Cookie Policy
Version 1.0 Last updated 29 July 2026 · applies to savedate.me and every invitation published on it
The short version
- We use four cookies, all our own. Every one of them is strictly necessary.
- No advertising cookies, no cross-site tracking, no data selling — ever.
- We set no analytics cookies today. The Analytics and Marketing switches in our banner are placeholders so that a future choice is honoured; leaving them on changes nothing right now.
- No device fingerprinting — no canvas hashing, no WebGL analysis, no hidden identification scripts, here or on any invitation page.
- Some pages load fonts, maps or videos from other companies. Those requests reveal your IP address to them — the services and the reasons are listed below.
1. What cookies are
A cookie is a small text file a website asks your browser to store and send back on later visits. Websites also use similar technologies — local storage and session storage — which keep data on your device but are never sent automatically with requests. This policy covers all of them, and should be read alongside our Privacy Policy.
Cookies set by the website you are visiting are called first-party. Cookies set by another company whose content is embedded in the page are third-party. All cookies we set are first-party.
2. Cookies we set
2.1 Strictly necessary Always active
These are required to sign you in, keep your account secure and remember your cookie choice. Under the ePrivacy rules they do not require consent, and they cannot be switched off while you use the service. They contain no advertising identifiers and are never used to profile you.
| Cookie | Purpose | Duration |
|---|---|---|
SAVEDATE_SESS |
Keeps your signed-in session and protects forms against cross-site request forgery. Holds a random identifier only — no name, email or password. It is also issued to visitors who are not signed in, because the same protection covers public pages and RSVP forms. | Session — removed when you close the browser |
SAVEDATE_TRUST |
Only if you use two-factor authentication and choose to trust a device: lets that browser skip the code next time. Holds a random token, which we store only in hashed form. Signing out removes it. | 7 days |
sd_dev |
Set when you sign in: a random token that lets us recognise a browser that has signed in to SaveDate before. Used only for account security and abuse prevention — for example, spotting one person operating several accounts to misuse the service. It contains no personal details, identifies the browser rather than you, and is never used for advertising, analytics or tracking on other websites. Only a one-way hash of it is stored on our side. | 2 years |
sd_consent |
Remembers the cookie choice you made in the banner so you are not asked on every visit. Stores the choice itself (for example "accept all" or "reject all") and nothing else. | 12 months |
2.2 Functional No cookies used
We set no functional cookies. Two small items are kept in your browser's local storage instead — they stay on your device and are not transmitted with page requests:
| Item | Purpose | Duration |
|---|---|---|
sd_vid local storage |
A random identifier for this browser, created when the cookie banner first appears. It links your consent record to the browser that gave it, so we can evidence the decision and group repeat decisions. It is not tied to your name and is not used for advertising or tracking across other websites. | Until you clear site data |
| Interface preferences local storage | Small editor and panel states, so the tool reopens the way you left it. | Until you clear site data |
2.3 Analytics No cookies used
We do not use Google Analytics or any other third-party analytics cookie, and we do not build visitor profiles. Invitation view counts shown to hosts are counted on our own server as simple totals — they are not stored against a cookie and cannot be traced back to an individual guest.
The banner still offers an Analytics option so that, if we ever add a privacy-friendly measurement tool, the preference you already expressed is respected from day one. Until that happens the switch has no effect.
2.4 Marketing and advertising No cookies used
We set no advertising or retargeting cookies, run no ad networks, and do not sell or share personal information for cross-context behavioural advertising. The Marketing switch is a placeholder on the same basis as Analytics above.
2.5 Device fingerprinting Never used
Some websites identify visitors without cookies by measuring how a device behaves — combining details such as how it renders graphics (canvas or WebGL "hashing"), which fonts are installed and how audio is processed into a signature unique enough to recognise the device again. We do not do this, on any page, and we do not buy or receive such fingerprints from anyone else. The connection details we do record on our public forms are described in section 2.4 of the Privacy Policy — they are ordinary server records, kept for security, not a fingerprint of your device.
