The service uses cookies and local storage for sign-in, sessions, security, unfinished RSVPs and operational monitoring. Optional public website analytics starts only after consent; this choice does not apply to separate PostHog monitoring.
Browser-based PostHog may initialise as soon as the service loads and store ph_* items in cookies or local storage. It captures restricted error and operational events; signing out does not automatically delete its storage.
After consent, the public website may measure page visits and clicks on main links using a random pseudonymous identifier. It does not process names, contact details or project content for this purpose. Online card payment or the payment portal opens only after a payment or billing action is started.
- Sign-in cookies and user sessions.
- Cookies or similar technologies needed for security and sign-in protection.
- Technical storage needed for correct application function and navigation.
Some screens may load external services only after a specific feature is used. A map service is used for address completion if enabled. Text translation through an external service runs on the server and is not browser analytics.
Payment provider pages may open during an online payment, when payment details are added or when the payment portal is opened. The provider's cookies and local storage are governed by its own documentation.
Guest websites and public RSVP pages may use technical link identifiers or tokens to serve a specific guest group or form response.
Server-side product analytics is intended only to provide a basic understanding of service use. It is disabled by default and does not itself store an analytics cookie in the browser.
Pseudonymous public website analytics starts only after consent in the banner on public pages. It stores a consent record containing the version, the accept or decline choice and the decision timestamp, together with a random pseudonymous visitor identifier.
PostHog is used for error and operational monitoring. Session recording starts after entry into the signed-in application if it is enabled for the relevant environment or workspace; text, inputs and attributes are masked, and console data, request headers and bodies, heatmaps and cross-origin iframes are not recorded. The recording may nevertheless be linked to the internal user ID, name, email and workspace and remains personal data. Google Analytics is used only on the public website after consent and with advertising storage disabled; marketing pixels are not part of the current configuration.
- Essential sign-in cookies are needed for sign-in and the application may not work without them.
- The user can block or delete cookies in browser settings, but this can remove sign-in or break application functionality.
- Optional public website analytics can be declined or changed later in the cookie settings. Declining removes the pseudonymous public analytics identifier, but not separate PostHog items; those can be removed by deleting cookies and site data in the browser.
| Item | Purpose | Duration |
|---|---|---|
| better-auth.session_token or secure variant | HTTP-only account sign-in and session; essential. | Up to 30 days, renewed on a rolling basis while in use, or until sign-out. |
| kruspin.public_web_analytics_consent.v1 | The version, the choice to accept or decline public website analytics, and the decision timestamp in local storage. | Until the stored data is deleted or the consent version changes. |
| kruspin.public_web_analytics_visitor.v1 | Random pseudonymous identifier for consented public website measurement; removed when analytics is declined. | Until consent is withdrawn, the stored data is deleted or the version changes. |
| Google Analytics cookies | Pseudonymous public website measurement only after consent, if Google Analytics is configured. | According to the Google Analytics configuration and the consent granted. |
| ph_* (PostHog cookies and local storage) | Error and operational monitoring and session linking; when recording is enabled, also the interactions within the signed-in application. | According to the PostHog configuration; the SDK cookie may last for up to 365 days. Signing out does not automatically delete these items. |
| Local storage for an unfinished RSVP | An unfinished RSVP form in this browser; it may contain names, children's ages, contact details, answers, the public code and a session identifier. | No automatic expiry; until successful completion of the form or manual deletion of the site's data. |