Política de Cookies — Consentimiento y Preferencias
1. Qué son las cookies y cómo las usamos
Las cookies son pequeños archivos de texto que tu navegador guarda cuando visitas un sitio web. Ayudan a recordar preferencias, mantener funciones esenciales y—cuando lo permites—medir rendimiento y efectividad de campañas.
En 2luv usamos cookies principalmente para: (a) recordar tu consentimiento, (b) ofrecer funciones y seguridad en algunas páginas (por ejemplo, contenido protegido con contraseña) y (c) cuando lo autorizas, medir uso y conversiones.
2. Tipos de cookies usadas y finalidad
Necesarias: esenciales para la seguridad y la funcionalidad básica (por ejemplo, recordar el consentimiento y autenticar contenido protegido).
Funcionales: mejoran tu experiencia y ayudan en la navegación (por ejemplo, recordar el último contenido accedido).
Preferencias: guardan elecciones como el idioma.
Analíticas: ayudan a medir y entender el uso del sitio (estadísticas), cuando están habilitadas.
Marketing: ayudan a medir campañas y conversiones, cuando están habilitadas.
3. Cómo recopilamos tu consentimiento y por cuánto tiempo se guarda
Cuando accedes a 2luv, mostramos un banner de cookies para que puedas aceptar, rechazar o personalizar tus preferencias (por ejemplo, Analíticas y Marketing).
Tu elección se guarda para que podamos respetarla en futuras visitas. En general, conservamos el registro hasta por 12 meses (puede variar según la configuración del navegador). En algunos casos, también usamos el localStorage del navegador para guardar preferencias.
4. Cómo puedes rechazar cookies
Puedes rechazar cookies opcionales directamente en el banner haciendo clic en Rechazar o desactivando categorías en Personalizar.
También puedes gestionar cookies en la configuración de tu navegador (bloquear, eliminar o limitar). Si borras las cookies, algunas preferencias pueden restablecerse.
5. Qué cookies se usan
La lista de abajo incluye cookies de origen (configuradas por 2luv) y cookies/identificadores que pueden ser configurados por servicios de terceros (Analíticas/Anuncios). Algunos nombres y duraciones pueden variar según el proveedor y el navegador.
| Tecnologia | Categoría | Responsable | Nombre | Finalidad | Duración | Dominio | Consent mode | Limpieza |
|---|---|---|---|---|---|---|---|---|
| cookie / localStorage | Necesarias | 2luv-ui | Guarda tu elección de consentimiento (incluidas las preferencias de Consent Mode) para que podamos respetar tus opciones en futuras visitas. | 12 meses | 2luv domain | security_storage | Kept when optional data is rejected; reset when the visitor clears all browser data. | |
| Cookie | Necesarias | 2luv-ui | Mantiene el servicio en el idioma, formato de fecha y direccion de lectura correctos en este navegador. | 12 meses | 2luv domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | Necesarias | 2luv-ui | Mantiene precios, moneda, disponibilidad de planes y enrutamiento regional coherentes en este navegador. | 12 meses | 2luv domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | Preferencias | 2luv-api | Ayuda a retomar rápidamente el último regalo/carta accedido en este navegador. | 30 days | 2luv API domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | Necesarias | 2luv-api | Cookie de seguridad (httpOnly) para identificar el dispositivo/navegador y ayudar a proteger accesos y operaciones sensibles. | 12 months | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | Necesarias | 2luv-api | Autorización HttpOnly de corta duración vinculada a este dispositivo/navegador para actualizar los resultados de Encontrar Mi Regalo sin reutilizar el código recibido por correo. | Sesión del navegador, máximo 8 horas | Dominio de la API de 2luv | security_storage | Se elimina mediante la acción de limpieza completa del dispositivo o la sesión a través de la API. | |
| localStorage | Necesarias | 2luv-ui | Recuerda temporalmente en este navegador el correo verificado de Encontrar Mi Regalo para actualizar los resultados después de navegar o recargar. | Válido durante 8 horas; el registro vencido se elimina al volver a abrir Encontrar Mi Regalo | Solo este navegador | security_storage | Se elimina al elegir otro correo, al caducar o mediante la limpieza completa del dispositivo o la sesión. | |
