§ 1.0What is a cookie?
A cookie is a small text file a website asks your browser to store. Some are essential to making a site work (you literally can't sign in without a session cookie); others are optional and used for analytics or personalization. We split ours into three buckets — strictly necessary, functional, and analytics — and ask you to opt in to anything beyond strictly necessary.
§ 2.0Categories we use
Three categories, no advertising/targeting cookies. We don't run a third-party ad pixel; the marketing site has no Meta, X, TikTok, or LinkedIn tags.
- Strictly necessary — required for login, security, and event-day operation. Always on; cannot be disabled in the banner because the platform won't work without them.
- Functional — remember your preferences (theme, density, time format, language).
- Analytics — first-party, aggregated. We use a self-hosted analytics stack; no data leaves WayHopper-controlled infrastructure.
§ 3.0Full cookie inventory
Updated for revision v3.0. If you see a cookie set in your browser that's not in this table, please let us know.
| Name | Category | Purpose | Expires |
|---|---|---|---|
wh_session | Necessary | Authenticated session token (httpOnly, secure, SameSite=Lax). Required to stay signed in. | Session |
wh_csrf | Necessary | CSRF protection token. Rotates each session. | Session |
wh_event_offline | Necessary | Supports offline check-in recovery in the WayHopper app when signal drops (finish when back online). | Session / short-lived |
wh_pref_palette | Functional | Remembers your palette choice (brand / ink / stark). | 12 months |
wh_pref_density | Functional | Remembers the dashboard table density. | 12 months |
wh_pref_locale | Functional | Remembers your language & currency. | 12 months |
wh_a_id | Analytics | First-party anonymous visitor ID. Resets every 7 days; never linked to your account. | 7 days |
wh_a_session | Analytics | First-party session bucket. Aggregated funnel metrics only. | 30 minutes |
wh_cc | Necessary | Stores your cookie-banner choices. Required so we don't re-prompt you. | 12 months |
§ 4.0Third-party scripts
The marketing site loads two third-party scripts, both opt-in via the banner:
- Cal.com — embedded only on the Book Demo page. Sets one session cookie scoped to the embed iframe. Drops on close.
- Vimeo — used to embed demo videos on platform pages. Sets
playercookie when you press play; we use "do-not-track" mode by default.
The operator dashboard loads only first-party assets. No third-party JS runs there.
§ 5.0Local storage & similar technologies
The WayHopper app may use on-device storage to support offline check-ins when signal drops (photo at the stop, finish when back online). That is a recovery path for dead spots—not a fully offline maps mode. This storage is used to operate the event experience and is not sold to third parties.
§ 6.0How to control cookies
You can manage cookies in three places:
- The cookie banner on first visit. You can reopen it any time via the "Cookie preferences" link in the footer.
- Your browser settings. All modern browsers let you block or clear cookies per-site.
- The Privacy pane inside your account settings — for signed-in users, this is the canonical control.
If you block strictly necessary cookies, the platform will not function (you can still browse marketing pages).
§ 7.0Do Not Track & Global Privacy Control
We respect the Global Privacy Control (GPC) signal — if your browser sends GPC, we treat it as a withdrawal of consent to analytics and functional cookies, the same as a "Reject all" click in the banner. We also honor the older "Do Not Track" header.
§ 8.0Changes & contact
We update this page when we change what we use. Material changes (e.g. adding an analytics provider, adding any third-party script to the dashboard) trigger a re-prompt of the cookie banner for all users.
Cookie preferences
Reopen the banner from the footer link, or visit your account settings → Privacy.
If you've blocked our analytics, you'll see no behavioral difference — they don't gate any functionality.
Cookie Policy — printable PDF
The exact text on this page, paginated and signed.
Version history
| Version | Effective | Summary of changes |
|---|---|---|
| v3.0 | 2026-03-01 | Added GPC support, self-hosted analytics stack, removed Plausible and final third-party tags. |
| v2.4 | 2025-08-12 | Cookie banner refreshed; granular per-category opt-in. |
| v2.2 | 2025-01-22 | Removed Hubspot embed from marketing site; cookies retired. |
| v2.0 | 2024-05-01 | Cookie banner introduced for non-EU regions for parity. |
| v1.5 | 2023-09-12 | Added Vimeo / Cal.com disclosure. |