Cookie-Richtlinie — Einwilligung & Präferenzen
1. Was Cookies sind und wie wir sie verwenden
Cookies sind kleine Textdateien, die dein Browser speichert, wenn du eine Website besuchst. Sie helfen, Einstellungen zu merken, essentielle Funktionen am Laufen zu halten und—wenn du es erlaubst—Leistung und Kampagnenerfolg zu messen.
Bei 2luv verwenden wir Cookies hauptsächlich, um: (a) deine Einwilligung zu speichern, (b) Funktionen und Sicherheit auf bestimmten Seiten bereitzustellen (z. B. passwortgeschützte Inhalte) und (c) bei entsprechender Zustimmung Nutzung und Conversions zu messen.
2. Verwendete Cookie-Typen und Zweck
Erforderlich: wichtig für Sicherheit und Grundfunktionen (z. B. Einwilligung merken und geschützte Inhalte authentifizieren).
Funktional: verbessert die Nutzung und Navigation (z. B. zuletzt aufgerufene Inhalte merken).
Präferenzen: speichert Auswahlen wie die Sprache.
Analyse: hilft, die Nutzung der Website zu messen und zu verstehen (Statistiken), wenn aktiviert.
Marketing: hilft, Kampagnen und Conversions zu messen, wenn aktiviert.
3. Wie wir deine Einwilligung einholen und wie lange sie gespeichert wird
Wenn du 2luv besuchst, zeigen wir ein Cookie-Banner, damit du akzeptieren, ablehnen oder deine Einstellungen anpassen kannst (z. B. Analyse und Marketing).
Deine Auswahl wird gespeichert, damit wir sie bei zukünftigen Besuchen respektieren können. In der Regel speichern wir den Nachweis bis zu 12 Monate (abhängig von Browser-Einstellungen). In einigen Fällen nutzen wir auch den localStorage des Browsers, um Präferenzen zu speichern.
4. Wie du Cookies ablehnen kannst
Du kannst optionale Cookies direkt im Banner ablehnen, indem du auf Ablehnen klickst oder Kategorien unter Anpassen deaktivierst.
Du kannst Cookies außerdem in den Browser-Einstellungen verwalten (blockieren, löschen oder einschränken). Wenn du Cookies löschst, können einige Einstellungen zurückgesetzt werden.
5. Welche Cookies verwendet werden
Die Liste unten enthält First-Party-Cookies (von 2luv gesetzt) sowie Cookies/Identifier, die von Drittanbietern (Analyse/Ads) gesetzt werden können. Einige Namen und Laufzeiten können je nach Anbieter und Browser variieren.
| Technologie | Kategorie | Verantwortlich | Name | Zweck | Dauer | Domain | Consent mode | Bereinigung |
|---|---|---|---|---|---|---|---|---|
| cookie / localStorage | Erforderlich | 2luv-ui | Speichert deine Einwilligungsentscheidung (einschließlich Consent-Mode-Präferenzen), damit wir deine Auswahl bei zukünftigen Besuchen respektieren können. | 12 Monate | 2luv domain | security_storage | Kept when optional data is rejected; reset when the visitor clears all browser data. | |
| Cookie | Erforderlich | 2luv-ui | Haelt den Dienst in diesem Browser in der richtigen Sprache, im passenden Datumsformat und in der richtigen Leserichtung. | 12 Monate | 2luv domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | Erforderlich | 2luv-ui | Haelt Preise, Waehrung, Planverfuegbarkeit und regionales Routing in diesem Browser konsistent. | 12 Monate | 2luv domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | Präferenzen | 2luv-api | Hilft, das zuletzt in diesem Browser aufgerufene Geschenk/den zuletzt aufgerufenen Brief schnell wieder zu öffnen. | 30 days | 2luv API domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | Erforderlich | 2luv-api | Sicherheits-Cookie (httpOnly) zur Identifizierung des Geräts/Browsers und zum Schutz von Zugriffen und sensiblen Vorgängen. | 12 months | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | Erforderlich | 2luv-api | Kurzfristige HttpOnly-Autorisierung, die an dieses Gerät/diesen Browser gebunden ist, um Ergebnisse von Mein Geschenk finden ohne erneute Verwendung des E-Mail-Codes zu aktualisieren. | Browsersitzung, höchstens 8 Stunden | 2luv-API-Domain | security_storage | Wird über die API durch die vollständige Geräte-/Sitzungsbereinigung gelöscht. | |
| localStorage | Erforderlich | 2luv-ui | Speichert die bestätigte E-Mail für Mein Geschenk finden vorübergehend in diesem Browser, damit Ergebnisse nach Navigation oder Neuladen aktualisiert werden können. | 8 Stunden gültig; ein abgelaufener Eintrag wird beim nächsten Öffnen von Mein Geschenk finden gelöscht | Nur dieser Browser | security_storage | Wird bei Auswahl einer anderen E-Mail, nach Ablauf oder durch die vollständige Geräte-/Sitzungsbereinigung gelöscht. | |
| Cookie | Erforderlich | 2luv-api | Authentifizierungs-Cookie (httpOnly), um den Zugriff auf passwortgeschützte Briefe aufrechtzuerhalten und autorisierte Aktionen im Zusammenhang mit diesem Inhalt zu ermöglichen. | 30 Tage | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | Erforderlich | Hilft, Menschen bei Briefsuche, Kontakt, KI-gestütztem Schreiben, Medien-Upload, Brieferstellung und Briefbearbeitung von automatisiertem Missbrauch zu unterscheiden. | bis zu 6 Monate | not consent-controlled; strictly necessary security | Loaded when the letter editor opens or a protected form is submitted; provider data must be managed through browser or Google settings. | |||