3. Third-party services that receive your IP address
In the interest of full transparency: some features load files from other companies. We do not set cookies through them and we send them no account details, but any request your browser makes to another company necessarily reveals your IP address and basic browser information to it. Each service is used for the narrow purpose listed.
| Service | Used for | Where it appears |
|---|---|---|
| Google Fonts | Typefaces | Site pages and some invitation designs |
| jsDelivr | Delivery of a standard open-source interface library | Site pages |
| Google Sign-In | Signing in with a Google account, only if you choose that button. Google sets its own cookies on its own domains under its policies. | Sign-in page |
| YouTube (privacy-enhanced mode) | Playing videos a host has added. We use the no-cookie player, so YouTube sets cookies only once you press play. | Invitation pages with video |
| CARTO and OpenStreetMap | Map tiles in the venue picker | Editor only |
| Photon (Komoot) and Nominatim (OpenStreetMap) | Address search when a host looks up a venue | Editor only |
| GeoJS / ipwho.is | Approximate city from IP, used only to put nearby venues first in that search | Editor only |
Sharing buttons for WhatsApp, Facebook, X, LinkedIn and Google Maps directions are plain links. Nothing is sent to those companies unless you actually click one.
4. What guests experience
Someone who opens an invitation you send is treated as a visitor, not a tracked user. They receive the strictly necessary session cookie described in 2.1, which secures the RSVP and greeting forms. No advertising or analytics cookie is placed, and nothing they do is shared with other websites. Information they type into an RSVP or greeting is stored for the host of that invitation, as set out in our Privacy Policy.
5. How your consent is recorded
When you answer the cookie banner we keep a record of that decision so we can show it was freely given, as data-protection law requires. The record contains:
- the date and time, and the choice made, together with the categories accepted;
- the version of this policy in force at the time;
- your IP address and the country derived from it;
- your browser and operating system, as reported by your browser;
- the anonymous browser identifier described in 2.2, and the page you were on;
- your account, only if you were signed in at the time.
This record exists to evidence consent and to honour it — it is not used for marketing or profiling, and it is not shared with third parties for their own purposes. We keep it for as long as needed to demonstrate the decision, and no longer than 24 months after it is withdrawn or replaced.
6. Managing your choices
You can change your mind at any time:
- Change your choice below — update your categories right here, on this page.
- Your browser settings — every browser can block or delete cookies and clear local storage for a site. Because our cookies are strictly necessary, blocking them signs you out and may stop sign-in and RSVP forms from working. You can sign back in at any time.
- Global Privacy Control — we honour a GPC signal as an objection to any non-essential use. Since we set no advertising or analytics cookies, there is nothing further to opt out of.
7. Your rights in the EU, EEA and UK (GDPR)
Where the GDPR or UK GDPR applies to you, non-essential cookies are used only with your consent, and strictly necessary cookies rely on our legitimate interest in operating a secure service and on performing the contract you asked for. You have the right to:
- ask what personal data we hold about you and receive a copy;
- have inaccurate data corrected, and have data erased where the law allows;
- ask us to restrict processing, or object to processing based on legitimate interests;
- receive your data in a portable format;
- withdraw consent at any time — this is as easy as giving it, using the button above;
- complain to your national data-protection authority (in Ireland, the Data Protection Commission; in the UK, the ICO).
Withdrawing consent does not affect processing that already took place lawfully.
8. Your rights in California (CCPA / CPRA)
We do not sell personal information, and we do not share it for cross-context behavioural advertising, so there is no "Do Not Sell or Share My Personal Information" list to join. We do not use sensitive personal information to infer characteristics, and we offer no financial incentive in exchange for data. You still have the right to know what we collect, to request deletion or correction, and not to be discriminated against for exercising those rights. Requests are handled through the contact address below, and we will verify them against your account before acting.
9. Changes to this policy
If we add a cookie or a service that changes the picture above, we will update this page, raise the version number and — where the change requires consent — ask you again through the banner. The date at the top always shows when this text last changed.
10. Contact
Questions about cookies or a request about your data: support@savedate.me. Account and billing matters: accounts@savedate.me. We aim to reply within a few days, and within one month for formal data requests.
Cookie Preferences
Choose which categories you allow on this browser. Strictly necessary cookies keep SaveDate secure and working, so they stay on. Analytics and Marketing set no cookies today — your choice is stored and honoured if that ever changes.
Saving records the decision — date, choice, policy version and the details listed in section 5 — as proof of consent.