| Cookie | Necesarias | 2luv-api | Cookie de autenticación (httpOnly) usada para mantener el acceso a cartas protegidas con contraseña y permitir acciones autorizadas relacionadas con ese contenido. | 30 días | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | Necesarias | Ayuda a distinguir a las personas del abuso automatizado durante la búsqueda, el contacto, la escritura asistida por IA, la carga de medios, la creación y la edición de cartas. | hasta 6 meses | not consent-controlled; strictly necessary security | Loaded only on protected form submission; provider data must be managed through browser or Google settings. | |||
| Cookie | Analíticas | Google Analytics: ayuda a entender el uso del sitio (estadísticas agregadas), rendimiento y navegación, respetando Consent Mode. | hasta 13 meses | Google / 2luv domain | analytics_storage | Deleted when optional cookies are rejected where browser access allows it. | ||
| Cookie | Preferencias | 2luv-api | Compatibility resume cookie name that the current letter API clears when deleting session state. | legacy/session | 2luv API domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | Necesarias | 2luv-api | Short-lived HttpOnly owner capability for legacy Gift edits. | Up to 30 days; recovered sessions use 1 hour | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | Necesarias | 2luv-api | HttpOnly view or owner capability for interactive Card collections. | Session or 30 days | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | Necesarias | 2luv-api | Short-lived signed capability used to read one checkout payment status. | 24 hours | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| localStorage | Necesarias | 2luv-ui | Stores an unfinished create flow locally so a visitor can recover a draft before publishing. | 30 days after last save | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| IndexedDB | Necesarias | 2luv-ui | Stores draft photo blobs locally while a visitor is composing an unpublished gift or letter. | 30 days after last save | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| localStorage | Necesarias | 2luv-ui | Prevents duplicate create requests when a submission is retried. | Until creation succeeds or browser data is cleared | browser only | security_storage | Deleted after successful creation or by the full device/session cleanup action. | |
| sessionStorage | Necesarias | 2luv-ui | Keeps the latest create-flow lead and letter link available during payment continuation. | Until replaced or browser data is cleared | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| sessionStorage | Necesarias | 2luv-ui | Stores an unpublished WebMCP-assisted create draft in this browser. | Until published, replaced or browser data is cleared | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| sessionStorage | Necesarias | 2luv-ui | Legacy owner capability from older builds; current builds use HttpOnly cookies and never write this key. | Browser tab session | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| sessionStorage | Analíticas | 2luv-ui | Stores temporary Google Analytics debug state for the current tab. | Browser tab session | browser only | analytics_storage | Deleted when analytics consent is revoked or by the full device/session cleanup action. | |
| localStorage | Preferencias | 2luv-ui | Stores the selected light, dark, or system theme preference; system is resolved locally from the browser color-scheme setting. | until changed or cleared | browser only | functionality_storage | Deleted by the full device/session cleanup action. | |
| localStorage | Preferencias | 2luv-ui | Legacy mirror of the selected language used by public controls. | until changed or cleared | browser only | functionality_storage | Deleted by the full device/session cleanup action. | |
| localStorage | Preferencias | 2luv-ui | Stores recently opened gift and letter links in this browser so the landing page can resume the latest item after preference consent. | until changed, consent is revoked, or cleared | browser only | functionality_storage | Deleted when preference consent is revoked or by the full device/session cleanup action. | |
| localStorage | Marketing | 2luv-ui | Stores consented campaign and click identifiers for checkout attribution. | 90 days | browser only | ad_storage | Deleted when marketing consent is revoked or by the full device/session cleanup action. | |
| Cookie | Marketing | 2luv-ui | Preserves browser and advertising click identifiers for server-side Meta and TikTok conversions. Click cookies are created only after an actual ad click; no social pixel scripts are loaded. | 90 days | 2luv domain | ad_storage / ad_user_data | Deleted when marketing consent is revoked or optional browser data is cleared. | |
