Cookie 政策 — 同意與偏好設定
1. 什麼是 Cookie,以及我們如何使用
Cookie 是當你訪問網站時由瀏覽器儲存的小型文字檔案。它們可以幫助記住偏好設定、保持關鍵功能正常運行,並在你允許的情況下衡量效能與行銷活動效果。
在 2luv,我們主要使用 Cookie 來:(a) 記住你的同意選擇;(b) 在部分頁面提供功能與安全性(例如:受密碼保護的内容);(c) 在你授權時衡量使用情況與轉換。
2. Cookie 類型與用途
必要類:對安全與基礎功能至關重要(例如:記住同意設定、驗證受保護内容)。
功能類:提升體驗並幫助導覽(例如:記住最近訪問的内容)。
偏好類:儲存如語言等選擇。
分析類:在啟用時幫助衡量與理解網站使用情況(統計)。
行銷類:在啟用時幫助衡量活動與轉換。
3. 我們如何收集同意以及儲存時長
當你訪問 2luv 時,我們會顯示 Cookie 橫幅,讓你選擇接受、拒絕或自定義偏好(例如:分析與行銷)。
你的選擇會被儲存,以便在之後訪問時繼續尊重你的偏好。通常我們最多儲存 12 個月(可能因瀏覽器設定而不同)。在某些情況下,我們也會使用瀏覽器的 localStorage 來儲存偏好設定。
4. 如何拒絕 Cookie
你可以在橫幅中直接點擊「拒絕」來拒絕可選 Cookie,或在「自定義」中關閉相關類別。
你也可以在瀏覽器設定中管理 Cookie(阻止、刪除或限制)。如果你刪除 Cookie,部分偏好可能會被重置。
5. 我們使用哪些 Cookie
下方列表包含第一方 Cookie(由 2luv 設置)以及可能由第三方服務(分析/廣告)設置的 Cookie/識別符。部分名稱與儲存時長可能會因提供方與瀏覽器而變化。
| 技術 | 類別 | 負責方 | 名稱 | 用途 | 有效期 | 域 | Consent mode | 清除 |
|---|---|---|---|---|---|---|---|---|
| cookie / localStorage | 必要類 | 2luv-ui | 儲存你的同意選擇(包括 Consent Mode 偏好),以便我們在你未來訪問時遵循你的選擇。 | 12 個月 | 2luv domain | security_storage | Kept when optional data is rejected; reset when the visitor clears all browser data. | |
| Cookie | 必要類 | 2luv-ui | 在此瀏覽器中保持服務使用正確的語言、日期格式與閱讀方向。 | 12 個月 | 2luv domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | 必要類 | 2luv-ui | 在此瀏覽器中保持價格、貨幣、方案可用性與區域路由一致。 | 12 個月 | 2luv domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | 偏好類 | 2luv-api | 幫助快速繼續訪問你在此瀏覽器中最後打開的禮物/信件。 | 30 days | 2luv API domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | 必要類 | 2luv-api | 安全 Cookie(httpOnly),用於識別設備/瀏覽器並幫助保護存取與敏感操作。 | 12 months | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | 必要類 | 2luv-api | 綁定至此裝置/瀏覽器的短期 HttpOnly 授權,用於重新整理「尋找我的禮物」結果,無需重複使用電子郵件驗證碼。 | 瀏覽器工作階段,最長 8 小時 | 2luv API 網域 | security_storage | 透過 API 執行完整的裝置/工作階段清理時刪除。 | |
| localStorage | 必要類 | 2luv-ui | 在此瀏覽器中暫時記住已驗證的「尋找我的禮物」電子郵件,以便在導覽或重新載入後重新整理結果。 | 有效期 8 小時;過期記錄會在下次開啟「尋找我的禮物」時刪除 | 僅此瀏覽器 | security_storage | 選擇其他電子郵件、到期或執行完整裝置/工作階段清理時刪除。 | |
| Cookie | 必要類 | 2luv-api | 認證 Cookie(httpOnly),用於保持對密碼保護信件的訪問,並允許與該內容相關的授權操作。 | 30 天 | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | 必要類 | 在情書搜尋、聯絡、AI 輔助寫作、媒體上傳、情書建立和情書編輯過程中,協助區分真人與自動化濫用。 | 最長 6 個月 | not consent-controlled; strictly necessary security | Loaded when the letter editor opens or a protected form is submitted; provider data must be managed through browser or Google settings. | |||
| Cookie | 分析類 | Google Analytics:幫助了解網站使用情況(匯總統計)、效能與導覽,並遵循 Consent Mode。 | 最長 13 個月 | Google / 2luv domain | analytics_storage | Deleted when optional cookies are rejected where browser access allows it. | ||
| Cookie | 偏好類 | 2luv-api | Compatibility resume cookie name that the current letter API clears when deleting session state. | legacy/session | 2luv API domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | 必要類 | 2luv-api | Short-lived HttpOnly owner capability for legacy Gift edits. | Up to 30 days; recovered sessions use 1 hour | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | 必要類 | 2luv-api | HttpOnly view or owner capability for interactive Card collections. | Session or 30 days | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | 必要類 | 2luv-api | Short-lived signed capability used to read one checkout payment status. | 24 hours | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| localStorage | 必要類 | 2luv-ui | Stores an unfinished create flow locally so a visitor can recover a draft before publishing. | 30 days after last save | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| IndexedDB | 必要類 | 2luv-ui | Stores draft photo blobs locally while a visitor is composing an unpublished gift or letter. | 30 days after last save | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| IndexedDB | 必要類 | 2luv-ui | Keeps private creation and editing drafts, local photos and confirmed operation receipts recoverable on this device; excludes passwords and access tokens. | 30 days after last save; expired checkpoints pruned on next use in bounded batches; photo bytes removed when no remaining checkpoint references them | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| localStorage / sessionStorage | 必要類 | 2luv-ui | Identifies the draft and the separate checkpoint for this editor to resume; neither is an authorization credential. | Until creation succeeds or browser data is cleared | browser only | security_storage | Deleted after successful creation or by the full device/session cleanup action. | |
