Cookieポリシー — 同意と設定
1. Cookieとは何か、どのように使用するか
Cookieは、Webサイトを訪問した際にブラウザに保存される小さなテキストファイルです。設定を記憶したり、重要な機能を動作させたり、許可された場合にはパフォーマンスやキャンペーン効果を測定するのに役立ちます。
2luvでは主に、(a) 同意設定を記憶する、(b) 一部ページの機能やセキュリティを提供する(例:パスワード保護されたコンテンツ)、(c) 許可された場合に利用状況やコンバージョンを測定する目的でCookieを使用します。
2. 使用するCookieの種類と目的
必須:セキュリティと基本機能に不可欠(例:同意の記憶、保護コンテンツの認証)。
機能:体験向上とナビゲーション支援(例:最後にアクセスした内容の記憶)。
設定:言語などの選択を保存。
分析:有効化された場合にサイト利用状況(統計)を測定・理解するのに役立つ。
マーケティング:有効化された場合にキャンペーンやコンバージョンの測定に役立つ。
3. 同意の取得方法と保存期間
2luvにアクセスすると、Cookieバナーを表示し、受け入れ/拒否/設定のカスタマイズ(例:分析・マーケティング)を行えます。
選択内容は今後の訪問時にも尊重できるよう保存されます。通常は最大12か月保存します(ブラウザ設定により異なる場合があります)。一部のケースでは、設定保存のためにブラウザのlocalStorageも使用します。
4. Cookieを拒否する方法
バナーで「拒否」を選択するか、「カスタマイズ」でカテゴリを無効化することで、任意のCookieを拒否できます。
また、ブラウザ設定からCookieを管理(ブロック/削除/制限)することも可能です。Cookieを削除すると、一部の設定がリセットされる場合があります。
5. 使用されるCookie
以下の一覧には、2luvが設定するファーストパーティCookie、および第三者サービス(分析/広告)が設定する可能性のあるCookie/識別子が含まれます。名称や保存期間は提供元やブラウザにより異なる場合があります。
| 技術 | 分類 | 管理者 | 名前 | 目的 | 期間 | ドメイン | Consent mode | 削除 |
|---|---|---|---|---|---|---|---|---|
| cookie / localStorage | 必須 | 2luv-ui | Consent Mode の設定を含む同意選択を保存し、次回以降の訪問でも選択を尊重できるようにします。 | 12か月 | 2luv domain | security_storage | Kept when optional data is rejected; reset when the visitor clears all browser data. | |
| Cookie | 必須 | 2luv-ui | このブラウザで正しい言語、日付形式、読み方向でサービスを表示します。 | 12か月 | 2luv domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | 必須 | 2luv-ui | このブラウザで価格、通貨、プランの提供状況、地域ルーティングを一貫させます。 | 12か月 | 2luv domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | 設定 | 2luv-api | このブラウザで最後に開いたギフト/レターにすばやく戻れるようにします。 | 30 days | 2luv API domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | 必須 | 2luv-api | セキュリティ用 Cookie(httpOnly)。デバイス/ブラウザを識別し、アクセスや機微な操作を保護します。 | 12 months | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | 必須 | 2luv-api | このデバイス/ブラウザに紐づく短期間の HttpOnly 認証で、メールのコードを再利用せずに「ギフトを探す」の結果を更新します。 | ブラウザセッション、最長8時間 | 2luv API ドメイン | security_storage | API のデバイス/セッション完全消去操作によって削除されます。 | |
| localStorage | 必須 | 2luv-ui | 確認済みの「ギフトを探す」メールアドレスをこのブラウザに一時保存し、移動や再読み込み後に結果を更新できるようにします。 | 8時間有効。期限切れの記録は次回「ギフトを探す」を開いた時に削除されます | このブラウザのみ | security_storage | 別のメールを選択した時、期限切れ時、またはデバイス/セッションの完全消去時に削除されます。 | |
| Cookie | 必須 | 2luv-api | 認証 Cookie(httpOnly)。パスワード保護されたレターへのアクセスを維持し、関連する許可された操作を可能にします。 | 30日 | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | 必須 | レター検索、お問い合わせ、AI 支援による文章作成、メディアアップロード、レター作成、レター編集時に、人間と自動化された不正利用を区別するために使用します。 | 最大6か月 | not consent-controlled; strictly necessary security | Loaded when the letter editor opens or a protected form is submitted; provider data must be managed through browser or Google settings. | |||
| Cookie | 分析 | Google Analytics:Consent Mode を尊重しつつ、サイト利用(集計統計)、パフォーマンス、ナビゲーションを理解するのに役立ちます。 | 最大13か月 | Google / 2luv domain | analytics_storage | Deleted when optional cookies are rejected where browser access allows it. | ||
| Cookie | 設定 | 2luv-api | Compatibility resume cookie name that the current letter API clears when deleting session state. | legacy/session | 2luv API domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | 必須 | 2luv-api | Short-lived HttpOnly owner capability for legacy Gift edits. | Up to 30 days; recovered sessions use 1 hour | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | 必須 | 2luv-api | HttpOnly view or owner capability for interactive Card collections. | Session or 30 days | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | 必須 | 2luv-api | Short-lived signed capability used to read one checkout payment status. | 24 hours | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| localStorage | 必須 | 2luv-ui | Stores an unfinished create flow locally so a visitor can recover a draft before publishing. | 30 days after last save | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| IndexedDB | 必須 | 2luv-ui | Stores draft photo blobs locally while a visitor is composing an unpublished gift or letter. | 30 days after last save | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| IndexedDB | 必須 | 2luv-ui | Keeps private creation and editing drafts, local photos and confirmed operation receipts recoverable on this device; excludes passwords and access tokens. | 30 days after last save; expired checkpoints pruned on next use in bounded batches; photo bytes removed when no remaining checkpoint references them | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| localStorage / sessionStorage | 必須 | 2luv-ui | Identifies the draft and the separate checkpoint for this editor to resume; neither is an authorization credential. | Until creation succeeds or browser data is cleared | browser only | security_storage | Deleted after successful creation or by the full device/session cleanup action. | |
| localStorage / sessionStorage | 必須 | 2luv-ui | Resumes each Letter editor's private checkpoint without storing authorization credentials. | Until editing succeeds or browser data is cleared; at most 100 Letter pointers | browser only | security_storage | Deleted after confirmed editing or by full device/session cleanup. | |
| localStorage | 必須 | 2luv-ui | Prevents duplicate create requests when a submission is retried. | Until creation succeeds or browser data is cleared | browser only | security_storage | Deleted after successful creation or by the full device/session cleanup action. | |
| sessionStorage | 必須 | 2luv-ui | Keeps the latest create-flow lead and letter link available during payment continuation. | Until replaced or browser data is cleared | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| sessionStorage | 必須 | 2luv-ui | Stores an unpublished WebMCP-assisted create draft in this browser. | Until published, replaced or browser data is cleared | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| sessionStorage | 必須 | 2luv-ui | Legacy owner capability from older builds; current builds use HttpOnly cookies and never write this key. | Browser tab session | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| sessionStorage | 分析 | 2luv-ui | Stores temporary Google Analytics debug state for the current tab. | Browser tab session | browser only | analytics_storage | Deleted when analytics consent is revoked or by the full device/session cleanup action. | |
| localStorage | 設定 | 2luv-ui | Stores the selected light, dark, or system theme preference; system is resolved locally from the browser color-scheme setting. | until changed or cleared | browser only | functionality_storage | Deleted by the full device/session cleanup action. | |
| localStorage | 設定 | 2luv-ui | Legacy mirror of the selected language used by public controls. | until changed or cleared | browser only | functionality_storage | Deleted by the full device/session cleanup action. | |
| localStorage | 設定 | 2luv-ui | Stores recently opened gift and letter links in this browser so the landing page can resume the latest item after preference consent. | until changed, consent is revoked, or cleared | browser only | functionality_storage | Deleted when preference consent is revoked or by the full device/session cleanup action. | |
| localStorage | マーケティング | 2luv-ui | Stores consented campaign and click identifiers for checkout attribution. | 90 days | browser only | ad_storage | Deleted when marketing consent is revoked or by the full device/session cleanup action. | |
| Cookie | マーケティング | 2luv-ui | Preserves browser and advertising click identifiers for server-side Meta and TikTok conversions. Click cookies are created only after an actual ad click; no social pixel scripts are loaded. | 90 days | 2luv domain | ad_storage / ad_user_data | Deleted when marketing consent is revoked or optional browser data is cleared. | |
| Cookie | マーケティング | 2luv-ui | Reads an existing TikTok browser identifier for consented server-side conversions. The current UI does not create or renew this cookie. | Existing cookie expiry | 2luv domain | ad_storage / ad_user_data | Deleted when marketing consent is revoked or optional browser data is cleared. | |
