Cookie 政策 — 同意与偏好设置
1. 什么是 Cookie,以及我们如何使用
Cookie 是当你访问网站时由浏览器保存的小型文本文件。它们可以帮助记住偏好设置、保持关键功能正常运行,并在你允许的情况下衡量性能与营销活动效果。
在 2luv,我们主要使用 Cookie 来:(a) 记住你的同意选择;(b) 在部分页面提供功能与安全性(例如:受密码保护的内容);(c) 在你授权时衡量使用情况与转化。
2. Cookie 类型与用途
必要类:对安全与基础功能至关重要(例如:记住同意设置、验证受保护内容)。
功能类:提升体验并帮助导航(例如:记住最近访问的内容)。
偏好类:保存如语言等选择。
分析类:在启用时帮助衡量与理解网站使用情况(统计)。
营销类:在启用时帮助衡量活动与转化。
3. 我们如何收集同意以及保存时长
当你访问 2luv 时,我们会显示 Cookie 横幅,让你选择接受、拒绝或自定义偏好(例如:分析与营销)。
你的选择会被保存,以便在之后访问时继续尊重你的偏好。通常我们最多保存 12 个月(可能因浏览器设置而不同)。在某些情况下,我们也会使用浏览器的 localStorage 来保存偏好设置。
4. 如何拒绝 Cookie
你可以在横幅中直接点击“拒绝”来拒绝可选 Cookie,或在“自定义”中关闭相关类别。
你也可以在浏览器设置中管理 Cookie(阻止、删除或限制)。如果你删除 Cookie,部分偏好可能会被重置。
5. 我们使用哪些 Cookie
下方列表包含第一方 Cookie(由 2luv 设置)以及可能由第三方服务(分析/广告)设置的 Cookie/标识符。部分名称与保存时长可能会因提供方与浏览器而变化。
| 技术 | 类别 | 负责人 | 名称 | 用途 | 有效期 | 域 | Consent mode | 清理 |
|---|---|---|---|---|---|---|---|---|
| cookie / localStorage | 必要类 | 2luv-ui | 保存你的同意选择(包括 Consent Mode 偏好),以便我们在你未来访问时遵循你的选择。 | 12 个月 | 2luv domain | security_storage | Kept when optional data is rejected; reset when the visitor clears all browser data. | |
| Cookie | 必要类 | 2luv-ui | 在此浏览器中保持服务使用正确的语言、日期格式和阅读方向。 | 12 个月 | 2luv domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | 必要类 | 2luv-ui | 在此浏览器中保持价格、货币、套餐可用性和区域路由一致。 | 12 个月 | 2luv domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | 偏好类 | 2luv-api | 帮助快速继续访问你在此浏览器中最后打开的礼物/信件。 | 30 days | 2luv API domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | 必要类 | 2luv-api | 安全 Cookie(httpOnly),用于识别设备/浏览器并帮助保护访问与敏感操作。 | 12 months | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | 必要类 | 2luv-api | 绑定到此设备/浏览器的短期 HttpOnly 授权,用于刷新“查找我的礼物”结果,无需重复使用邮件验证码。 | 浏览器会话,最长 8 小时 | 2luv API 域名 | security_storage | 通过 API 执行完整的设备/会话清理时删除。 | |
| localStorage | 必要类 | 2luv-ui | 在此浏览器中临时记住已验证的“查找我的礼物”邮箱,以便在导航或重新加载后刷新结果。 | 有效期 8 小时;过期记录会在下次打开“查找我的礼物”时删除 | 仅此浏览器 | security_storage | 选择其他邮箱、到期或执行完整设备/会话清理时删除。 | |
| Cookie | 必要类 | 2luv-api | 认证 Cookie(httpOnly),用于保持对密码保护信件的访问,并允许与该内容相关的授权操作。 | 30 天 | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | 必要类 | 在情书搜索、联系、AI 辅助写作、媒体上传、情书创建和情书编辑过程中,帮助区分真人与自动化滥用。 | 最长 6 个月 | not consent-controlled; strictly necessary security | Loaded when the letter editor opens or a protected form is submitted; provider data must be managed through browser or Google settings. | |||
| Cookie | 分析类 | Google Analytics:帮助了解网站使用情况(汇总统计)、性能与导航,并遵循 Consent Mode。 | 最长 13 个月 | Google / 2luv domain | analytics_storage | Deleted when optional cookies are rejected where browser access allows it. | ||
| Cookie | 偏好类 | 2luv-api | Compatibility resume cookie name that the current letter API clears when deleting session state. | legacy/session | 2luv API domain | functionality_storage | Deleted by the full device/session cleanup action. | |
| Cookie | 必要类 | 2luv-api | Short-lived HttpOnly owner capability for legacy Gift edits. | Up to 30 days; recovered sessions use 1 hour | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | 必要类 | 2luv-api | HttpOnly view or owner capability for interactive Card collections. | Session or 30 days | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| Cookie | 必要类 | 2luv-api | Short-lived signed capability used to read one checkout payment status. | 24 hours | 2luv API domain | security_storage | Deleted by the full device/session cleanup action through the API. | |