| localStorage / sessionStorage | 必要類 | 2luv-ui | Resumes each Letter editor's private checkpoint without storing authorization credentials. | Until editing succeeds or browser data is cleared; at most 100 Letter pointers | browser only | security_storage | Deleted after confirmed editing or by full device/session cleanup. | |
| localStorage | 必要類 | 2luv-ui | Prevents duplicate create requests when a submission is retried. | Until creation succeeds or browser data is cleared | browser only | security_storage | Deleted after successful creation or by the full device/session cleanup action. | |
| sessionStorage | 必要類 | 2luv-ui | Keeps the latest create-flow lead and letter link available during payment continuation. | Until replaced or browser data is cleared | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| sessionStorage | 必要類 | 2luv-ui | Stores an unpublished WebMCP-assisted create draft in this browser. | Until published, replaced or browser data is cleared | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| sessionStorage | 必要類 | 2luv-ui | Legacy owner capability from older builds; current builds use HttpOnly cookies and never write this key. | Browser tab session | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| sessionStorage | 分析類 | 2luv-ui | Stores temporary Google Analytics debug state for the current tab. | Browser tab session | browser only | analytics_storage | Deleted when analytics consent is revoked or by the full device/session cleanup action. | |
| localStorage | 偏好類 | 2luv-ui | Stores the selected light, dark, or system theme preference; system is resolved locally from the browser color-scheme setting. | until changed or cleared | browser only | functionality_storage | Deleted by the full device/session cleanup action. | |
| localStorage | 偏好類 | 2luv-ui | Legacy mirror of the selected language used by public controls. | until changed or cleared | browser only | functionality_storage | Deleted by the full device/session cleanup action. | |
| localStorage | 偏好類 | 2luv-ui | Stores recently opened gift and letter links in this browser so the landing page can resume the latest item after preference consent. | until changed, consent is revoked, or cleared | browser only | functionality_storage | Deleted when preference consent is revoked or by the full device/session cleanup action. | |
| localStorage | 行銷類 | 2luv-ui | Stores consented campaign and click identifiers for checkout attribution. | 90 days | browser only | ad_storage | Deleted when marketing consent is revoked or by the full device/session cleanup action. | |
| Cookie | 行銷類 | 2luv-ui | Preserves browser and advertising click identifiers for server-side Meta and TikTok conversions. Click cookies are created only after an actual ad click; no social pixel scripts are loaded. | 90 days | 2luv domain | ad_storage / ad_user_data | Deleted when marketing consent is revoked or optional browser data is cleared. | |
| Cookie | 行銷類 | 2luv-ui | Reads an existing TikTok browser identifier for consented server-side conversions. The current UI does not create or renew this cookie. | Existing cookie expiry | 2luv domain | ad_storage / ad_user_data | Deleted when marketing consent is revoked or optional browser data is cleared. | |
