Cookie Policy
Last updated: 2026-07-10
Effective: 22 July 2026.
1. Scope
This Cookie Policy describes cookies and equivalent browser storage used by
Remény Farm Kft. on chirpcoop.com and tyuk.remeny.farm. The hosts provide
the same capabilities; host selection changes language and brand, not feature
availability. See the Privacy Policy for the wider processing notice.
The Policy covers cookies, localStorage, sessionStorage, and scripts that
access a device. It reflects the GDPR, the ePrivacy Directive, and section
155(4) of Act C of 2003 on Electronic Communications. It describes shipped
behavior and is not a statement that a particular legal basis will apply in
every jurisdiction.
2. Current first-party storage inventory
| Item | Storage and purpose | Retention | Category |
|---|---|---|---|
| chirp-consent-v1 | localStorage; records separate analytics and marketing choices, version, and update time so the Service can honor them. | Until changed, browser storage is cleared, or the format is replaced. | Strictly necessary preference |
| sb-<project-ref>-auth-token | Supabase localStorage; access and refresh tokens maintain a requested signed-in or anonymous session. | Session lifetime, until sign-out, token expiry/revocation, or browser-storage deletion. | Strictly necessary |
| chirpcoop.pendingMailerLiteEmailSync | localStorage; a 24-hour, versioned marker used after an account-email change to queue the confirmed address for MailerLite sync. It contains the opaque account ID, SHA-256 digests of the old and target normalized addresses, and expiry; it contains no plaintext email. | At most 24 hours; cleared on invalid data, mismatch, sign-out, or successful queueing. | Strictly necessary account operation |
| chirp_ephemeral:<path>:<name> | sessionStorage; temporarily retains a checkout bearer value (session_id or gift code) after removing it from the visible URL so the return/redemption flow can finish safely. | Usable for at most 6 hours; removed when consumed or cleared, when an invalid/expired value is read, or when the tab session ends. | Strictly necessary checkout/redemption operation |
| chirp_pick_token | sessionStorage; opaque server-issued token proving the current anonymous hen reservations. | Until checkout/abandonment clears the pick session or the tab session ends. | Strictly necessary checkout operation |
| chirp_pick_draft | sessionStorage; selected quantity, candidate display data, and reservation expiry used to restore the direct-pick checkout after a refresh. Server reservations remain authoritative. | Until checkout/abandonment clears the draft or the tab session ends. | Strictly necessary checkout operation |
| chirp-referral-discount | localStorage; the referral handle from a referral link and its capture time, sent with checkout so the promised buyer discount can be applied and the capped referrer reward can be fulfilled server-side. | 30 days from capture; also removed when invalid or expired. Not removed when marketing consent is withdrawn. | Strictly necessary checkout operation |
| chirpcoop.reelSound | localStorage; records the visitor's on/off preference for checkout-reel sound. | Until changed or browser storage is deleted. | Strictly necessary interface preference |
| chirpcoop.discordBannerDismissed | localStorage; value 1 remembers that a signed-in Patron dismissed the Discord community prompt. | Until browser storage is deleted. | Strictly necessary interface preference |
| chirp-referral | localStorage; consented last-touch referral handle and utm_source, utm_medium, and utm_campaign, plus capture time, for checkout attribution. | 30 days from capture; also removed when invalid, expired, or marketing consent is withdrawn. | Marketing |
| chirp_checkout_attempt:<kind> | sessionStorage; random attempt ID links a consented gift or RealChirp checkout sequence. | Current browser-tab session; removed on marketing withdrawal. | Marketing |
| ty_sales_visit_logged | sessionStorage; with marketing consent, prevents the first-party sales-visit counter from being incremented repeatedly in one tab session. | Current browser-tab session; removed when marketing consent is withdrawn. | Marketing |
Framework or security providers may use short-lived operational state where it
is strictly necessary to deliver a request securely. The hosted Cloudflare
Turnstile token itself is memory-only: it is not written to cookies,
localStorage, sessionStorage, URLs, analytics, logs, or rendered HTML and is
passed only to Supabase Auth.