| Cookie | Analyse | Google Analytics: hilft, die Nutzung der Website (aggregierte Statistiken), Performance und Navigation zu verstehen und berücksichtigt dabei den Consent Mode. | bis zu 13 Monate | Google / 2luv domain | analytics_storage | Deleted when optional cookies are rejected where browser access allows it. | ||
| Cookie | Präferenzen | 2luv-api | Compatibility resume cookie name that the current letter API clears when deleting session state. | legacy/session | 2luv API domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | Erforderlich | 2luv-api | Short-lived HttpOnly owner capability for legacy Gift edits. | Up to 30 days; recovered sessions use 1 hour | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | Erforderlich | 2luv-api | HttpOnly view or owner capability for interactive Card collections. | Session or 30 days | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | Erforderlich | 2luv-api | Short-lived signed capability used to read one checkout payment status. | 24 hours | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| localStorage | Erforderlich | 2luv-ui | Stores an unfinished create flow locally so a visitor can recover a draft before publishing. | 30 days after last save | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| IndexedDB | Erforderlich | 2luv-ui | Stores draft photo blobs locally while a visitor is composing an unpublished gift or letter. | 30 days after last save | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| IndexedDB | Erforderlich | 2luv-ui | Keeps private creation and editing drafts, local photos and confirmed operation receipts recoverable on this device; excludes passwords and access tokens. | 30 days after last save; expired checkpoints pruned on next use in bounded batches; photo bytes removed when no remaining checkpoint references them | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| localStorage / sessionStorage | Erforderlich | 2luv-ui | Identifies the draft and the separate checkpoint for this editor to resume; neither is an authorization credential. | Until creation succeeds or browser data is cleared | browser only | security_storage | Deleted after successful creation or by the full device/session cleanup action. | |
| localStorage / sessionStorage | Erforderlich | 2luv-ui | Resumes each Letter editor's private checkpoint without storing authorization credentials. | Until editing succeeds or browser data is cleared; at most 100 Letter pointers | browser only | security_storage | Deleted after confirmed editing or by full device/session cleanup. | |
| localStorage | Erforderlich | 2luv-ui | Prevents duplicate create requests when a submission is retried. | Until creation succeeds or browser data is cleared | browser only | security_storage | Deleted after successful creation or by the full device/session cleanup action. | |
| sessionStorage | Erforderlich | 2luv-ui | Keeps the latest create-flow lead and letter link available during payment continuation. | Until replaced or browser data is cleared | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| sessionStorage | Erforderlich | 2luv-ui | Stores an unpublished WebMCP-assisted create draft in this browser. | Until published, replaced or browser data is cleared | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| sessionStorage | Erforderlich | 2luv-ui | Legacy owner capability from older builds; current builds use HttpOnly cookies and never write this key. | Browser tab session | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| sessionStorage | Analyse | 2luv-ui | Stores temporary Google Analytics debug state for the current tab. | Browser tab session | browser only | analytics_storage | Deleted when analytics consent is revoked or by the full device/session cleanup action. | |
| localStorage | Präferenzen | 2luv-ui | Stores the selected light, dark, or system theme preference; system is resolved locally from the browser color-scheme setting. | until changed or cleared | browser only | functionality_storage | Deleted by the full device/session cleanup action. | |
| localStorage | Präferenzen | 2luv-ui | Legacy mirror of the selected language used by public controls. | until changed or cleared | browser only | functionality_storage | Deleted by the full device/session cleanup action. | |
| localStorage | Präferenzen | 2luv-ui | Stores recently opened gift and letter links in this browser so the landing page can resume the latest item after preference consent. | until changed, consent is revoked, or cleared | browser only | functionality_storage | Deleted when preference consent is revoked or by the full device/session cleanup action. | |
| localStorage | Marketing | 2luv-ui | Stores consented campaign and click identifiers for checkout attribution. | 90 days | browser only | ad_storage | Deleted when marketing consent is revoked or by the full device/session cleanup action. | |
