Cookie Policy
Last updated: August 21, 2026
1. What Are Cookies
Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work, remember your preferences, and provide usage information. We also use browser localStorage, which serves a similar purpose but stores data locally on your device without transmitting it to our servers on every request.
This Cookie Policy explains what cookies and similar technologies the Day Spa Data platform ("the Service") uses, why we use them, and your choices regarding their use.
2. Essential Cookies
These cookies are strictly necessary for the Service to function. They cannot be disabled without breaking core functionality. No consent is required for essential cookies.
| Cookie / Storage | Purpose | Duration | Type |
|---|---|---|---|
| sb-* | Supabase authentication tokens that maintain your login session | Session, refreshed while active | Essential |
| active-owner | Signed cookie storing the currently selected organization for users with access to more than one. Cleared when you sign out or switch organizations | 1 year | Essential |
| impersonation | Signed cookie enabling a support administrator's time-limited impersonation session (set only for our administrators) | 2 hours | Essential |
| dsd_pwset | Short-lived signed grant used while you set or reset your password | 20 minutes | Essential |
| dsd_pref_uid | Stores your user ID and selected organization, so that on a shared computer another person signing in gets their own view preferences instead of yours, and switching organizations clears the previous one's location selection | 1 year | Essential |
3. Preference Cookies
These cookies store your dashboard view preferences — which locations you have selected, your date range and comparison settings, and which tab or view you last used on certain pages. They are sent to our servers with each request so pages can render with your selections already applied. They contain view-state only (location IDs, dates, tab names), not personal information.
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
| dsd_location_ids | Your selected locations | 1 year | Preference |
| dsd_period_start / dsd_period_end / dsd_period_preset | Your selected reporting date range or preset (e.g. "This Month") | 1 year | Preference |
| dsd_comparison_type / dsd_comparison_custom_range | Your selected comparison period settings | 1 year | Preference |
| dsd_home_view / dsd_retention_service_categories / dsd_rebooking_service_categories / dsd_rebooking_tab | Per-page view choices (home layout, category filters, active tab) | 1 year | Preference |
4. Analytics Cookies
We use PostHog for product analytics. PostHog sets cookies and uses localStorage to record page views, feature usage, and basic account identifiers (email, name, role), which helps us understand how the Service is used and prioritize improvements. Analytics traffic is routed through our own domain to PostHog's US cloud. PostHog also records session replays of the Service — a reconstruction of navigation, clicks and scrolling. We configure it not to transmit the page content that identifies a person: the columns and fields holding client and employee names, every form field, and the screens showing client or employee detail are masked in your browser before the replay is sent, as is any email address, phone number or long numeric code wherever it appears. The rest of the interface — headings, menus, buttons, dates, service names and summary figures — is recorded as shown. Console output and network request bodies are not recorded. Replays are retained for 30 days.
| Cookie / Storage | Purpose | Duration | Provider |
|---|---|---|---|
| ph_* | PostHog analytics: distinct user ID, session identifier, feature flags | 1 year | PostHog |
5. Error Monitoring and Session Replay
We use Sentry to capture client-side JavaScript errors and to record replays of sessions in which an error occurs, plus a small random sample (about 10%) of sessions for product-quality purposes. Replays are configured to mask all user-facing text, form inputs, and media so that personally identifiable content rendered in the dashboard is not transmitted to Sentry. Sentry keeps its session state in browser storage rather than long-lived cookies.
6. Local Storage
We use browser localStorage to store dashboard preferences on your device. This data is not transmitted to our servers and remains entirely on your device.
| Key | Purpose |
|---|---|
| theme | Your preferred color theme (light, dark, or system) |
| dsd_sidebar_sections | Which navigation sidebar sections are expanded or collapsed |
| hospMinOnFloor / hospGuestsPerConcierge | Hospitality staffing settings on the team hospitality page |
7. Managing Cookies
Most web browsers allow you to control cookies through their settings. You can typically find these settings in your browser's "Preferences" or "Settings" menu under "Privacy" or "Cookies."
Please note that disabling essential cookies will prevent you from logging in and using the Service. Clearing preference cookies or localStorage will reset your dashboard view settings to their defaults.
For more information about cookies and how to manage them, visit allaboutcookies.org.
8. Changes to This Policy
We may update this Cookie Policy from time to time to reflect changes in the cookies we use or for other operational, legal, or regulatory reasons. The "Last updated" date at the top of this page indicates when the policy was last revised.
9. Contact
For questions about our use of cookies, contact us at:
Day Spa Data LLC
Email: legal@dayspadata.com