LumeQR logo

Cookie Policy

Last Updated: October 5, 2026

This Cookie Policy explains how LumeQR (“LumeQR,” “we,” “us,” or “our”) uses cookies, Local Storage, Session Storage, and similar browser-based technologies when you access or use the LumeQR website and related services.

This Cookie Policy should be read together with our Privacy Policy, which explains in more detail how we collect, use, store, and protect personal information.

1. What Are Cookies and Similar Technologies?

Cookies are small data files that websites store on your device through your browser. They may be used to maintain login sessions, store session-related information, support authentication, and enable websites to function properly.

In addition to cookies, LumeQR may use other browser-based storage technologies, including:

  • Local Storage;
  • Session Storage;
  • temporary session state; and
  • other client-side storage mechanisms necessary for authentication, editor recovery, payment flows, security, or similar product functionality.

Unless otherwise stated, references to “cookies and similar technologies” in this Policy include these browser storage mechanisms.

2. Why LumeQR Uses Cookies and Similar Technologies

LumeQR currently uses cookies and similar technologies primarily to provide, secure, and maintain the operation of the Service.

These technologies may be used to:

  • authenticate users and support login;
  • maintain account sessions;
  • perform security checks during OAuth, Magic Link, and similar authentication flows;
  • maintain anonymous user sessions and anonymous QR code drafts;
  • securely associate anonymous drafts with a user account after login;
  • monitor session activity and support security-related sign-out;
  • restore pages and user actions after authentication;
  • restore QR code editing, saving, and download workflows;
  • coordinate PayPal subscription and payment flows;
  • coordinate certain temporary operations across browser tabs; and
  • prevent duplicate operations and protect important product workflows.

LumeQR currently does not use client-side analytics or advertising technologies for targeted advertising, cross-site behavioral tracking, website traffic analytics, or session recording.

3. Strictly Necessary Cookies

The cookies currently used by LumeQR are primarily strictly necessary cookies.

These cookies are required for authentication, security, account sessions, and core product functionality. If you block these cookies through your browser, some or all features of LumeQR may not function properly.

3.1 Authentication Cookies

LumeQR uses Supabase Auth to provide account authentication and session management.

Our current authentication flow primarily stores user sessions in first-party cookies rather than relying primarily on Local Storage.

Authentication cookies may contain or support:

  • authentication session information;
  • access tokens;
  • refresh tokens;
  • PKCE verification information; and
  • authentication state associated with anonymous users.

Both anonymous users and signed-in users may use this authentication mechanism to maintain a session.

Certain Supabase Auth cookies may be split into multiple cookies when necessary due to browser cookie size limitations.

These cookies are used to verify identity, maintain login sessions, refresh authentication credentials, and support secure authentication flows.

3.2 PKCE Verification Cookies

When you use Google Sign-In, Email Magic Links, or other authentication flows based on OAuth or PKCE, LumeQR may use temporary cookies through Supabase to store a PKCE verifier.

These cookies are generally used only to complete the relevant authentication flow and are removed after the authorization code exchange is completed.

3.3 Session Activity Cookies

LumeQR uses a cookie named lumeqr_last_active_at to record recent account activity for session security and inactivity-based sign-out.

This information may also be stored in Local Storage.

LumeQR may use this activity information to determine whether a session has remained inactive for an extended period and to sign the user out when the applicable inactivity threshold is reached.

The expiration period of the cookie itself is separate from LumeQR's inactivity-based session logic. The actual duration of a session may therefore also depend on authentication service behavior, token refresh mechanisms, and account activity.

3.4 Anonymous Draft Claim Cookie

LumeQR allows users to begin creating QR code drafts before signing in.

The main contents of an anonymous draft are stored in LumeQR's backend database rather than primarily in standard browser cookies. The anonymous user identity is maintained through a Supabase Auth session.

When an anonymous user signs in, LumeQR may temporarily set a cookie named:

lumeqr_draft_claim_token

This cookie is used to securely associate the current anonymous draft with the user's authenticated account.

This cookie:

  • is temporary;
  • is set as HttpOnly;
  • uses SameSite=Lax;
  • uses the Secure attribute in production environments;
  • is restricted to the relevant authentication endpoint path; and
  • is retained for up to approximately two hours and removed when the claim succeeds, expires, or otherwise completes.

4. Local Storage and Session Storage

In addition to cookies, LumeQR uses Local Storage and Session Storage to retain certain temporary product states.

These technologies are primarily used to restore user actions and maintain continuity across authentication, navigation, editing, and payment flows. They are not currently used for advertising tracking.

