Dasar Kuki — Persetujuan & Keutamaan
1. Apakah itu kuki dan bagaimana kami menggunakannya
Kuki ialah fail teks kecil yang disimpan oleh pelayar anda apabila anda melawat sesebuah laman web. Ia membantu mengingati keutamaan, memastikan ciri penting berfungsi, dan—apabila anda mengizinkan—mengukur prestasi serta keberkesanan kempen.
Di 2luv, kami menggunakan kuki terutamanya untuk: (a) mengingati persetujuan anda, (b) menyediakan ciri dan keselamatan pada sesetengah halaman (contohnya, kandungan dilindungi kata laluan), dan (c) apabila dibenarkan, mengukur penggunaan dan penukaran.
2. Jenis kuki yang digunakan dan tujuannya
Diperlukan: penting untuk keselamatan dan fungsi asas (contohnya, mengingati persetujuan dan mengesahkan kandungan dilindungi).
Fungsian: meningkatkan pengalaman dan membantu navigasi (contohnya, mengingati kandungan yang terakhir diakses).
Keutamaan: menyimpan pilihan seperti bahasa.
Analitik: membantu mengukur dan memahami penggunaan laman (statistik) apabila diaktifkan.
Pemasaran: membantu mengukur kempen dan penukaran apabila diaktifkan.
3. Cara kami mendapatkan persetujuan anda dan tempoh ia disimpan
Apabila anda mengakses 2luv, kami memaparkan sepanduk kuki supaya anda boleh menerima, menolak, atau menyesuaikan keutamaan (contohnya, Analitik dan Pemasaran).
Pilihan anda disimpan supaya kami dapat menghormatinya pada lawatan seterusnya. Secara umum, kami menyimpan rekod sehingga 12 bulan (ia boleh berbeza bergantung pada tetapan pelayar). Dalam sesetengah kes, kami juga menggunakan localStorage pelayar untuk menyimpan keutamaan.
4. Cara anda boleh menolak kuki
Anda boleh menolak kuki pilihan terus pada sepanduk dengan mengklik Tolak atau mematikan kategori dalam Sesuaikan.
Anda juga boleh mengurus kuki dalam tetapan pelayar (sekat, padam, atau hadkan). Jika anda memadam kuki, sesetengah keutamaan mungkin ditetapkan semula.
5. Kuki yang digunakan
Senarai di bawah merangkumi kuki pihak pertama (ditetapkan oleh 2luv) serta kuki/pengecam yang mungkin ditetapkan oleh perkhidmatan pihak ketiga (Analitik/Iklan). Sesetengah nama dan tempoh mungkin berbeza bergantung pada penyedia dan pelayar.
| Teknologi | Kategori | Pemilik | Nama | Tujuan | Tempoh | Domain | Consent mode | Pembersihan |
|---|---|---|---|---|---|---|---|---|
| cookie / localStorage | Diperlukan | 2luv-ui | Menyimpan pilihan persetujuan anda (termasuk keutamaan Consent Mode) supaya kami dapat menghormati pilihan anda pada lawatan akan datang. | 12 bulan | 2luv domain | security_storage | Kept when optional data is rejected; reset when the visitor clears all browser data. | |
| Cookie | Diperlukan | 2luv-ui | Mengekalkan perkhidmatan dalam bahasa, format tarikh dan arah bacaan yang betul pada pelayar ini. | 12 bulan | 2luv domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | Diperlukan | 2luv-ui | Mengekalkan harga, mata wang, ketersediaan pelan dan penghalaan serantau yang konsisten pada pelayar ini. | 12 bulan | 2luv domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | Keutamaan | 2luv-api | Membantu menyambung semula dengan cepat hadiah/surat terakhir yang diakses dalam pelayar ini. | 30 days | 2luv API domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | Diperlukan | 2luv-api | Kuki keselamatan (httpOnly) untuk mengenal pasti peranti/pelayar dan membantu melindungi akses serta operasi sensitif. | 12 months | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | Diperlukan | 2luv-api | Kebenaran HttpOnly jangka pendek yang terikat pada peranti/pelayar ini untuk menyegarkan hasil Cari Hadiah Saya tanpa menggunakan semula kod e-mel. | Sesi pelayar, maksimum 8 jam | Domain API 2luv | security_storage | Dipadam melalui tindakan pembersihan penuh peranti atau sesi menerusi API. | |
| localStorage | Diperlukan | 2luv-ui | Mengingati sementara e-mel Cari Hadiah Saya yang disahkan dalam pelayar ini supaya hasil boleh disegarkan selepas navigasi atau muat semula. | Sah selama 8 jam; rekod tamat tempoh dipadam apabila Cari Hadiah Saya dibuka semula | Pelayar ini sahaja | security_storage | Dipadam apabila e-mel lain dipilih, apabila tamat tempoh, atau melalui pembersihan penuh peranti atau sesi. | |
| Cookie | Diperlukan | 2luv-api | Kuki pengesahan (httpOnly) untuk mengekalkan akses kepada surat yang dilindungi kata laluan dan membolehkan tindakan yang dibenarkan berkaitan kandungan tersebut. | 30 hari | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | Diperlukan | Membantu membezakan manusia daripada penyalahgunaan automatik semasa carian, hubungan, penulisan berbantu AI, muat naik media, penciptaan dan suntingan surat. | sehingga 6 bulan | not consent-controlled; strictly necessary security | Loaded only on protected form submission; provider data must be managed through browser or Google settings. | |||
