Cookie Policy
Last updated: August 27, 2026
1. Controller and scope
This Cookie Policy applies to Faviyo at faviyo.com and www.faviyo.com.
The controller is:
palmstudio GmbH
Pfalzgrafenstraße 38
67434 Neustadt an der Weinstraße
Germany
Email: support@faviyo.com
This Policy explains how Faviyo uses cookies and similar browser technologies, which technologies are necessary, which are optional, how long they can remain, and how you can change your choices.
For broader information about personal-data processing, see the Privacy Policy.
2. What cookies and similar technologies are
A cookie is a small text value stored by a browser for a website. Similar technologies include local storage, IndexedDB, software-development-kit identifiers, and other device storage or access mechanisms.
These technologies can be used to:
- maintain a secure authenticated session;
- remember a privacy choice;
- protect and operate a requested service;
- distinguish sessions or installations;
- measure website use after consent.
Browser storage can contain an identifier even when it does not contain a person's name. An identifier can still be personal data when it can be related to a device, browser, session, or account.
3. CookieHub consent management
Faviyo uses CookieHub site configuration e4c603e1 to request and manage consent on the two production hostnames.
CookieHub is loaded before optional application integrations and currently presents:
- Necessary, for technologies required to provide requested authentication, security, and consent-management functions; and
- Analytics, for optional Firebase Analytics.
Optional Analytics remains off until you allow that category. You can deny optional technologies and continue using Faviyo's core functionality.
CookieHub is deliberately not loaded on localhost, Vercel preview domains, staging hostnames, or other non-production hosts. Those environments therefore do not store choices in Faviyo's production CookieHub instance and do not initialize Firebase Analytics.
4. Necessary technologies
Necessary technologies are used to transmit communications, provide a service you expressly request, secure the service, maintain your signed-in session, and remember or demonstrate your privacy choice. They are not used for behavioral advertising.
CookieHub consent cookie
Name: cookiehub
Provider: CookieHub ehf. on behalf of palmstudio GmbH
Purpose: Stores the CookieHub configuration and categories you allowed or denied, together with a random token used to locate the associated consent record where consent logging is enabled.
Domain: faviyo.com, so the choice can apply consistently to the apex and www production hosts.
Type: First-party consent cookie.
Maximum duration: Up to 365 days from the relevant choice, unless removed earlier or the CookieHub configuration changes.
Legal classification: Necessary for administering, remembering, and demonstrating your privacy choice.
CookieHub consent log
Provider: CookieHub ehf., Iceland
Purpose: Allows palmstudio GmbH to demonstrate when and how a consent choice was recorded and to administer that choice.
Data: Random consent token, page URL, widget revision, categories, date and time, country, anonymized IP information, and browser/operating-system information.
Storage: CookieHub states that primary application and consent-log data is stored in the EEA. Its globally distributed delivery infrastructure can process technical request metadata at edge locations.
Maximum duration: Up to 12 months unless an applicable preservation duty or different lawful configuration requires otherwise.
Firebase Authentication browser storage
Provider: Google Firebase
Purpose: Creates and maintains the authenticated session you request, attaches authentication credentials to protected Faviyo requests, refreshes the session, and restores it between page visits.
Technology: Firebase can use browser mechanisms such as IndexedDB and local storage. Exact internal keys and storage choices can change with the Firebase SDK and browser capabilities.
Duration: Session information remains until sign-out, token expiry or replacement, Account deletion, browser-data clearing, or another Firebase security event. Some short-lived tokens rotate automatically.
Effect if blocked: Sign-in, session restoration, protected routes, or account features may not work correctly.
Security and technical state
Faviyo, Vercel, Firebase, and the browser can process transient network, cache, security, load-balancing, and request state needed to deliver the website and API. Not every transient value is a persistent cookie. Where persistent storage is introduced for a new necessary purpose, this Policy and CookieHub's declaration will be updated.
5. Optional Analytics
Firebase Analytics and Google Analytics cookies
Provider: Google Firebase / Google Analytics
Category: Analytics
Status before consent: Firebase Analytics is not initialized by Faviyo before the CookieHub Analytics category is allowed.
Purpose: Helps us understand aggregate website use, sessions, feature interactions, device categories, and technical problems so we can improve the experimental service.
Possible data: Page and session activity, configured interaction events, device and browser characteristics, operating system, language, approximate location inferred from network information, Firebase installation identifier, Analytics identifiers, consent state, and diagnostics.
Cookies:
_ga— distinguishes browser or analytics instances;_ga_*— maintains state associated with the configured Google Analytics property.