| localStorage | 必要类 | 2luv-ui | Stores an unfinished create flow locally so a visitor can recover a draft before publishing. | 30 days after last save | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| IndexedDB | 必要类 | 2luv-ui | Stores draft photo blobs locally while a visitor is composing an unpublished gift or letter. | 30 days after last save | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| IndexedDB | 必要类 | 2luv-ui | Keeps private creation and editing drafts, local photos and confirmed operation receipts recoverable on this device; excludes passwords and access tokens. | 30 days after last save; expired checkpoints pruned on next use in bounded batches; photo bytes removed when no remaining checkpoint references them | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| localStorage / sessionStorage | 必要类 | 2luv-ui | Identifies the draft and the separate checkpoint for this editor to resume; neither is an authorization credential. | Until creation succeeds or browser data is cleared | browser only | security_storage | Deleted after successful creation or by the full device/session cleanup action. | |
| localStorage / sessionStorage | 必要类 | 2luv-ui | Resumes each Letter editor's private checkpoint without storing authorization credentials. | Until editing succeeds or browser data is cleared; at most 100 Letter pointers | browser only | security_storage | Deleted after confirmed editing or by full device/session cleanup. | |
| localStorage | 必要类 | 2luv-ui | Prevents duplicate create requests when a submission is retried. | Until creation succeeds or browser data is cleared | browser only | security_storage | Deleted after successful creation or by the full device/session cleanup action. | |
| sessionStorage | 必要类 | 2luv-ui | Keeps the latest create-flow lead and letter link available during payment continuation. | Until replaced or browser data is cleared | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| sessionStorage | 必要类 | 2luv-ui | Stores an unpublished WebMCP-assisted create draft in this browser. | Until published, replaced or browser data is cleared | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| sessionStorage | 必要类 | 2luv-ui | Legacy owner capability from older builds; current builds use HttpOnly cookies and never write this key. | Browser tab session | browser only | security_storage | Deleted by the full device/session cleanup action. | |
| sessionStorage | 分析类 | 2luv-ui | Stores temporary Google Analytics debug state for the current tab. | Browser tab session | browser only | analytics_storage | Deleted when analytics consent is revoked or by the full device/session cleanup action. | |
| localStorage | 偏好类 | 2luv-ui | Stores the selected light, dark, or system theme preference; system is resolved locally from the browser color-scheme setting. | until changed or cleared | browser only | functionality_storage | Deleted by the full device/session cleanup action. | |
| localStorage | 偏好类 | 2luv-ui | Legacy mirror of the selected language used by public controls. | until changed or cleared | browser only | functionality_storage | Deleted by the full device/session cleanup action. | |
| localStorage | 偏好类 | 2luv-ui | Stores recently opened gift and letter links in this browser so the landing page can resume the latest item after preference consent. | until changed, consent is revoked, or cleared | browser only | functionality_storage | Deleted when preference consent is revoked or by the full device/session cleanup action. | |
| localStorage | 营销类 | 2luv-ui | Stores consented campaign and click identifiers for checkout attribution. | 90 days | browser only | ad_storage | Deleted when marketing consent is revoked or by the full device/session cleanup action. | |
| Cookie | 营销类 | 2luv-ui | Preserves browser and advertising click identifiers for server-side Meta and TikTok conversions. Click cookies are created only after an actual ad click; no social pixel scripts are loaded. | 90 days | 2luv domain | ad_storage / ad_user_data | Deleted when marketing consent is revoked or optional browser data is cleared. | |
| Cookie | 营销类 | 2luv-ui | Reads an existing TikTok browser identifier for consented server-side conversions. The current UI does not create or renew this cookie. | Existing cookie expiry | 2luv domain | ad_storage / ad_user_data | Deleted when marketing consent is revoked or optional browser data is cleared. | |