| Cookie | Marketing | 2luv-ui | Preserves browser and advertising click identifiers for server-side Meta and TikTok conversions. Click cookies are created only after an actual ad click; no social pixel scripts are loaded. | 90 days | 2luv domain | ad_storage / ad_user_data | Deleted when marketing consent is revoked or optional browser data is cleared. | |
| Cookie | Marketing | 2luv-ui | Reads an existing TikTok browser identifier for consented server-side conversions. The current UI does not create or renew this cookie. | Existing cookie expiry | 2luv domain | ad_storage / ad_user_data | Deleted when marketing consent is revoked or optional browser data is cleared. | |
| sessionStorage | Präferenzen | 2luv-ui | Tracks promo cards shown during the current tab session to avoid repeated prompts. | browser tab session | browser only | functionality_storage | Deleted when the tab closes or by the full device/session cleanup action. | |
| sessionStorage | Präferenzen | 2luv-ui | Stores the keyboard state for the Termo interactive card during the current tab session. | browser tab session | browser only | functionality_storage | Deleted when the tab closes or by the full device/session cleanup action. | |
| network telemetry | Erforderlich | Microsoft | Records sanitized server request routes, status, duration and failures for reliability and security operations without browser identifiers. | Azure project retention policy | Microsoft Azure / 2luv server | not browser consent-controlled; operational server telemetry | Managed through the Azure Application Insights retention policy. | |
| network telemetry | Analyse | Sentry | Captures frontend errors and performance traces only after analytics consent. | provider-defined project retention | Sentry SaaS / 2luv domain | analytics_storage | Sentry loads only after analytics consent; optional browser data cleanup removes legacy Sentry Replay keys from earlier builds. | |
| Cookie | Marketing | Measures ad conversions and campaign attribution only when marketing consent is granted. | provider-defined, commonly up to 3 months | Google / 2luv domain | ad_storage, ad_user_data, ad_personalization | Deleted when optional cookies are rejected where browser access allows it. | ||
| network telemetry | Marketing | Sends normalized email or phone only as SHA-256 hashes for enhanced conversion matching after ad_user_data consent. | in memory until sent or consent is revoked; provider-defined retention after receipt | ad_user_data | Queued user_data is cleared when marketing consent is denied; raw contact values are never sent through the Google tag. | |||
| Third-party embed | Marketing | Music provider | Loads third-party media previews after marketing consent or when the visitor opens the provider directly. | provider-defined | third-party providers | ad_storage | Blocked until consent; provider data must be managed with the provider. | |
| HTTP cache | Erforderlich | 2luv-api | Caches public, non-sensitive metadata briefly for performance and availability. | 60 seconds browser, up to 1 hour stale revalidation depending on endpoint | browser/CDN | not consent-controlled | Browser cache can be cleared from browser settings. | |
| HTTP cache | Erforderlich | 2luv-api | Sensitive responses are marked private or no-store to avoid shared caching. | no-store or private short-lived | browser only | not consent-controlled | No shared cache should retain these responses. | |
| CDN cache | Erforderlich | 2luv edge | Caches versioned public assets so pages load quickly without storing visitor profile data. | 7 days to 12 months depending on asset type | browser/CDN | not consent-controlled | Browser cache can be cleared from browser settings. | |
| Server memory | Erforderlich | 2luv-api | Short-lived server-side caches reduce repeated API and media work without being written to the visitor browser. | 10 seconds to 6 hours depending on cache | 2luv-api memory | not consent-controlled | Expires automatically on TTL or process restart. | |
| Database | Erforderlich | 2luv-api | Keeps short operational state required for uploads, edit sessions and payment safety. | 5 minutes to 24 hours where TTL exists; payment safety records follow backend retention | 2luv database | security_storage | Backend retention and operational cleanup, not browser cookie cleanup. |
6. Wie du deine Rechte ausüben kannst
Du kannst Informationen anfordern und deine Datenschutzrechte ausüben (z. B. Bestätigung der Verarbeitung, Auskunft, Berichtigung, Anonymisierung, Datenübertragbarkeit, Löschung und Widerruf der Einwilligung), sofern anwendbar, indem du uns kontaktierst.
Kontakt: contact@2-luv.com.
7. Änderungen und Änderungsdatum der Cookie-Richtlinie
Wir können diese Cookie-Richtlinie aktualisieren, um Änderungen an unseren Services, Technologien oder gesetzlichen Pflichten widerzuspiegeln. Bei relevanten Änderungen aktualisieren wir das Datum “Zuletzt aktualisiert” oben auf dieser Seite.