| sessionStorage | 設定 | 2luv-ui | Tracks promo cards shown during the current tab session to avoid repeated prompts. | browser tab session | browser only | functionality_storage | Deleted when the tab closes or by the full device/session cleanup action. | |
| sessionStorage | 設定 | 2luv-ui | Stores the keyboard state for the Termo interactive card during the current tab session. | browser tab session | browser only | functionality_storage | Deleted when the tab closes or by the full device/session cleanup action. | |
| network telemetry | 必須 | Microsoft | Records sanitized server request routes, status, duration and failures for reliability and security operations without browser identifiers. | Azure project retention policy | Microsoft Azure / 2luv server | not browser consent-controlled; operational server telemetry | Managed through the Azure Application Insights retention policy. | |
| network telemetry | 分析 | Sentry | Captures frontend errors and performance traces only after analytics consent. | provider-defined project retention | Sentry SaaS / 2luv domain | analytics_storage | Sentry loads only after analytics consent; optional browser data cleanup removes legacy Sentry Replay keys from earlier builds. | |
| Cookie | マーケティング | Measures ad conversions and campaign attribution only when marketing consent is granted. | provider-defined, commonly up to 3 months | Google / 2luv domain | ad_storage, ad_user_data, ad_personalization | Deleted when optional cookies are rejected where browser access allows it. | ||
| network telemetry | マーケティング | Sends normalized email or phone only as SHA-256 hashes for enhanced conversion matching after ad_user_data consent. | in memory until sent or consent is revoked; provider-defined retention after receipt | ad_user_data | Queued user_data is cleared when marketing consent is denied; raw contact values are never sent through the Google tag. | |||
| Third-party embed | マーケティング | Music provider | Loads third-party media previews after marketing consent or when the visitor opens the provider directly. | provider-defined | third-party providers | ad_storage | Blocked until consent; provider data must be managed with the provider. | |
| HTTP cache | 必須 | 2luv-api | Caches public, non-sensitive metadata briefly for performance and availability. | 60 seconds browser, up to 1 hour stale revalidation depending on endpoint | browser/CDN | not consent-controlled | Browser cache can be cleared from browser settings. | |
| HTTP cache | 必須 | 2luv-api | Sensitive responses are marked private or no-store to avoid shared caching. | no-store or private short-lived | browser only | not consent-controlled | No shared cache should retain these responses. | |
| CDN cache | 必須 | 2luv edge | Caches versioned public assets so pages load quickly without storing visitor profile data. | 7 days to 12 months depending on asset type | browser/CDN | not consent-controlled | Browser cache can be cleared from browser settings. | |
| Server memory | 必須 | 2luv-api | Short-lived server-side caches reduce repeated API and media work without being written to the visitor browser. | 10 seconds to 6 hours depending on cache | 2luv-api memory | not consent-controlled | Expires automatically on TTL or process restart. | |
| Database | 必須 | 2luv-api | Keeps short operational state required for uploads, edit sessions and payment safety. | 5 minutes to 24 hours where TTL exists; payment safety records follow backend retention | 2luv database | security_storage | Backend retention and operational cleanup, not browser cookie cleanup. |
6. 権利の行使方法
適用される場合、当社に連絡することで、情報の請求やプライバシーに関する権利(例:処理の確認、アクセス、訂正、匿名化、ポータビリティ、削除、同意の撤回)を行使できます。
連絡先:contact@2-luv.com。
7. Cookieポリシーの変更と改定日
当社は、サービス、技術、または法的義務の変更を反映するために本Cookieポリシーを更新することがあります。重要な変更がある場合、このページ上部の「最終更新」日付を更新します。