4.1 Authentication and Login Flows

LumeQR may temporarily store information such as:

  • the authentication method selected by the user;
  • the page to return to after authentication;
  • whether an OAuth authorization code has already been exchanged;
  • temporary state related to email verification; and
  • actions that need to resume after authentication is completed.

This information helps ensure that a user can continue the original workflow after page navigation, refresh, or an OAuth redirect.

4.2 QR Code Editing, Saving, and Download Flows

LumeQR may use browser storage to retain short-term editing or workflow recovery information, including:

  • pending QR code save operations;
  • selected download formats or dimensions;
  • QR code identifiers;
  • certain editor components and QR style information;
  • image or PDF actions initiated before authentication;
  • editor actions that need to resume after login; and
  • short-term lock or signing information associated with QR code downloads.

These mechanisms help prevent users from losing in-progress actions due to login, page refreshes, or navigation.

4.3 Payment and Subscription Flows

When a user initiates a PayPal subscription or payment flow, LumeQR may use Local Storage or Session Storage to retain short-term workflow information, such as:

  • the selected subscription plan;
  • a checkoutAttemptId;
  • whether the subscription flow should automatically resume after login;
  • cross-tab coordination identifiers; and
  • temporary payment-flow state or lease information.

This information helps LumeQR correctly continue the subscription flow after authentication, redirection to PayPal, or return to LumeQR.

5. Anonymous Users and Anonymous Drafts

If you are not signed in to LumeQR, we may create an anonymous Supabase Auth session for you.

This allows you to begin creating a QR code draft before creating or signing in to an account.

QR code content, components, styles, and other draft information associated with anonymous users are primarily stored in LumeQR's backend database rather than solely in browser Local Storage.

If you later sign in, LumeQR may use a one-time secure credential to associate the anonymous draft with your authenticated account.

This process may involve:

  • anonymous authentication cookies;
  • a temporary draft-claim cookie;
  • authentication recovery state; and
  • temporary information stored in Local Storage or Session Storage.

These technologies are used to ensure that the anonymous creation workflow can continue securely and consistently after login.

6. Google Sign-In

LumeQR currently supports Google Sign-In.

When you choose to sign in with Google:

  1. LumeQR initiates an OAuth authentication flow through Supabase;
  2. your browser is redirected to Google's login or authorization page;
  3. after authorization, you are redirected back to LumeQR; and
  4. Supabase and LumeQR use the required authentication cookies to establish the session.

LumeQR does not create a separate Google-specific cookie solely for Google Sign-In.

When your browser accesses a Google domain, Google may use cookies, device information, security mechanisms, or other technologies in accordance with its own privacy and cookie policies.

The specific cookies or identification technologies used by Google on its own domains cannot be fully determined from LumeQR's codebase.

For additional information, please review Google's applicable privacy and cookie policies.

7. PayPal Payments and Subscriptions

LumeQR currently uses PayPal to provide certain subscription and payment services.

The current payment flow generally works as follows:

  1. your browser sends a subscription request to LumeQR;
  2. LumeQR's server communicates with the PayPal REST API;
  3. PayPal returns an approval URL;
  4. your browser is redirected to PayPal;
  5. you complete the approval process on PayPal; and
  6. PayPal redirects you back to LumeQR.

LumeQR currently does not embed the PayPal JavaScript SDK or a PayPal Button iframe directly within the LumeQR website.

During this process, LumeQR may use Local Storage or Session Storage to retain checkout intent, a checkoutAttemptId, the selected subscription plan, and certain cross-tab coordination information.

When you access PayPal's website, PayPal may use cookies, Local Storage, device identification, fraud-prevention technologies, and other payment security mechanisms in accordance with its own policies.

The specific technologies used by PayPal on its own websites cannot be fully determined from the LumeQR codebase.

For more information, please review PayPal's applicable privacy and cookie policies.

8. Cloudflare and Infrastructure Services

LumeQR uses certain third-party infrastructure services to provide image hosting, file storage, website hosting, content delivery, and related network functionality.

These services may currently include:

  • Cloudflare Images;
  • Cloudflare R2; and
  • Cloudflare Pages or related CDN and hosting infrastructure.

For example:

  • images may be uploaded directly to Cloudflare Images;
  • images may be delivered from Cloudflare content delivery domains;
  • PDFs or other files may be uploaded to Cloudflare R2 using signed URLs; and
  • access to LumeQR may pass through Cloudflare hosting or network infrastructure.

The current LumeQR codebase does not contain a LumeQR-specific cookie that is created specifically for Cloudflare Images or Cloudflare R2.

However, whether Cloudflare uses cookies in a production environment for network security, bot detection, challenges, CDN functionality, or other infrastructure services may depend on the applicable deployment configuration and Cloudflare services.