| Cookie | Marketing | 2luv-ui | Reads an existing TikTok browser identifier for consented server-side conversions. The current UI does not create or renew this cookie. | Existing cookie expiry | 2luv domain | ad_storage / ad_user_data | Deleted when marketing consent is revoked or optional browser data is cleared. | |
| sessionStorage | Preferencias | 2luv-ui | Tracks promo cards shown during the current tab session to avoid repeated prompts. | browser tab session | browser only | functionality_storage | Deleted when the tab closes or by the full device/session cleanup action. | |
| sessionStorage | Preferencias | 2luv-ui | Stores the keyboard state for the Termo interactive card during the current tab session. | browser tab session | browser only | functionality_storage | Deleted when the tab closes or by the full device/session cleanup action. | |
| network telemetry | Necesarias | Microsoft | Records sanitized server request routes, status, duration and failures for reliability and security operations without browser identifiers. | Azure project retention policy | Microsoft Azure / 2luv server | not browser consent-controlled; operational server telemetry | Managed through the Azure Application Insights retention policy. | |
| network telemetry | Analíticas | Sentry | Captures frontend errors and performance traces only after analytics consent. | provider-defined project retention | Sentry SaaS / 2luv domain | analytics_storage | Sentry loads only after analytics consent; optional browser data cleanup removes legacy Sentry Replay keys from earlier builds. | |
| Cookie | Marketing | Measures ad conversions and campaign attribution only when marketing consent is granted. | provider-defined, commonly up to 3 months | Google / 2luv domain | ad_storage, ad_user_data, ad_personalization | Deleted when optional cookies are rejected where browser access allows it. | ||
| network telemetry | Marketing | Sends normalized email or phone only as SHA-256 hashes for enhanced conversion matching after ad_user_data consent. | in memory until sent or consent is revoked; provider-defined retention after receipt | ad_user_data | Queued user_data is cleared when marketing consent is denied; raw contact values are never sent through the Google tag. | |||
| Third-party embed | Marketing | Music provider | Loads third-party media previews after marketing consent or when the visitor opens the provider directly. | provider-defined | third-party providers | ad_storage | Blocked until consent; provider data must be managed with the provider. | |
| HTTP cache | Necesarias | 2luv-api | Caches public, non-sensitive metadata briefly for performance and availability. | 60 seconds browser, up to 1 hour stale revalidation depending on endpoint | browser/CDN | not consent-controlled | Browser cache can be cleared from browser settings. | |
| HTTP cache | Necesarias | 2luv-api | Sensitive responses are marked private or no-store to avoid shared caching. | no-store or private short-lived | browser only | not consent-controlled | No shared cache should retain these responses. | |
| CDN cache | Necesarias | 2luv edge | Caches versioned public assets so pages load quickly without storing visitor profile data. | 7 days to 12 months depending on asset type | browser/CDN | not consent-controlled | Browser cache can be cleared from browser settings. | |
| Server memory | Necesarias | 2luv-api | Short-lived server-side caches reduce repeated API and media work without being written to the visitor browser. | 10 seconds to 6 hours depending on cache | 2luv-api memory | not consent-controlled | Expires automatically on TTL or process restart. | |
| Database | Necesarias | 2luv-api | Keeps short operational state required for uploads, edit sessions and payment safety. | 5 minutes to 24 hours where TTL exists; payment safety records follow backend retention | 2luv database | security_storage | Backend retention and operational cleanup, not browser cookie cleanup. |
6. Cómo ejercer tus derechos
Puedes solicitar información y ejercer tus derechos de privacidad (por ejemplo: confirmación del tratamiento, acceso, corrección, anonimización, portabilidad, eliminación y revocación del consentimiento), cuando corresponda, contactándonos.
Canal de contacto: contact@2-luv.com.
7. Cambios y fecha de modificación de la Política de Cookies
Podemos actualizar esta Política de Cookies para reflejar cambios en nuestros servicios, tecnologías u obligaciones legales. Cuando haya cambios relevantes, actualizaremos la fecha de “Última actualización” en la parte superior de esta página.