KindGuest sets only strictly-necessary cookies — one to keep you signed in and two short-lived ones used during the sign-in handshake. None of them are used for tracking, analytics or advertising.
Last updated: 18 July 2026
| Name | Purpose | Lifetime |
|---|---|---|
| auth_token | Keeps you signed in. Contains a signed token with your user id, email, role and restaurant id. httpOnly, SameSite=Lax, Secure in production. | 24 hours |
| oauth_state | Security check during Google Sign-In: protects against cross-site request forgery by confirming the login response matches the request we started. Deleted as soon as sign-in completes. | 10 minutes |
| oauth_return_to | Remembers which page you were heading to so we can return you there after signing in. Deleted as soon as sign-in completes. | 10 minutes |
All three are first-party and strictly necessary to provide the login you requested.
We do not use any of the following:
Consent banners are required for non-essential cookies. All three cookies above are strictly necessary to provide a service you actively requested (signing in and staying signed in), so they are exempt from consent requirements.
If we ever add analytics or any other non-essential cookie, we will add a consent mechanism and update this page before doing so.
The guest feedback form does not set any cookie. It stores a single timestamp in your browser’s local storage to show a friendly “please wait” message if you try to submit twice in quick succession. That value never leaves your device and is not a cookie.
You can clear or block cookies in your browser settings. Blocking the session cookie will prevent you from staying signed in. Questions: ccalin.webdesign@gmail.com.