1. What cookies and storage technologies are
A cookie is a small piece of data stored by a website through your browser. Online services can also use local storage, session storage, pixels, tags, scripts, device identifiers and related methods to store information on, or access information from, a device.
These technologies can provide essential security and account functions, remember choices, keep an application state, measure use or support advertising. The purpose—not only the technology name—determines the notice, choice and legal treatment required.
2. Categories and choices
Security, authentication, billing flow, consent records and core timer state where necessary.
Timer choices, audio or interface preferences. Some may be exempt where used solely to adapt the requested service.
Enabled only under the consent or documented legal exception that applies to the actual live purpose and implementation.
UP Timer will provide clear information and a meaningful control for non-essential storage. Where consent is used, it should be as easy to reject or withdraw as it is to accept.
3. Current working inventory
The table describes the known or planned technology categories. It is not a substitute for a launch-day technical audit. Exact names, providers, purposes and lifetimes must be verified against the production domains.
| Technology / provider | Purpose | Typical duration | Choice position |
|---|---|---|---|
| Timer local or session storage | Remember timer settings, selected preferences, Lite-window timing and application state on the device. | Session, until replaced, until a defined expiry, or until browser storage is cleared—depending on the item. | Essential or preference depending on the exact purpose. Must be documented item by item. |
| Supabase authentication storage | Maintain sign-in sessions, refresh authentication and support account security. | Session or persistent according to the configured authentication session. | Strictly necessary for an account and requested sign-in. |
| Stripe hosted checkout and customer portal | Payment, fraud prevention, checkout, invoices and subscription management on Stripe-hosted pages. | Set by Stripe according to its service and policy. | Necessary for the payment or billing route requested. |
| Wocode / Duda website technologies | Deliver the marketing site, security, forms or platform functions. | To be confirmed by production audit. | Depends on the specific technology and purpose. |
| Consent preference record | Remember the cookie/storage choice and avoid repeatedly asking on every page. | For a proportionate period, then refreshed; exact duration to confirm. | Needed to record and honour the choice. |
| Google Analytics / Tag Manager, if enabled | Measure page and conversion events and improve the website/product experience. | Depends on the final configuration. | Optional unless a documented statutory exception applies and its conditions, including an appropriate objection mechanism, are met. |
| Vercel and security/hosting logs | Deliver requests, protect the service, diagnose faults and monitor availability. | Provider/configuration dependent. | Server logs are not always device storage, but are explained in the Privacy Policy. |
4. Timer settings and browser storage
The timer may store selected durations, working hours, water settings, movement settings, Learn Sprint choices, audio/voice preferences, Lite-window timing and other application state in your browser.
This can allow the timer to work or remember a choice without sending every setting to an account database. Browser storage is linked to the browser profile and device. Clearing it can reset settings or remove a locally held Lite-window record.
Do not attempt to alter browser storage to bypass Lite, trial, subscription or security controls. The service may also use server-side records to calculate entitlement.
5. Analytics and campaign measurement
Analytics may be introduced to understand page visits, CTA clicks, account creation, manual trial activation, Full subscriptions, Company interest and support contact. The implementation must minimise data, avoid collecting sensitive timer content unnecessarily and match the live consent or legal-exception design.
Marketing or behavioural advertising storage will not be treated as essential. It must not be enabled before the required choice is made.
6. Third-party services
Account, payment, hosting, email, analytics and embedded services can set or access their own technologies. Relevant providers may include Wocode/Duda, Vercel, Supabase, Stripe, Resend and Google services where enabled.
When you follow a link to a separately hosted checkout, portal or external service, that provider’s own policy and controls may apply. We remain responsible for making appropriate choices about technologies we place or cause to be placed on UP Timer pages.
7. How to manage your choices
- Use the UP Timer cookie or privacy control when it is displayed.
- Change optional categories without losing access to the core website.
- Use browser settings to view, block or delete cookies and site data.
- Clear local storage if you want to remove locally saved timer settings, understanding this can reset the application state.
- Use a private browser window for a separate temporary session, subject to browser behaviour.
Blocking strictly necessary storage can prevent account, security, timer-state or payment functions from working. Withdrawing optional consent does not affect the lawfulness of processing before withdrawal.
8. Production audit and changes
This policy is a launch working draft. Before publication, both uptimer.app and timer.uptimer.app must be tested in fresh browser sessions before and after each consent choice. The audit must include iframes, forms, authentication, Stripe routes, analytics, local storage, service workers and mobile behaviour.
We will update the inventory when technology, providers, purposes or retention changes. A material change may require a new notice or fresh choice.
9. Contact
Email questions about cookies, local storage or consent to privacy@uptimer.app. The Privacy Policy explains personal-information processing and rights.
