Cookie Policy
Version: 1.0 Effective: 14 September 2026
BoothApps.ai is operated by Innova.uno Sp. z o.o., Byslawska 84, 04-993 Warsaw, Poland (KRS 0000417704, NIP PL5213629718, REGON 146081689). In this policy "we", "us" and "our" mean that company, and "you" means anyone who visits our site.
This policy explains what we store on your device, what we read from it, why we do it, and how you control it. It covers the public website boothapps.ai, the signed-in customer dashboard, the payment overlay our payment provider runs on our pages, and the feedback portal at feedback.boothapps.ai.
How we handle personal data in general, and how you exercise your rights, is described in our Privacy Policy. The providers we work with are listed in the Subprocessor Register.
1. What cookies and similar technologies are
Cookies are small text files a site asks your browser to keep. The browser sends them back with later requests, which is how a site can tell that it is still you between one page and the next.
Local storage is a browser feature that lets a site keep small pieces of data on your device. It is not sent automatically with every request, but the law treats it the same way as cookies: storing anything on your device, or reading anything from it, needs either strict necessity or your consent.
Scripts are pieces of code a page loads and runs in your browser. A script can set cookies, write to local storage, and send information to the server it came from. Loading a script from another company's server always reveals your IP address and basic request information to that company, even if the script itself stores nothing.
Pixels are tiny images or requests used to signal that a page was opened. We do not use advertising or social media pixels.
First party means set by boothapps.ai. Third party means set by another company whose script or frame runs on our pages, such as Google, Cloudflare or Paddle.
2. Legal basis
Two sets of rules apply at the same time.
Storing and reading information on your device. Article 5(3) of the ePrivacy Directive (2002/58/EC), implemented in Poland by Article 399 of the Electronic Communications Law of 12 July 2024 (Prawo komunikacji elektronicznej), allows us to store or read information on your device only if you have consented, or if doing so is strictly necessary to deliver the service you asked for. We rely on that exception (Article 399 sec. 3 point 2) only for the items marked Required in the table below: without them you could not sign in and stay signed in, submit a form that is protected against automated abuse, complete a payment, or have your cookie choice remembered. We read the exception strictly. Convenience, measuring how the site is used, and attributing a sale are not strict necessity. We ask for consent for analytics and for browser error tracking. Two items are neither marked Required nor gated by the banner today: the dashboard interface preference and the affiliate referral code, both described in section 4. This policy discloses them as they are, rather than describing a gate that does not exist.
Processing the personal data involved. Where an item also involves personal data, the GDPR applies on top. Required items rest on our legitimate interest in operating and securing the service and, once you are signed in, on the performance of our contract with you (Article 6(1)(b) and 6(1)(f) GDPR). Analytics and browser error tracking rest on your consent (Article 6(1)(a) GDPR). Consent can be withdrawn at any time, and withdrawal does not affect what happened before it.
Your consent record. When you make a choice on the consent banner we store it in your browser under the key cookie_consent, together with the date and time. The record stays on your device. It is not sent to us or to anyone else.
3. How the consent banner works
On your first visit a banner appears at the bottom of the page. It offers two choices:
- Accept All turns on every optional category.
- Manage Preferences opens a dialog with the categories listed below and two buttons: Only Required, which refuses everything optional, and Save Preferences, which stores exactly the selection you made.
The optional switches in that dialog currently open in the on position. If you press Save Preferences without changing them, you accept both optional categories. Switch them off before you save to refuse them, or press Only Required, which refuses both in one step.
The categories are:
| Category | What it covers | Can it be switched off? |
|---|---|---|
| Required | Sign-in and session, the consent record, form security, payment | No, the service does not work without it |
| Interface preferences | Small records of what you dismissed or collapsed in the signed-in dashboard, such as the affiliate information banner | Not offered in the banner. They are written only after you act, hold no identifier, and are not used to measure or attribute anything. Clearing site data removes them |
| Analytical | Browser error tracking (GlitchTip), self-hosted on our own servers | Yes, and the switch opens on, so refuse it before saving if you do not want it |
| Analytics | Google Analytics 4 visitor statistics | Yes, and the switch opens on, so refuse it before saving if you do not want it |
Google Analytics and Consent Mode. We use Google Consent Mode v2. Before the Google tag loads, we set analytics_storage and ad_storage to denied. The Google tag script itself is loaded from Google's servers on every page, whatever you choose, so Google receives your IP address and basic request information as the recipient of that request. While consent is denied, Google states that the tag does not read or write Google Analytics cookies and sends consent-state signals without cookie-based identifiers. We cannot independently verify what Google does with those signals, and we do not describe them as anonymous. If you accept the Analytics category, we switch analytics_storage to granted, the Google Analytics cookies described below are set, and normal measurement begins. We use no Google advertising features, so advertising storage is never granted.
Error tracking. The GlitchTip browser SDK starts only if you accepted the Analytical category, and the check is made when the page loads. If you accept during a visit, error tracking begins on your next page load.
Withdrawing or changing your choice. Clear the site data for boothapps.ai in your browser (see section 6). That removes the consent record together with the optional cookies, and the banner appears again on your next visit so you can choose differently. Refusing the optional categories has no effect on the service: everything you paid for works the same.
