Cookie policy
Last updated 2026-01
The short version
We set two cookies, both strictly necessary for the site to work. There are no advertising cookies, no analytics cookies and no third-party trackers — which is also why you are not being asked to click through a consent banner.
What we set
| Name | Purpose | Lifetime |
|---|---|---|
iiytp_session |
Keeps you signed in to the dashboard. It holds a random token only — no personal data — and is marked HttpOnly, Secure and SameSite=Lax. Guests never receive it. | 30 days, or until you sign out |
iiytp_csrf |
Protects forms against cross-site request forgery. It has to be readable by the page so the value can be echoed back with each submission. | 12 hours |
On event websites
Opening an invitation or an event website sets only the CSRF cookie, and only so that RSVP and upload forms can be submitted safely. No cookie is used to identify or follow a guest.
Third parties
Event websites load fonts from Google Fonts, which means your browser
contacts fonts.googleapis.com and fonts.gstatic.com.
Google states that Fonts sets no cookies. If you take payments, the
checkout runs on the payment provider's own domain under their cookie policy.
Controlling cookies
You can clear or block cookies in your browser settings. Blocking the two above will stop you signing in and stop forms submitting, because both are required for those things to work at all.
Analytics
Event organizers can see how many people opened an invitation and viewed the page. Those counts come from the invitation link itself and from records we already hold to run the event — not from a cookie, a pixel or a third-party script. Read more in the privacy policy.