Skip to main content
MyEventScape

Legal

Cookie notice

MyEventScape sets three kinds of cookie, all of them necessary to run the service. There is no advertising, no analytics vendor, and no cross-site tracking anywhere on this site.

Last updated August 21, 2026

Why there is no cookie banner

Consent banners exist because most sites load cookies that serve someone other than the visitor. We do not. Every cookie described below is strictly necessary to deliver a service you asked for — signing in, accepting an invitation, remembering a layout choice — which is the narrow category that does not require prior consent under the ePrivacy Directive and comparable rules. If we ever add anything outside that category, we will ask first.

What we set

CookiePurposeDuration
sb-<project>-auth-tokenMyEventScape (Supabase Auth)Keeps you signed in and carries your session between pages. Set when you log in, and split across numbered variants when the session is too large for one cookie.Session, refreshed on use; cleared on sign-out
pending_inviteMyEventScapeHolds an invitation token while you finish signing up, so the invite still applies once you have an account.30 minutes
mes_sidebar_collapsedMyEventScapeRemembers whether you collapsed the workspace sidebar, so the server renders the width you chose instead of flashing the other one.Persistent, until cleared

The authentication and invitation cookies are set with HttpOnly, SameSite=Lax, and — outside local development — the Secure flag, so they cannot be read by scripts and are not sent along with cross-site requests.

Browser storage that is not a cookie

Your browser also keeps a small amount of data locally that is never sent to us: your light or dark theme preference, and short-lived working state for the site planner so an in-progress drawing survives a reload. This lives in your browser’s local storage, stays on the device, and is cleared when you clear site data.

Third-party cookies

We do not embed advertising, social, or analytics trackers. Two exceptions are worth naming, because both take you somewhere else:

  • Payments. Checkout and billing management are hosted by Stripe on Stripe’s own pages. Stripe sets its own cookies there, including ones used for fraud prevention, under its own privacy policy.
  • Maps. Map tiles, fonts, and address lookups are requested from third-party map providers. Those requests reach the provider with your IP address and the map area being viewed, which they may log for abuse prevention and capacity planning. They are not used to build an advertising profile.

Both are listed on our subprocessor page with links to their policies.

Your controls

Every browser lets you view, block, and delete cookies for a site, and offers a private browsing mode that discards them on exit. Blocking cookies for MyEventScape will sign you out and prevent you from signing back in, because the session cookie is how the platform knows who you are. Blocking cookies does not limit any other part of the service, since nothing else depends on them.

We honor Global Privacy Control signals where they apply, though we have nothing to sell or share in the sense those laws use. Questions about this notice go to privacy@myeventscape.com; the privacy policy covers the wider picture.

Questions about this policy? Email privacy@myeventscape.com or visit our contact page.