data.
Section 3
What we do use
Strictly necessary storage is set without consent because the service cannot function without it. The one measurement entry is created only after you allow it. This is the complete list; it is generated from the same source the site’s code reads, and a test fails if the two ever differ.
| Purpose | Name and type | Category | Lifetime |
|---|---|---|---|
| Sign-in access tokenA signed bearer token that proves to our API who you are on each request. Set by our own sign-in page — there is no identity provider and no sign-in cookie. | award-search.session-tokenLocal storage | Strictly necessary | One hour, then replaced; removed when you sign out |
| Sign-in refresh secretLets the site obtain a new access token without asking for your password again. Our server keeps only a one-way hash of it. | award-search.refresh-tokenLocal storage | Strictly necessary | 30 days, rotated on each use; removed when you sign out |
| Developer sign-in tokenNever set by the site. It is read only if a developer placed a token there themselves while working on the product; on a normal visit it does not exist. | award-search.dev-tokenLocal storage | Strictly necessary | Until removed by hand |
| Your checkout, when you returnWhich plan and interval you were paying for when you left for our checkout provider, so the page you return to can confirm that purchase. Contains no card or payment details. | award-search.checkout-intentSession storage | Strictly necessary | Until you close the tab |
| Your cookie choiceRecords whether you allowed or declined usage measurement, and when, so we do not ask again on every visit. Contains that choice and nothing else. Also mirrored in local storage under the same name. | award-consentCookie | Strictly necessary | 12 months |
| Your cookie choice (mirror)The same record as the cookie above, kept so your choice survives a browser that blocks cookies but not site storage. | award-consentLocal storage | Strictly necessary | 12 months |
| AppearanceLight, dark or follow-the-system. Set only once you change the setting. | award-themeLocal storage | Preference | Until you change it |
| Demo sign-out flagExists only when the site runs on fixture data — a demo or development deployment, never the production service. It records that you signed out of the demo so the fixture API keeps answering as a signed-out one. | award-search.mock-signed-outLocal storage | Strictly necessary | Until you sign back into the demo |
| Demo accountsExists only when the site runs on fixture data. It holds the demo accounts you created in this tab so a demo sign-up survives a reload; none of it reaches a server. | award-search.mock-accountsSession storage | Strictly necessary | Until you close the tab |
| Usage-measurement sessionA random identifier for one browsing session, so the steps of one visit can be counted as one funnel. Created only after you allow measurement, never linked to your account, and sent only to our own servers. | award-analytics-sessionSession storage | Measurement | Until you close the tab |
Section 4
Giving and withdrawing consent
Consent is collected by this site’s own banner, shown once at the foot of the page until you answer it. Refusing is as easy as accepting: the two buttons are the same size, there is no pre-ticked box, no “legitimate interest” toggle left on by default, and no repeated prompt after a refusal. Your answer is stored in the consent record listed above and nowhere else.
You can change your choice at any time from the control below, or from the privacy page in your account. Withdrawing consent stops any further measurement immediately and deletes the session identifier; you can also clear it in your browser.
Blocking strictly necessary storage in your browser will prevent you signing in, but the public pages will still work.
Cookie settings
Reading your saved choice…
Measurement means page-load timings and which features are used, sent to our own servers with no account identifier. Changing your choice takes effect immediately; withdrawing it stops any further measurement and deletes the session identifier.
Section 5
Usage measurement, if you allow it
There is no analytics provider. With your consent the site sends two kinds of measurement to our own servers and nobody else’s:
- Page performance — a sampled share of visits report the standard Web Vitals timings (how long the page took to paint and respond), with the page’s section, your device class and nothing that identifies you.
- Feature usage — which steps of the product were reached: a search previewed, a search started, a result opened, an alert created. Each step carries only bucketed context (a plan tier, a cabin, “2–7 days”), never the airports, dates, points or balances you entered, and the server refuses anything outside that list.
We use it to see where searches fail and which features are worth improving, not to build a profile of you. Nothing sent is joined to your account.
Section 6
Questions
Questions about this notice, or about storage you have seen that is not listed here, go to privacy@[domain](not yet configured). If we have missed one, we will either document it or remove it.
Facts the operator must supply before this document takes effect
2 of 2 bracketed values in this document are not yet configured. Each one is a fact, not a missing clause — the wording around it is complete. Each is supplied as the build argument named beside it.
- [Effective date](not yet configured)
- The date this version of the document takes effect. Set it when counsel signs off, not before.
NEXT_PUBLIC_COMPANY_LEGAL_EFFECTIVE_DATE - privacy@[domain](not yet configured)
- Mailbox for data-subject requests: access, correction, deletion, portability and objection.
NEXT_PUBLIC_COMPANY_PRIVACY_EMAIL