Cookies Policy
This Cookies Policy explains how United Vows LLC ("United Vows," "we," "us") uses cookies and similar technologies on our website and platform. It supplements our Privacy Policy at unitedvows.com/privacy. By using United Vows, you agree to the use of cookies as described in this policy, subject to your right to opt out of non-essential cookies as described below.
1. What are cookies?
Cookies are small text files placed on your device when you visit a website. They are used to store information about your interactions with a site, for example, whether you're logged in, what language you prefer, or which pages you've visited. Cookies are commonly categorized as "first-party" (set by the website you're visiting) or "third-party" (set by services embedded in the site, such as analytics or payment processors).
This policy also covers similar technologies: local storage, session storage, and pixel tags. These work similarly to cookies but use different mechanisms.
2. Categories of cookies we use
2.1 Strictly necessary cookies
These cookies are required for the platform to function. They cannot be disabled because the platform would not work without them. Examples include:
- Authentication / session cookies (authjs.session-token, its __Secure- prefixed form and its split-chunk variants, up to 30 days): keep you logged in across pages.
- Security cookies: CSRF protection, rate-limit enforcement, fraud-prevention signals.
- Load-balancing cookies: route your request to the correct server.
- uv-cookie-decision and uv-cookie-prefs (first-party, 1 year): record that you answered the cookie banner and which categories you allowed. They are how your answer survives the next page load, so they are set whatever you choose β including when you refuse everything optional.
- uv-gpc (first-party, 1 year): records that your browser sent a Global Privacy Control signal, so we keep honoring it after you navigate away from the page it arrived on.
- uv_opt_out (first-party, 2 years): records that you used the privacy preferences page to opt out of the sale or sharing of your personal information. Kept for two years so we can show the opt-out was honored.
- NEXT_LOCALE (first-party, 1 year): the language you picked with the language switcher. It is set only when you change the language yourself and holds nothing but the language code; without it the interface resets to English on the next page.
- uv_app (first-party, 1 year): set only if you opened United Vows through our app shell rather than an ordinary browser tab. It records that one fact so the layout stays right on later visits (iPad desktop mode erases the signal we would otherwise read from the browser itself). It holds a single yes value, identifies nobody, and is never used for analytics.
- uv_favor_code (first-party, 14 days): set only when you scan or open a wedding guest-favor QR code. It carries that code through sign-up so the couple who shared it is credited even if you sign up with Google instead of the on-page form β the code is otherwise lost the moment that flow leaves our site. It holds no identifier besides the code itself. Once the code has been redeemed nothing reads it again, and the cookie expires on its own 14 days after it was set; we do not delete it earlier than that.
2.2 Functional cookies
These cookies would remember preferences and choices beyond what the platform needs in order to run β a theme, a saved dashboard layout, recently viewed vendors.
We do not currently set any functional cookies. The one preference stored on your device, the language you choose with the language switcher, is listed under strictly necessary above: we set it only at your own request, and the interface cannot honor your choice on the next page without it. The Functional toggle in our cookie banner and preference centre therefore governs an empty category today. We keep the toggle so your answer is already on record if that changes, and we would update this policy before setting anything under it. Other preferences β a dashboard layout, an onboarding step you have finished β are stored in your account or in your browser's local storage, not in a cookie.
2.3 Analytics cookies
These cookies help us understand how users interact with the platform so we can improve it. We use:
- PostHog: aggregated product analytics (page views, feature usage, click paths).
- Sentry: error monitoring (when an error occurs, certain context is captured to help us debug).
- uv_first_touch (first-party, 90 days): records the link, search, or campaign that brought you to United Vows, plus the page you landed on and when. This lets us tell which of our own pages and posts actually reach couples and vendors. It holds no identifier and no fingerprint, it is never shared with an advertising network, and it is set only once you have accepted analytics cookies.
- uv_last_touch (first-party, 90 days): records the most recent campaign link you followed to United Vows, so a return visit through one of our own emails or posts is not attributed to the very first link you ever clicked. Same contents and same rules as uv_first_touch: no identifier, no fingerprint, never shared with an advertising network, and set only once you have accepted analytics cookies.
- uv_vendor_referrer (first-party, 12 months): set when you follow another vendor's personal invite link to United Vows, so that if you finish setting up your own vendor listing β even in a later visit β the vendor who invited you is credited for the referral. It is never set on an invite link pointed at the couple's signup flow, it is deleted once the referral is recorded, and it is set only once you have accepted analytics cookies. Declining analytics cookies (or a Do Not Track / Global Privacy Control signal) means we cannot connect a signup that happens after you leave and come back to the invite you followed; the "you were invited by ___" banner shown on your arrival still works either way, since that is resolved from the link itself, not from this cookie. If you accept analytics on the page the invite link brings you to, we set it then; if you later switch analytics off in the preference centre, we delete it.
Analytics cookies are set only after you have consented through the cookie banner, except where your browser is sending a Do Not Track (DNT) or Global Privacy Control (GPC) signal, in which case we treat the signal as a refusal of consent and do not set these cookies.
2.4 Marketing cookies
We do not currently use marketing or advertising cookies. We do not share personal information with third parties for cross-context behavioral advertising. If this changes, we will update this policy and request your consent before enabling such cookies.
3. Third-party cookies set by integrated services
Some pages and features set cookies on behalf of third-party services:
- Stripe: when you make a payment, Stripe sets cookies for fraud prevention and PCI compliance. See Stripe's cookies policy at stripe.com/cookies-policy.
- OAuth providers (Google, Microsoft): when you sign in via OAuth, the provider may set cookies for the authentication flow.
These cookies are governed by the third party's own cookies policy.
4. Cookie lifespans
- Session cookies are deleted when you close your browser.
- Persistent cookies remain on your device for the period specified by the cookie issuer. Most United Vows persistent cookies expire within 1 year; security and authentication cookies may have shorter lifespans (15 minutes to 30 days depending on context).
5. Managing your cookie preferences
On the platform: when you first visit United Vows, you will be presented with a cookie banner allowing you to accept or refuse non-essential cookies. You can change your preferences at any time by visiting the cookie preference center linked from the footer of every page.
Browser settings: most browsers allow you to refuse cookies, delete cookies after each session, or notify you before a cookie is set. Browser settings are typically found in "Privacy" or "Security" preferences. Blocking strictly necessary cookies will prevent the platform from working.
Do Not Track / Global Privacy Control: we honor DNT and GPC browser signals as refusals of consent for non-essential cookies. If your browser sends either signal, we treat it as opt-out.
6. Specific categories of users
California users: under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), you have the right to opt out of "sharing" of personal information for cross-context behavioral advertising. United Vows does not currently engage in such sharing. To confirm or to make a deletion request, email privacy@unitedvows.com.
EU/EEA/UK users: under the ePrivacy Directive and GDPR, we will set non-essential cookies only with your explicit prior consent. The cookie banner you see at first visit captures that consent on a per-category basis. You can withdraw consent at any time through the cookie preference center.
7. Changes to this policy
We may update this Cookies Policy occasionally to reflect changes in the cookies we use, the law, or our practices. Material changes will be communicated through the cookie banner upon your next visit after the change.
8. Contact
Privacy and cookies questions: privacy@unitedvows.com.