Cookie notice
Croatian electronic-communications law (transposing the ePrivacy Directive) and the GDPR apply. Consent is required before any non-essential cookie is stored. Dozen currently sets only strictly necessary cookies on getdozen.dev. There is no analytics, advertising, or social-pixel cookie. A short notice on first visit explains this; you can dismiss it with OK.
What we set on getdozen.dev
- Supabase session cookies: keep a signed-in session after email, Google, or a waitlist confirmation. Without them login and the confirmation flow cannot work.
- dozen_auth_next: short-lived, stores the path to return to after sign-in.
- Host / security cookies set by Vercel or Cloudflare solely to deliver the site (for example bot or TLS cookies).
- Cloudflare Turnstile: a short-lived challenge cookie used only on account, waitlist, and bug-report forms to stop bots. It is not used for advertising.
These fall under the “strictly necessary” exception. Legal basis for related personal data is contract or the steps you ask us to take (GDPR Art. 6(1)(b)), or our interest in running a secure site (Art. 6(1)(f)).
Stripe checkout
When you pay, Stripe hosts checkout on stripe.com. Stripe may set its own cookies there to process the payment and prevent fraud. Those cookies are controlled by Stripe under its privacy notice, not by this page.
What we do not set
No Google Analytics, Meta pixel, advertising IDs, or optional preference cookies on getdozen.dev. If that changes, we will add a consent choice before any optional cookie is stored, and we will update this notice.
Banner preference (not a cookie)
Dismissing the first-visit banner stores dozen_cookie_notice in your browser's local storage so we do not show the banner again. That value is not sent to our servers.
How to delete them
Use your browser settings to clear cookies for getdozen.dev. That signs you out. More on personal data: privacy policy.
Terms of use · Payment terms · Privacy policy · Cookie notice
Last updated 29 August 2026