Cookie & Storage Policy
Effective Date: March 25, 2026 · Last Updated: March 25, 2026
This policy explains how eFoilCrew ("we," "us," or "our") uses cookies, local storage, and similar technologies when you visit or use our Service. It should be read alongside our Privacy Policy.
1. What Are Cookies & Local Storage?
Cookies are small text files stored on your device by your web browser. Local storage (localStorage and sessionStorage) is a browser feature that allows websites to store data on your device. Both are used to remember preferences, maintain sessions, and understand how the Service is used.
eFoilCrew is a progressive web application (PWA) and relies more heavily on browser local storage than traditional cookies. We also register a service worker for offline functionality.
2. Essential Storage (No Consent Required)
These are strictly necessary for the Service to function and cannot be disabled:
| Name / Key | Type | Purpose | Duration |
|---|---|---|---|
| Supabase auth tokens | Cookie | Authentication session management | Session / refresh token lifetime |
theme | localStorage | Stores your light/dark theme preference | Persistent |
palette | localStorage | Stores your colour palette preference | Persistent |
waterBg | localStorage | Stores your background animation preference | Persistent |
cardDisplayMode | localStorage | Session card visual mode preference | Persistent |
sessions-view-preference | localStorage | Timeline layout preference | Persistent |
haptics-enabled | localStorage | Haptic feedback preference (touch devices) | Persistent |
| UI hint markers | localStorage | Track which onboarding tips you've seen (e.g., heatmap magnifier, altitude hint) | Persistent |
| Card size preferences | localStorage | Per-view card size settings (year/month/spot) | Persistent |
| Service Worker cache | Cache API | Offline asset caching for PWA functionality | Until cleared |
3. Analytics Storage (Consent Required)
Analytics identifiers are set when you opt in via the consent banner. The consent-record entries in the table below are written whichever way you answer: they exist so we can remember your answer and act on it, including when that answer is no. Read-only demo sessions, described under the table, run analytics without a banner answer at all.
| Name / Key | Type | Purpose | Duration |
|---|---|---|---|
analytics-consent | localStorage | Records your consent choice (accepted/declined) | Persistent |
__ph_opt_in_out_… | localStorage | Records the answer you gave PostHog, so the library honours it. Written once you answer, whichever way, and when a read-only demo session starts; holds no identifier | Persistent |
| PostHog cookies & identifiers | Cookie + localStorage | Behavioural analytics, event tracking, and session replay linked to your account | 12 months |
Read-only demo sessions
If you open eFoilCrew through a shared demo link, analytics and session recording start with the demo. You are told rather than asked: the demo banner says that demo sessions are recorded, and it stays on screen for the whole visit. Your answer to the consent banner does not control any of this. The banner is suppressed once the demo chrome loads, and if it appears before that, declining it does not stop the recording. PostHog writes its cookie and its localStorage entry for the visit, and the visit is identified by a random identifier minted when the link is opened. Where that identifier is not available, the visit is attached to the shared demonstration account instead, which belongs to no individual.
A demo link is sent to a named business contact who holds no account with us, and a demo session shows a prepared demonstration account rather than your own riding data. Section 2.8 of our Privacy Policy describes what we collect during one. Where the rest of this policy says what your answer to the banner controls, it is describing a visit that is not a demo session.
On our main pages and inside the app the analytics library is not loaded at all until you accept, so PostHog writes no cookie and no identifier to your device there. Our standalone press pages do load it, to count page views, but they keep it in memory rather than writing an identifier to your device.
On our main pages and inside the app, ignoring the banner leaves the analytics library unloaded and creates no PostHog cookie or identifier. If you decline, we store the consent-record entries in the table above, which record the refusal: no identifier, no analytics cookie, nothing that can be used to recognise you.
Some session-storage entries are written whatever you answer, and are erased when you close the tab: sentryReplaySession for error reporting, and efc-attribution for recording which link brought you here. Section 4 describes them. The consent banner itself is shown once you open the app, not on our public pages, because nothing on a public page needs an answer.
4. Session Storage
We use browser sessionStorage (which is automatically cleared when you close the tab) for temporary UI state such as map view position and other interface state. Session storage is not shared across tabs and does not persist between visits.
Some entries there are worth describing by name, because unlike the analytics storage in section 3 they are written whether or not you have answered the consent banner. They are erased when you close the tab.
sentryReplaySession is written by our error reporting when a page loads, whether or not anything has gone wrong. It holds a random identifier for the current tab, so that if the site does break, the recording of the moments before the failure is not cut in half. It carries no account, name or email, and it is not used for analytics. Error reporting is described in section 2.9 of our Privacy Policy.
efc-attribution is written if you arrive on a link that carries campaign parameters, or from another site. It keeps those two facts for the length of the tab so that a sign-up can record which channel it came from. We use session storage rather than a cookie deliberately: it is gone when you close the tab, it cannot follow you to another site, and it identifies nobody.
5. Third-Party Cookies
We do not use third-party advertising cookies. PostHog sets analytics cookies when analytics is running with durable storage on your device, and section 3 says when that is. Mapbox sets functional cookies for map tile loading. We do not allow any other third parties to set cookies through our Service.
6. Managing Your Preferences
Analytics Consent
You can accept or decline analytics on the consent banner shown the first time you open the app. To change your answer afterwards, at any time, use the Analytics toggle in your account settings. Turning it off stops collection straight away and records the refusal; turning it on has the same effect as accepting on the banner.
Browser Settings
Most browsers allow you to control cookies and local storage through their settings. You can block or delete cookies and clear local storage at any time. Note that blocking essential storage may prevent the Service from functioning correctly.
Service Worker
You can unregister the service worker through your browser's developer tools (Application > Service Workers) to stop offline caching.
7. Changes to This Policy
We may update this Cookie Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date.
8. Contact Us
If you have questions about our use of cookies and local storage, please contact us at privacy@efoilcrew.com.