Maximum cookie duration: Approximately 400 days under the current CookieHub service declaration, unless consent is withdrawn, the cookies are deleted, or Google/Faviyo changes the lawful configuration.
Analytics-data retention: Faviyo's policy is not to configure user-level event retention for longer than 14 months. A shorter provider default or earlier deletion can apply. Aggregated reporting that no longer identifies an individual event may be retained longer.
Advertising: Faviyo does not currently use Firebase Analytics for third-party behavioral advertising, remarketing, or ad personalization.
6. Google Consent Mode
CookieHub's production configuration supports Google Consent Mode v2. Consent Mode communicates category choices in a standardized form to compatible Google services.
Faviyo additionally prevents Firebase Analytics initialization until Analytics is allowed. Therefore, the current Faviyo implementation does not rely only on a consent signal while loading Analytics in advance; the Analytics SDK itself is held back by the application until opt-in.
Faviyo does not currently use Google Ads through this implementation. If advertising or another Google tag is introduced, it must be classified, documented, and blocked or configured consistently before use.
7. External links and embedded provider data
Faviyo can display provider metadata and external links associated with Spotify, Geoapify, OpenStreetMap data, Google Maps, and websites added by users.
Displaying stored metadata or an ordinary link does not by itself authorize the destination to set optional cookies on Faviyo. When you actively follow an external link, you leave Faviyo and the destination may set its own cookies or browser storage under its own consent and privacy rules.
Faviyo does not currently embed a Spotify player, Google map, external video player, or social-media widget that is intended to place third-party marketing cookies on initial Faviyo page load. If such an embed is added, it must be reviewed and blocked until the relevant consent where required.
8. How to give, refuse, or change consent
On your first applicable production visit, CookieHub presents the available choices. You can:
- allow all available categories;
- deny optional categories;
- open settings and make a granular choice;
- use Faviyo without optional Analytics.
You can later reopen the preference center through Cookie settings in Faviyo's footer or Legal page. CookieHub can also expose a persistent privacy control depending on the published widget configuration.
Withdrawing Analytics consent causes Faviyo to:
- disable Firebase Analytics collection;
- remove accessible
_gaand_ga_*cookies for the Faviyo domain; - delete the Firebase installation created for the consented Analytics session;
- prevent future Analytics initialization unless Analytics is allowed again.
Withdrawal applies to future processing. It does not retroactively invalidate processing that occurred while consent was valid.
9. Browser and device controls
Most browsers allow you to inspect, block, or delete cookies and website data. Clearing the cookiehub cookie can cause the consent interface to appear again. Clearing Firebase Authentication storage can sign you out.
Blocking all storage may prevent Faviyo from remembering consent or maintaining an authenticated session. Browser settings operate independently of CookieHub and can be broader than the preference selected within Faviyo.
Some browsers or devices send Global Privacy Control or Do Not Track signals. CookieHub can apply recognized regional privacy signals according to its published configuration. Because standards and legal effects vary, you should also use Cookie settings for a direct Faviyo category choice.
10. Legal basis
Under Section 25(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG), storing or accessing information can occur without consent where it is strictly necessary to transmit a communication or provide a digital service expressly requested by the user. Faviyo relies on that rule for authentication, essential security, and consent-management storage to the extent applicable.
Optional Analytics storage and access is based on consent under Section 25(1) TDDDG. Associated personal-data processing is based on Article 6(1)(a) GDPR.
Necessary personal-data processing is based, depending on the purpose, on performance of the user contract under Article 6(1)(b) GDPR, compliance with legal obligations under Article 6(1)(c), or legitimate security and operational interests under Article 6(1)(f).
11. Providers and international processing
CookieHub ehf. is established in Iceland, within the EEA. Its primary application and consent-log data is stored in the EEA, while global delivery providers can process technical CDN request data.
Google provides Firebase Authentication and optional Firebase Analytics. Firebase Authentication is operated from US data centers, and Google services can use infrastructure outside the EEA. Where required, transfers rely on an applicable adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism described in the Privacy Policy.
12. Changes to technologies
We will update this Policy and the CookieHub configuration when Faviyo adds or materially changes a cookie, SDK, embed, browser-storage mechanism, analytics property, or other tracking technology.
Faviyo should run a new CookieHub production scan after relevant deployments. The live declaration below is maintained from CookieHub's published production inventory and may provide more specific cookie names and durations detected during the latest scan.
13. Contact
Questions about cookies, consent records, or Analytics withdrawal can be sent to:
palmstudio GmbH
Pfalzgrafenstraße 38
67434 Neustadt an der Weinstraße
Germany
Current cookie declaration
The live declaration below is maintained from Faviyo's CookieHub configuration and reflects the cookies detected for the production website.