4. What we store and read
| Name / key | Type | Set by | Purpose | Category | Duration |
|---|---|---|---|---|---|
sb-<project>-auth-token, plus numbered variants such as .0 and .1 when the token is split | Cookie, HttpOnly | boothapps.ai (Supabase Auth) | Keeps you signed in, refreshes your session, and lets us end it when you sign out | Required | Your signed-in session, subject to our session policy of 14 days of inactivity and 60 days in total |
cookie_consent | Local storage | boothapps.ai | Records which optional categories you accepted, and when | Required | Until you delete it, no automatic expiry |
affiliate_banner_dismissed | Local storage | boothapps.ai | Remembers that you closed the affiliate information banner in the dashboard | Interface preference, not gated by the banner, see section 2 | Until you clear site data |
Google tag (gtag.js) | Third-party script | Loads the measurement tag and applies the consent state described in section 3 | Loaded on every page, measurement only after consent | Not stored on your device | |
_ga, _ga_<container> | Third-party cookies | Distinguish visitors and sessions for visitor statistics | Analytics, consent required | As documented by Google, up to 2 years | |
| GlitchTip browser SDK | First-party script | boothapps.ai | Sends browser error reports through our own endpoint /api/glitchtip-tunnel to our self-hosted GlitchTip server in Germany, so that we can fix faults. No third party receives them | Analytical, consent required | Sets no cookie and stores nothing on your device |
| Cloudflare Turnstile script and challenge state | Third-party script, and cookies of the cf_clearance type where Cloudflare's documentation provides for them | Cloudflare | Tells humans from automated scripts on the sign-in, registration, password reset, waitlist and contact forms, and issues a single-use verification token | Required, security | The token is valid for minutes; any cookie Cloudflare sets lasts as documented by Cloudflare |
boothapps_referral_code | Local storage | boothapps.ai | Remembers the affiliate code from the link you arrived through, so that a later purchase is credited to that affiliate | Attribution, not gated by the banner, see the note below | 30 days, or until you clear site data |
| Paddle checkout cookies | Third-party cookies, inside Paddle's own payment frame | Paddle | Run the payment form, keep your checkout session and prevent payment fraud. Paddle publishes no per-cookie list for its checkout frame, and describes them as necessary to operate and secure the checkout | Required, payment | As described in Paddle's notice |
| Feedback portal session cookie | Cookie on feedback.boothapps.ai | Innova.uno Sp. z o.o. (self-hosted Fider) | Keeps you signed in to the feedback portal after you sign in there | Required | Your portal session |
About the referral code. If you open a link that carries an affiliate code, we write that code into your browser's local storage straight away, before any choice on the consent banner, and we record the click on our server with a one-way hash of your IP address, your browser user agent, the referring address and the page you landed on. The code serves one purpose only: crediting the affiliate who referred you. It is not used for advertising or profiling, it does not follow you to other sites, and it is not combined with the analytics data described above. You can delete it at any time by clearing site data for boothapps.ai.
Our web fonts are served from our own servers, so no font provider is contacted. We run no chat widget, no advertising or social media pixel, and no website analytics other than the Google Analytics entry above.
5. Third parties and international transfers
| Provider | What it does here | Where | Its notice |
|---|---|---|---|
| Google (Google Ireland Limited and Google LLC) | Google Analytics 4, only after you consent. Data may be processed in the United States | Global, including the USA | policies.google.com/privacy |
| Cloudflare, Inc. | Turnstile form protection, plus content delivery and DNS for our sites | Global network | cloudflare.com/privacypolicy |
| Paddle (Paddle.com Market Limited for customers in the EEA and the United Kingdom, Paddle.com Inc. for customers in the United States) | Merchant of record for our sales. Paddle runs its own checkout frame on our pages, sets its own strictly necessary cookies there for the payment and for fraud prevention, and is an independent controller of the data it collects at checkout | United Kingdom and the United States | paddle.com/legal/privacy |
| Supabase | Authentication and the database behind the dashboard, which is what the sb- cookies belong to | European Union hosting | supabase.com/privacy |
Our error tracking and our feedback portal are self-hosted on our own servers in Germany, so error reports and feedback accounts stay with us.
Where a provider processes personal data outside the European Economic Area, the transfer rests on the mechanism recorded for that provider in the Subprocessor Register, which also states each provider's role and the data it receives. The Register is the complete list. This section names only the providers involved in storage on your device.
6. Managing cookies in your browser
Every current browser lets you see, block and delete cookies and site data, either for all sites or only for boothapps.ai. The controls are usually under Settings, then Privacy and security, then Cookies and site data. In most browsers you can also open the site information control next to the address bar and clear the data for the site you are on.
- To withdraw your consent here, clear cookies and site data for boothapps.ai. The consent record, the Google Analytics cookies and the referral code are removed together, and the banner returns.
- Private or incognito windows discard everything when you close them, so the banner appears in each new session.
- Browser do-not-track and global privacy control signals are not read by our banner. Your choice in the banner is what governs.
- Google Analytics can also be blocked for every site with Google's opt-out browser add-on.
If you block the Required items, the service stops working in predictable ways: you cannot sign in or stay signed in, protected forms may refuse to submit, checkout may not open, and your cookie choice cannot be remembered, so the banner reappears on every page. Blocking the optional categories costs you nothing.
7. Changes to this policy and contact
We update this policy when we add, remove or change a tool that stores or reads information on your device. The version and effective date at the top always show which text is current. Where a change affects the optional categories, we will ask for your consent again.
Questions about this policy, or about anything our sites store on your device:
Innova.uno Sp. z o.o. Byslawska 84, 04-993 Warsaw, Poland support@boothapps.ai
You can also lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.