| Cookie | Analitik | Google Analytics: membantu memahami penggunaan laman (statistik agregat), prestasi dan navigasi, sambil mematuhi Consent Mode. | sehingga 13 bulan | Google / 2luv domain | analytics_storage | Deleted when optional cookies are rejected where browser access allows it. | ||
| Cookie | Keutamaan | 2luv-api | Compatibility resume cookie name that the current letter API clears when deleting session state. | legacy/session | 2luv API domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | Diperlukan | 2luv-api | Short-lived HttpOnly owner capability for legacy Gift edits. | Up to 30 days; recovered sessions use 1 hour | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | Diperlukan | 2luv-api | HttpOnly view or owner capability for interactive Card collections. | Session or 30 days | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | Diperlukan | 2luv-api | Short-lived signed capability used to read one checkout payment status. | 24 hours | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| localStorage | Diperlukan | 2luv-ui | Stores an unfinished create flow locally so a visitor can recover a draft before publishing. | 30 days after last save | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| IndexedDB | Diperlukan | 2luv-ui | Stores draft photo blobs locally while a visitor is composing an unpublished gift or letter. | 30 days after last save | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| localStorage | Diperlukan | 2luv-ui | Prevents duplicate create requests when a submission is retried. | Until creation succeeds or browser data is cleared | browser only | security_storage | Deleted after successful creation or by the full device/session cleanup action. | |
| sessionStorage | Diperlukan | 2luv-ui | Keeps the latest create-flow lead and letter link available during payment continuation. | Until replaced or browser data is cleared | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| sessionStorage | Diperlukan | 2luv-ui | Stores an unpublished WebMCP-assisted create draft in this browser. | Until published, replaced or browser data is cleared | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| sessionStorage | Diperlukan | 2luv-ui | Legacy owner capability from older builds; current builds use HttpOnly cookies and never write this key. | Browser tab session | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| sessionStorage | Analitik | 2luv-ui | Stores temporary Google Analytics debug state for the current tab. | Browser tab session | browser only | analytics_storage | Deleted when analytics consent is revoked or by the full device/session cleanup action. | |
| localStorage | Keutamaan | 2luv-ui | Stores the selected light, dark, or system theme preference; system is resolved locally from the browser color-scheme setting. | until changed or cleared | browser only | functionality_storage | Deleted by the full device/session cleanup action. | |
| localStorage | Keutamaan | 2luv-ui | Legacy mirror of the selected language used by public controls. | until changed or cleared | browser only | functionality_storage | Deleted by the full device/session cleanup action. | |
| localStorage | Keutamaan | 2luv-ui | Stores recently opened gift and letter links in this browser so the landing page can resume the latest item after preference consent. | until changed, consent is revoked, or cleared | browser only | functionality_storage | Deleted when preference consent is revoked or by the full device/session cleanup action. | |
| localStorage | Pemasaran | 2luv-ui | Stores consented campaign and click identifiers for checkout attribution. | 90 days | browser only | ad_storage | Deleted when marketing consent is revoked or by the full device/session cleanup action. | |
| Cookie | Pemasaran | 2luv-ui | Preserves browser and advertising click identifiers for server-side Meta and TikTok conversions. Click cookies are created only after an actual ad click; no social pixel scripts are loaded. | 90 days | 2luv domain | ad_storage / ad_user_data | Deleted when marketing consent is revoked or optional browser data is cleared. | |
