Cookie Policy
Last updated: 2026-07-09
1. What this policy covers
This policy explains how Pinkóczi Kornél egyéni vállalkozó (trading as Werklo) ("Werklo", "we") uses cookies and similar technologies (localStorage) on the werklo.net website and the Werklo platform. Webshops operated by our merchants on their own subdomains or domains display their own cookie banner and policy; for those, the merchant is responsible.
The Hungarian version is authoritative; this English text is a courtesy translation.
2. Strictly necessary cookies and storage
These are required for the platform to function and cannot be switched off:
– sb-<project>-auth-token (cookie, domain .werklo.net; may be split into several parts, e.g. sb-<project>-auth-token.0, .1, if the session is large): keeps you signed in to your account and admin panel, set by our authentication provider (Supabase). Lifetime: session / until sign-out.
– werklo-cookie-consent (localStorage, not a cookie): stores your cookie choice so we do not ask again.
– werklo_cart_<shop> (localStorage, not a cookie): remembers the cart you build in a given shop, stored only in your browser — strictly necessary to provide the cart you asked for, whether or not you are signed in.
These are used because they are strictly necessary to provide the service you request (signing in, keeping your cart, remembering your consent choice), so consent is not required for them under the ePrivacy rules. Where the GDPR applies to any personal data involved, the legal basis is the performance of our contract with you (GDPR Art. 6(1)(b)) or our legitimate interest in providing the requested service (Art. 6(1)(f)), depending on the context.
3. Overview of cookies and storage
All cookies and storage used on werklo.net and Werklo-hosted shops at a glance. Google Analytics 4 appears only in merchant shops that enable it, and only after you accept the cookie banner there.
| Name | Provider | Type | Purpose | Lifetime | Domain | Legal basis |
|---|
| sb-<project>-auth-token (may be split into .0, .1, ...) | Werklo (Supabase) | Cookie | Keeps you signed in | Session / until sign-out | .werklo.net | Strictly necessary (contract) |
| werklo-cookie-consent | Werklo | localStorage | Stores your cookie banner choice | Until you delete it | Site you visited | Strictly necessary |
| werklo_cart_<shop> | Werklo | localStorage | Your cart contents in a given shop | Until you delete it | Shop you visited | Strictly necessary (requested service) |
| (none) — Umami analytics | Werklo (self-hosted) | No cookie or storage | Aggregated visit statistics | — | — | Legitimate interest (cookieless) |
| _ga, _ga_<id> | Google (merchant shops only) | Cookie | Google Analytics 4 visitor measurement | Up to 2 years | Merchant shop domain | Consent (banner) |
4. Analytics
On werklo.net and on merchant storefronts we use Umami Analytics, a privacy-friendly, cookieless measurement tool we run on our own server. It does not place any cookie and does not write any persistent identifier to your browser. It identifies unique visitors using a hash of your IP address, hostname and browser user agent, salted with a value that rotates daily — your IP address itself is never stored, only briefly used to compute that hash for the current day. Umami does not build cross-site profiles.
Merchant shops may additionally use Google Analytics 4, but only after you accept the cookie banner shown in that shop — the script is not present on the page at all until you accept, so no data is sent to Google beforehand.
5. Managing cookies
You can delete or block cookies at any time in your browser settings (usually under Privacy or Site data). Blocking the strictly necessary cookies will prevent signing in and using the cart.
The cookie banner shown in merchant shops lets you decline all non-essential cookies as easily as accepting them — declining never affects your ability to browse or buy. To change or withdraw your choice later, use the "Cookie settings" link in that shop’s footer: it reopens the banner so you can choose again.