| sessionStorage | 偏好類 | 2luv-ui | Tracks promo cards shown during the current tab session to avoid repeated prompts. | browser tab session | browser only | functionality_storage | Deleted when the tab closes or by the full device/session cleanup action. | |
| sessionStorage | 偏好類 | 2luv-ui | Stores the keyboard state for the Termo interactive card during the current tab session. | browser tab session | browser only | functionality_storage | Deleted when the tab closes or by the full device/session cleanup action. | |
| network telemetry | 必要類 | Microsoft | Records sanitized server request routes, status, duration and failures for reliability and security operations without browser identifiers. | Azure project retention policy | Microsoft Azure / 2luv server | not browser consent-controlled; operational server telemetry | Managed through the Azure Application Insights retention policy. | |
| network telemetry | 分析類 | Sentry | Captures frontend errors and performance traces only after analytics consent. | provider-defined project retention | Sentry SaaS / 2luv domain | analytics_storage | Sentry loads only after analytics consent; optional browser data cleanup removes legacy Sentry Replay keys from earlier builds. | |
| Cookie | 行銷類 | Measures ad conversions and campaign attribution only when marketing consent is granted. | provider-defined, commonly up to 3 months | Google / 2luv domain | ad_storage, ad_user_data, ad_personalization | Deleted when optional cookies are rejected where browser access allows it. | ||
| network telemetry | 行銷類 | Sends normalized email or phone only as SHA-256 hashes for enhanced conversion matching after ad_user_data consent. | in memory until sent or consent is revoked; provider-defined retention after receipt | ad_user_data | Queued user_data is cleared when marketing consent is denied; raw contact values are never sent through the Google tag. | |||
| Third-party embed | 行銷類 | Music provider | Loads third-party media previews after marketing consent or when the visitor opens the provider directly. | provider-defined | third-party providers | ad_storage | Blocked until consent; provider data must be managed with the provider. | |
| HTTP cache | 必要類 | 2luv-api | Caches public, non-sensitive metadata briefly for performance and availability. | 60 seconds browser, up to 1 hour stale revalidation depending on endpoint | browser/CDN | not consent-controlled | Browser cache can be cleared from browser settings. | |
| HTTP cache | 必要類 | 2luv-api | Sensitive responses are marked private or no-store to avoid shared caching. | no-store or private short-lived | browser only | not consent-controlled | No shared cache should retain these responses. | |
| CDN cache | 必要類 | 2luv edge | Caches versioned public assets so pages load quickly without storing visitor profile data. | 7 days to 12 months depending on asset type | browser/CDN | not consent-controlled | Browser cache can be cleared from browser settings. | |
| Server memory | 必要類 | 2luv-api | Short-lived server-side caches reduce repeated API and media work without being written to the visitor browser. | 10 seconds to 6 hours depending on cache | 2luv-api memory | not consent-controlled | Expires automatically on TTL or process restart. | |
| Database | 必要類 | 2luv-api | Keeps short operational state required for uploads, edit sessions and payment safety. | 5 minutes to 24 hours where TTL exists; payment safety records follow backend retention | 2luv database | security_storage | Backend retention and operational cleanup, not browser cookie cleanup. |
6. 如何行使你的權利
在適用情況下,你可以聯絡我們以請求資訊並行使你的隱私權利(例如:確認處理、訪問、更正、匿名化、可攜性、刪除以及撤回同意)。
聯絡方式:contact@2-luv.com。
7. Cookie 政策的變更與修改日期
我們可能會更新本 Cookie 政策,以反映服務、技術或法律義務的變化。當出現重要變更時,我們會更新本頁頂部的「最後更新」日期。