| sessionStorage | 偏好类 | 2luv-ui | Tracks promo cards shown during the current tab session to avoid repeated prompts. | browser tab session | browser only | functionality_storage | Deleted when the tab closes or by the full device/session cleanup action. | |
| sessionStorage | 偏好类 | 2luv-ui | Stores the keyboard state for the Termo interactive card during the current tab session. | browser tab session | browser only | functionality_storage | Deleted when the tab closes or by the full device/session cleanup action. | |
| network telemetry | 必要类 | Microsoft | Records sanitized server request routes, status, duration and failures for reliability and security operations without browser identifiers. | Azure project retention policy | Microsoft Azure / 2luv server | not browser consent-controlled; operational server telemetry | Managed through the Azure Application Insights retention policy. | |
| network telemetry | 分析类 | Sentry | Captures frontend errors and performance traces only after analytics consent. | provider-defined project retention | Sentry SaaS / 2luv domain | analytics_storage | Sentry loads only after analytics consent; optional browser data cleanup removes legacy Sentry Replay keys from earlier builds. | |
| Cookie | 营销类 | Measures ad conversions and campaign attribution only when marketing consent is granted. | provider-defined, commonly up to 3 months | Google / 2luv domain | ad_storage, ad_user_data, ad_personalization | Deleted when optional cookies are rejected where browser access allows it. | ||
| network telemetry | 营销类 | Sends normalized email or phone only as SHA-256 hashes for enhanced conversion matching after ad_user_data consent. | in memory until sent or consent is revoked; provider-defined retention after receipt | ad_user_data | Queued user_data is cleared when marketing consent is denied; raw contact values are never sent through the Google tag. | |||
| Third-party embed | 营销类 | Music provider | Loads third-party media previews after marketing consent or when the visitor opens the provider directly. | provider-defined | third-party providers | ad_storage | Blocked until consent; provider data must be managed with the provider. | |
| HTTP cache | 必要类 | 2luv-api | Caches public, non-sensitive metadata briefly for performance and availability. | 60 seconds browser, up to 1 hour stale revalidation depending on endpoint | browser/CDN | not consent-controlled | Browser cache can be cleared from browser settings. | |
| HTTP cache | 必要类 | 2luv-api | Sensitive responses are marked private or no-store to avoid shared caching. | no-store or private short-lived | browser only | not consent-controlled | No shared cache should retain these responses. | |
| CDN cache | 必要类 | 2luv edge | Caches versioned public assets so pages load quickly without storing visitor profile data. | 7 days to 12 months depending on asset type | browser/CDN | not consent-controlled | Browser cache can be cleared from browser settings. | |
| Server memory | 必要类 | 2luv-api | Short-lived server-side caches reduce repeated API and media work without being written to the visitor browser. | 10 seconds to 6 hours depending on cache | 2luv-api memory | not consent-controlled | Expires automatically on TTL or process restart. | |
| Database | 必要类 | 2luv-api | Keeps short operational state required for uploads, edit sessions and payment safety. | 5 minutes to 24 hours where TTL exists; payment safety records follow backend retention | 2luv database | security_storage | Backend retention and operational cleanup, not browser cookie cleanup. |
6. 如何行使你的权利
在适用情况下,你可以联系我们以请求信息并行使你的隐私权利(例如:确认处理、访问、更正、匿名化、可携带、删除以及撤回同意)。
联系方式:contact@2-luv.com。
7. Cookie 政策的变更与修改日期
我们可能会更新本 Cookie 政策,以反映服务、技术或法律义务的变化。当出现重要变更时,我们会更新本页顶部的“最后更新”日期。