This Cookie Policy explains the cookies, local storage and similar technologies used on kwashly.com and in the Kwashly web app, what each one does, how long it lasts, and how to change your mind at any time. It sits alongside our Privacy Policy, which describes how we handle personal data more generally. The Kwashly browser extension does not set cookies; the storage it uses is described in the last section of this page and, in more depth, in our Extension Privacy disclosure.
1. What cookies and similar technologies are
A cookie is a small text file that a website asks your browser to store and send back on later visits. First-party cookies are set by kwashly.com; third-party cookies are set by a service we embed, such as Stripe’s payment form. We also use two related technologies: local storage, which keeps data in your browser until it is cleared and is never sent automatically with requests, and session storage, which is wiped when you close the tab.
2. Categories we use
- Strictly necessary — sign-in, security, load balancing, fraud prevention on the payment page, and remembering your consent choice. These are always on, because the site cannot work without them, and they do not require consent.
- Functional — remembering your currency, language, and the trip you were last working on, so a half-planned itinerary is not lost when you refresh.
- Analytics — counting visits, understanding which parts of trip planning people abandon, and measuring whether a change made the product better. Set only with your consent.
- Marketing and attribution — measuring which campaign or partner referral led to a signup or a booking, so we can pay affiliate commission correctly and stop spending on channels that do not work. Set only with your consent.
3. Consent and Google Consent Mode v2
On your first visit you see a consent banner with three equally prominent choices: accept all, reject all, or manage preferences by category. Nothing in the analytics or marketing categories runs before you choose, and rejecting is a single click — we do not use a “reject” path that is harder than “accept”.
We implement Google Consent Mode v2. Until you consent, the Google tags on the page load in a restricted state: analytics_storage, ad_storage, ad_user_data and ad_personalization are all set to denied, no analytics or advertising cookies are written, and only cookieless, aggregated pings are sent so that totals are not silently attributed to the wrong channel. If you accept, the relevant signals switch to granted and the cookies in the table below are written. If you reject, the signals stay denied for the life of your choice. We do not use Google Ads remarketing audiences built from your behavior on the site.
4. How to change or withdraw your consent
Open Cookie preferences in the footer of any page. The panel shows your current choice per category with the date it was recorded, and saving a new choice takes effect immediately: newly denied cookies are deleted in the same page view. Your consent is stored for 12 months, after which we ask again. You can also block or delete cookies in your browser settings, though strictly necessary cookies are needed to stay signed in, and clearing them will sign you out and reset your preferences. If you would rather we handled it, email [email protected] or use our contact page.
5. Cookie and storage inventory
| Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
| kwashly_session | Kwashly (first party) | Keeps you signed in and ties the browser to your account session; carries a CSRF token | Strictly necessary cookie | 30 days |
| kwashly_consent | Kwashly (first party) | Stores your cookie consent choice per category, plus the timestamp and policy version | Strictly necessary cookie | 12 months |
| kwashly_trip | Kwashly (first party) | Holds the trip you are currently planning — destination, dates, traveler count — so the planner survives a refresh | Functional local storage | Persistent until you clear it or delete the trip |
| _ga | Google Analytics 4 | Assigns a pseudonymous client identifier to distinguish visitors | Analytics cookie | 24 months |
| _ga_<container-id> | Google Analytics 4 | Keeps session state for the Kwashly analytics property | Analytics cookie | 24 months |
| ph_<project-key>_posthog | PostHog EU | Product analytics: which planner steps are used, feature flags, funnel completion | Analytics cookie | 12 months |
| __stripe_mid | Stripe | Fraud prevention: identifies the device across payment attempts | Strictly necessary third-party cookie | 12 months |
| __stripe_sid | Stripe | Fraud prevention within a single checkout session | Strictly necessary third-party cookie | 30 minutes |
| _gcl_au | Google (conversion linker) | Links an ad click to a later signup or booking so conversions are counted once | Marketing cookie | 90 days |
| kwashly_ref | Kwashly (first party) | Records the affiliate, hotel or partner referral that sent you, so commission is paid to the right partner | Marketing cookie | 30 days |
Google Analytics is configured with IP truncation and without Google Signals or advertising features. PostHog runs on its EU (Frankfurt) infrastructure and is configured not to record keystrokes in form fields. Stripe’s cookies are written by the embedded payment form and only appear once you open checkout; they are classed as strictly necessary because card payment cannot be accepted safely without them, and they are not used for advertising. Plan prices and checkout details are on our pricing page.
6. What we do not use
We do not use advertising pixels from social networks, cross-site tracking cookies, device fingerprinting, or session-replay recordings of your screen. We do not sell personal data, and we do not allow our analytics providers to use Kwashly data for their own purposes.
7. Extension storage is not a cookie
The Kwashly browser extension for Chrome, Edge, Firefox and Safari uses the browser’s own extension storage area, not cookies. It keeps three things there: your saved trips (destination, check-in and check-out dates, packing preference), a wallet token that lets the extension show your loyalty balance without asking you to sign in again, and your extension settings such as currency and whether the pack-lighter prompt is shown. This storage is readable only by the extension itself, is never sent to websites you visit, and is not used for tracking or advertising. Uninstalling the extension removes it; signing out clears the wallet token. The extension reads only the destination city, property or airport locality, check-in and check-out dates, and the baggage add-on price when a supported booking page shows one — see the Extension Privacy disclosure for the permission-by-permission detail.
8. Changes to this policy
We review this inventory every quarter and whenever we add or remove a third-party service. If a new cookie is introduced in the analytics or marketing categories, we raise the policy version and ask for consent again before it is set. The version number and date at the top of this page always reflect the current inventory.
9. Questions
Write to [email protected], or to our Data Protection Officer at [email protected] (Marta Vieira), Kwashly Labs, Lda., Rua da Prata 12, 2.º andar, 1100-052 Lisbon, Portugal. Our Terms of Service and Accessibility statement are also available.