| Cookie | Pemasaran | 2luv-ui | Reads an existing TikTok browser identifier for consented server-side conversions. The current UI does not create or renew this cookie. | Existing cookie expiry | 2luv domain | ad_storage / ad_user_data | Deleted when marketing consent is revoked or optional browser data is cleared. | |
| sessionStorage | Keutamaan | 2luv-ui | Tracks promo cards shown during the current tab session to avoid repeated prompts. | browser tab session | browser only | functionality_storage | Deleted when the tab closes or by the full device/session cleanup action. | |
| sessionStorage | Keutamaan | 2luv-ui | Stores the keyboard state for the Termo interactive card during the current tab session. | browser tab session | browser only | functionality_storage | Deleted when the tab closes or by the full device/session cleanup action. | |
| network telemetry | Diperlukan | Microsoft | Records sanitized server request routes, status, duration and failures for reliability and security operations without browser identifiers. | Azure project retention policy | Microsoft Azure / 2luv server | not browser consent-controlled; operational server telemetry | Managed through the Azure Application Insights retention policy. | |
| network telemetry | Analitik | Sentry | Captures frontend errors and performance traces only after analytics consent. | provider-defined project retention | Sentry SaaS / 2luv domain | analytics_storage | Sentry loads only after analytics consent; optional browser data cleanup removes legacy Sentry Replay keys from earlier builds. | |
| Cookie | Pemasaran | Measures ad conversions and campaign attribution only when marketing consent is granted. | provider-defined, commonly up to 3 months | Google / 2luv domain | ad_storage, ad_user_data, ad_personalization | Deleted when optional cookies are rejected where browser access allows it. | ||
| network telemetry | Pemasaran | Sends normalized email or phone only as SHA-256 hashes for enhanced conversion matching after ad_user_data consent. | in memory until sent or consent is revoked; provider-defined retention after receipt | ad_user_data | Queued user_data is cleared when marketing consent is denied; raw contact values are never sent through the Google tag. | |||
| Third-party embed | Pemasaran | Music provider | Loads third-party media previews after marketing consent or when the visitor opens the provider directly. | provider-defined | third-party providers | ad_storage | Blocked until consent; provider data must be managed with the provider. | |
| HTTP cache | Diperlukan | 2luv-api | Caches public, non-sensitive metadata briefly for performance and availability. | 60 seconds browser, up to 1 hour stale revalidation depending on endpoint | browser/CDN | not consent-controlled | Browser cache can be cleared from browser settings. | |
| HTTP cache | Diperlukan | 2luv-api | Sensitive responses are marked private or no-store to avoid shared caching. | no-store or private short-lived | browser only | not consent-controlled | No shared cache should retain these responses. | |
| CDN cache | Diperlukan | 2luv edge | Caches versioned public assets so pages load quickly without storing visitor profile data. | 7 days to 12 months depending on asset type | browser/CDN | not consent-controlled | Browser cache can be cleared from browser settings. | |
| Server memory | Diperlukan | 2luv-api | Short-lived server-side caches reduce repeated API and media work without being written to the visitor browser. | 10 seconds to 6 hours depending on cache | 2luv-api memory | not consent-controlled | Expires automatically on TTL or process restart. | |
| Database | Diperlukan | 2luv-api | Keeps short operational state required for uploads, edit sessions and payment safety. | 5 minutes to 24 hours where TTL exists; payment safety records follow backend retention | 2luv database | security_storage | Backend retention and operational cleanup, not browser cookie cleanup. |
6. Cara untuk menggunakan hak anda
Anda boleh meminta maklumat dan menggunakan hak privasi anda (contohnya: pengesahan pemprosesan, akses, pembetulan, penganoniman, kebolehpindahan, pemadaman, dan penarikan balik persetujuan), apabila berkenaan, dengan menghubungi kami.
Saluran hubungan: contact@2-luv.com.
7. Perubahan dan tarikh pengubahsuaian Dasar Kuki
Kami mungkin mengemas kini Dasar Kuki ini untuk mencerminkan perubahan pada perkhidmatan, teknologi atau kewajipan undang-undang kami. Apabila terdapat perubahan penting, kami akan mengemas kini tarikh “Kemas kini terakhir” di bahagian atas halaman ini.