werklo

Cookie Policy

Last updated: 2026-09-27

1. What this policy covers

This policy explains how Pinkóczi Kornél egyéni vállalkozó (trading as Werklo) ("Werklo", "we") uses cookies and similar technologies (localStorage) on the werklo.net website and the Werklo platform, including the merchant admin panel and the storage the platform itself sets in the shops it hosts (all listed in Section 3). Each shop also displays its own cookie banner and policy, and the merchant is responsible for what they add to their shop (for example Google Analytics or the Meta Pixel).

The Hungarian version is authoritative; this English text is a courtesy translation.

2. Strictly necessary cookies and storage

These are required for the platform to function and cannot be switched off:

– sb-<project>-auth-token (cookie, domain .werklo.net; may be split into several parts, e.g. sb-<project>-auth-token.0, .1, if the session is large): keeps you signed in to your account and admin panel, set by our authentication provider (Supabase). Lifetime: until you sign out, at most 400 days.

– werklo-cookie-consent (localStorage, not a cookie): stores your cookie choice so we do not ask again.

– werklo_cart_<shop> (localStorage, not a cookie): remembers the cart you build in a given shop, stored only in your browser. Strictly necessary to provide the cart you asked for, whether or not you are signed in.

These are used because they are strictly necessary to provide the service you request (signing in, keeping your cart, remembering your consent choice), so consent is not required for them under the ePrivacy rules. Where the GDPR applies to any personal data involved, the legal basis is the performance of our contract with you (GDPR Art. 6(1)(b)) or our legitimate interest in providing the requested service (Art. 6(1)(f)), depending on the context.

3. Overview of cookies and storage

All cookies and storage used on werklo.net and Werklo-hosted shops at a glance. Google Analytics 4 and the Meta Pixel appear only in merchant shops that enable them, and only after you accept the matching category in the cookie banner there.

NameProviderTypePurposeLifetimeDomainLegal basis
sb-<project>-auth-token (may be split into .0, .1, ...)Werklo (Supabase)CookieKeeps you signed inUntil sign-out, at most 400 days.werklo.netStrictly necessary (contract)
werklo_customerWerkloCookie (httpOnly)Keeps a buyer signed in to their account in one shop30 days, or until sign-outOnly the shop you signed in toStrictly necessary (requested service)
__stripe_mid, __stripe_sidStripeCookieFraud prevention during card payment, set by Stripe’s payment form at checkout1 year (mid), 30 minutes (sid)Shop you pay inStrictly necessary (payment you requested)
werklo-admin-nav, werklo:theme-preview-draft, werklo:theme-snapshotWerklolocalStorageMerchant admin only: remembers which menu groups you opened, and keeps an unsaved theme draft so a preview matches what you are editingUntil you delete itAdmin panelStrictly necessary (requested service)
werklo-cookie-consentWerklolocalStorageStores your cookie banner choiceUntil you delete itSite you visitedStrictly necessary
werklo_cart_<shop>WerklolocalStorageYour cart contents in a given shopUntil you delete itShop you visitedStrictly necessary (requested service)
werklo-age-verifiedWerklosessionStorageRemembers that you passed the age check in a shop that requires one, so it is not asked again on every pageUntil you close the browser tabShop you visitedStrictly necessary (legal obligation of the shop)
werklo_chat_conversationWerklolocalStorageKeeps your live-chat conversation with the shop open across pagesUntil you delete itShop you visitedStrictly necessary (requested service)
werklo_popup_dismissed_<shop>WerklolocalStorageRemembers that you closed a shop notice, so it is not shown againUntil you delete itShop you visitedStrictly necessary (requested service)
werklo_ga_purchase_<order>WerklosessionStorageMarks that the purchase event has already been counted, so reloading the thank-you page does not count the order twice. Only written in shops using Google Analytics 4, after consentUntil you close the browser tabShop you visitedConsent (banner), measurement
(none), Umami analyticsWerklo (self-hosted)No cookie or storageAggregated visit statistics--Legitimate interest (cookieless)
_ga, _ga_<id>Google (merchant shops only)CookieGoogle Analytics 4 visitor measurementUp to 2 yearsMerchant shop domainConsent (banner)
_fbp, _fbcMeta (merchant shops only)CookieMeta Pixel. Measures sales from the shop's Facebook and Instagram adsUp to 3 monthsMerchant shop domainConsent (banner)

4. Analytics

On werklo.net and on merchant storefronts we use Umami Analytics, a privacy-friendly, cookieless measurement tool we run on our own server. It does not place any cookie and does not write any persistent identifier to your browser. It identifies unique visitors using a hash of your IP address, hostname and browser user agent, salted with a value that rotates daily. Your IP address itself is never stored, only briefly used to compute that hash for the current day. Umami does not build cross-site profiles.

Merchant shops may additionally use Google Analytics 4 or the Meta Pixel, but only after you accept the cookie banner shown in that shop. Neither script is present on the page at all until you accept, so no data is sent to Google or Meta beforehand.

5. Managing cookies

You can delete or block cookies at any time in your browser settings (usually under Privacy or Site data). Blocking the strictly necessary cookies will prevent signing in and using the cart.

The cookie banner shown in merchant shops asks about two things separately, because they are two different things and consent has to be specific to each. "Measurement" covers Google Analytics 4, which counts visits and pages. "Advertising" covers the Meta Pixel, which lets the shop show you its products again on other sites and measure whether an advert led to a sale. You can accept one and refuse the other. Neither script is loaded until you accept that category, and refusing is a single click on a button that looks the same as the accept button.

Declining never affects your ability to browse or buy. To change or withdraw your choice later, use the "Cookie settings" link in that shop’s footer: it clears your stored choice and reopens the banner so you can choose again.

6. Changes and contact

We may update this policy from time to time; the current version is always available at https://www.werklo.net/cookies. Questions: privacy@werklo.net.