3. Optional measurement and processors
No optional measurement script or event is enabled before the relevant stored consent is present. Missing, invalid, blocked, or unwritable consent storage is treated as refusal. Authenticated, admin, account, redemption, game-bootstrap, and other sensitive routes and auth-secret URL fragments remain browser- telemetry-free regardless of choice.
| Category | Processor / technology | Data and purpose | Browser storage / retention |
|---|---|---|---|
| Analytics | Vercel Analytics and Speed Insights (Vercel Inc.) | Consented public-page use and performance measurements. The provider necessarily receives the request and measurement context needed to deliver these services. | The Service does not create a Vercel storage item. Provider-side data follows the configured Vercel retention and contract. |
| Analytics | PostHog Inc., through same-origin /ingest | Profileless public sales/funnel events under an ephemeral in-memory random ID. Allowed fields are limited to: event name; host, path, locale, surface, placement, target, section/FAQ/calculator values; checkout attempt, quantity, duration, provider, status/error; order ID, currency and value; picker counts; referral handle and UTM values; and share moment/channel. GeoIP processing and person profiles are disabled. | No PostHog cookie or durable PostHog ID. The random ID lasts only for the loaded document. Provider-side events follow the configured project retention. |
| Analytics + marketing | Google Tag Manager container with Google Analytics 4 and Google Ads conversion measurement (Google LLC) | The container loads on eligible public pages only after both stored choices are granted. GA4 measures consented public-page activity; GA4 and Google Ads receive the consented RealChirp begin_checkout event with total value, currency, quantity, and stable item ID/name/category and unit price. It contains no email, order ID, payment-session token, or referral value. | Depending on the enabled tag and granted state, Google tags may create first-party _ga, _ga_*, or _gcl_* cookies/identifiers; their lifetime follows the configured Google property/tag retention. No component of this container loads before both choices. |
| Marketing | First-party referral, sales-visit, and checkout attribution | The fields and markers in § 2 carry consented referral/UTM context to checkout, increment the sales-visit denominator once per tab, and prevent duplicate conversion reporting. | As listed in § 2. |
The Service does not use these tools for behavioural advertising and does not enable PostHog autocapture, session replay, or web person profiles. Separate mobile soft-launch telemetry is memory-only and is described in the Privacy Policy; it is not web cookie storage.
4. Choosing and withdrawing consent
The first eligible public visit presents separate Analytics and
Marketing choices. Rejecting all is equivalent to leaving both off. Google
Tag Manager requires both choices; Vercel measurement and PostHog sales events
require analytics consent; referral and checkout attribution require marketing
consent, as does the first-party once-per-tab sales-visit counter. The
chirp-referral-discount item is functional referral processing, not optional
marketing measurement: it carries only the referral handle needed to perform
the referral offer, and it works independently of these choices. The handle is
sent with checkout so the buyer discount can be applied and the server can
validate and record the conversion, then fulfill the referrer's reward subject
to the monthly anti-abuse cap.
The Cookie settings control in the footer reopens the choices at any time. Withdrawal blocks future sink calls immediately, removes the first-party marketing storage listed above, sends a denied Google consent update when its runtime exists, and reloads the document after revoking an active runtime so installed third-party listeners do not remain. Withdrawal does not affect the lawfulness of processing before withdrawal and does not itself erase data already received by a processor; use the Privacy Policy contact to request access or erasure where applicable.
Blocking all browser storage may prevent authentication and account-email operations from working. Browser controls can also delete stored items at any time.
5. Recipients and international transfers
Optional measurement data is received by the processors named in § 3 and by their contracted subprocessors as necessary to operate the service. Supabase receives authentication data; Cloudflare receives Turnstile security signals and stores/delivers uploaded avatar and real-chicken image objects through R2/CDN under the retention described in the Privacy Policy. Where processing involves a transfer outside the EEA, we rely on the relevant provider's applicable transfer mechanism, such as an EU–US Data Privacy Framework participation or Standard Contractual Clauses, as documented in the provider agreement. See the Privacy Policy for the processor inventory.
6. Contact and complaints
Questions, withdrawal follow-up, and data-subject requests can be sent to the
contact in the Privacy Policy. We respond within the period required
by applicable law. You may also complain to your competent supervisory
authority. In Hungary this is the National Authority for Data Protection and
Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9–11,
naih.hu, ugyfelszolgalat@naih.hu.