Skip to content

Cookie notice

Only what the service needs.

We currently use necessary cookies to keep accounts, private Wedding sites, and RSVP replies working securely. We do not use advertising cookies or optional marketing analytics.

Current setting
Necessary cookies only
Effective
September 4, 2026

Our current approach

Cookies are small pieces of information a website asks your browser to remember. Similar browser storage can serve the same purpose. We use these technologies only when needed to provide a feature someone requests, keep an account or RSVP secure, or prevent abuse.

We do not currently use advertising cookies, behavioral tracking, or optional marketing analytics. That is why we do not show a consent banner today. You do not need to accept marketing tracking to browse a Design or use the service.

First-party cookie inventory

These cookies are set on a The Cordially Invited page only when the corresponding feature is used.

Cookie
Supabase authentication cookies
Used for
Couples and collaborators
Purpose
Keep a signed-in account authenticated and refresh its secure session.
Duration
Until sign-out or the configured Supabase session expires.
Cookie
front_door_aha
Used for
People keeping a Design Fitting
Purpose
Carry requested Design, names, date, place, and purchase choice through the magic-link sign-in flow.
Duration
Up to 1 hour, then removed after successful setup.
Cookie
sg_<Wedding address>
Used for
Visitors to a password-protected Wedding
Purpose
Remember that the correct site password was entered for that Wedding.
Duration
Up to 30 days or until the site password changes.
Cookie
rsvp_session_<Wedding address>
Used for
Guests actively completing an RSVP
Purpose
Maintain a secure, Wedding-scoped RSVP session while a reply is completed.
Duration
Up to 2 hours.
Cookie
rsvp_revisit_<Wedding address>
Used for
Guests returning to an RSVP
Purpose
Allow a Guest to return and update an accepted response without another name search.
Duration
Up to 180 days, unless revoked or cleared sooner.

Dynamic cookie names include a project or Wedding identifier so one session cannot be confused with another. Authentication cookies may be split into multiple browser cookies by the authentication provider when required by size limits.

Security and checkout providers

Cloudflare Turnstile runs browser checks on protected forms to distinguish people from automated abuse. Stripe may set cookies and process device information on its hosted checkout and billing pages for payment, fraud prevention, and security. Those providers control their own domains and explain their practices in the Cloudflare Privacy Policy and Stripe Cookie Policy.

Your controls

Your browser lets you inspect, block, or delete cookies. Blocking a strictly necessary cookie can prevent sign-in, setup, site-password access, checkout, or RSVP editing from working. Clearing cookies does not itself delete information already submitted to a couple or stored in an account.

Instructions are available for Chrome, Safari, Firefox, and Edge. See the Privacy Notice for access and deletion choices.

If optional analytics is introduced

We will update this notice before enabling optional analytics or advertising technology. Where consent is required, those tools will remain off until a visitor makes an affirmative choice, refusal will be as easy as acceptance, and the choice can be changed later. Wedding websites, invitations, RSVP flows, Dashboards, previews, and admin pages will remain outside marketing analytics.

Questions about a cookie?

Write to hello@craftedkit.io. Please do not include passwords, payment details, or private RSVP information.