Such third-party behavior is governed by the applicable Cloudflare policies and the actual production configuration used by LumeQR.

9. Cookies and Tracking Technologies We Do Not Currently Use

Based on LumeQR's current product implementation, we do not currently use the following technologies for website visitors:

  • Google Analytics / GA4;
  • Google Tag Manager;
  • Meta Pixel;
  • TikTok Pixel;
  • Microsoft Clarity;
  • Hotjar;
  • PostHog;
  • Mixpanel;
  • Amplitude;
  • Plausible;
  • Umami;
  • Vercel Analytics;
  • Vercel Speed Insights;
  • Sentry;
  • LogRocket;
  • Cloudflare Web Analytics;
  • personalized advertising tracking;
  • cross-site behavioral tracking;
  • user session recording;
  • browser fingerprinting;
  • persistent device identification;
  • QR scan analytics; or
  • CAPTCHA-based tracking or similar mechanisms.

Certain analytics-related user interface elements or placeholders may exist within the product, but LumeQR has not currently implemented production website analytics or QR scan tracking services.

If LumeQR introduces analytics, advertising, marketing, or other non-essential tracking technologies in the future, we will update this Cookie Policy and, where required by applicable law, provide appropriate choices, opt-out mechanisms, or consent controls.

10. Cookie Consent and Cookie Banners

LumeQR does not currently implement:

  • a Cookie Consent Banner;
  • an “Accept All” control;
  • a “Reject Non-Essential” control;
  • Cookie Settings;
  • a Consent Management Platform (CMP);
  • analytics consent controls; or
  • advertising consent controls.

The /cookies page currently displays this Cookie Policy and is not a cookie-consent interface.

LumeQR currently does not use advertising cookies or non-essential analytics cookies that we have identified as requiring user consent.

If such cookies or technologies are introduced in the future, we will evaluate whether cookie consent controls or cookie settings are required under applicable law.

11. Retention of Cookies and Similar Data

Different cookies and browser storage data may have different retention periods.

Some data is used only for a particular authentication, login, or payment flow and may be removed when the relevant process is completed.

Some Session Storage data will generally be removed when the relevant browser tab or browser session ends.

Some Local Storage data may remain in the browser for longer periods. LumeQR may apply application-level expiration logic and remove or invalidate such data when a workflow completes, when expired data is next accessed, or when another applicable condition is met.

The actual period for which browser data remains stored may therefore depend on:

  • the purpose of the data;
  • cookie configuration;
  • browser storage type;
  • authentication service behavior;
  • token refresh mechanisms;
  • user account activity;
  • completion of the relevant product workflow; and
  • application-level expiration rules.

Please note that signing out of your LumeQR account does not necessarily cause all LumeQR Local Storage or Session Storage data to be immediately deleted.

Certain temporary data may instead be removed when the relevant workflow is completed, when it expires according to application logic, or when the browser tab or session ends.

12. How You Can Manage Cookies and Browser Storage

Most modern browsers allow you to:

  • view stored cookies;
  • delete cookies;
  • block all or certain cookies;
  • restrict third-party cookies;
  • clear website data;
  • remove Local Storage and other site storage; and
  • automatically clear certain data when the browser is closed.

The exact controls available depend on the browser you use.

Please note that if you block or delete LumeQR's strictly necessary cookies or authentication data, you may experience issues such as:

  • being unable to sign in;
  • losing your authenticated session;
  • losing the ability to identify an anonymous draft;
  • being unable to associate an anonymous draft with your account after login;
  • being unable to restore certain editing or download workflows;
  • interruption of payment or subscription workflows; or
  • loss of access to certain security or account features.

13. Third-Party Cookies and Similar Technologies

When you use features that involve third-party services, your browser may directly access websites or services operated by those third parties.

These services may currently include:

  • Supabase;
  • Google;
  • PayPal; and
  • Cloudflare.

These third parties may use cookies, browser storage, security technologies, device information, network logs, fraud-prevention systems, or similar technologies as required to provide their services.

LumeQR cannot fully control or determine all data-processing activities performed by third parties on their own domains solely from the LumeQR codebase.

Their practices are governed by their respective privacy policies, cookie policies, and service configurations.

14. Changes to This Cookie Policy

We may update this Cookie Policy from time to time as LumeQR's features, infrastructure, payment services, analytics capabilities, or applicable legal requirements change.

For example, we may update this Policy if we introduce:

  • website analytics;
  • QR scan analytics;
  • advertising or marketing tracking;
  • user behavior analytics;
  • additional payment providers;
  • cookie consent tools; or
  • other third-party services.

If we make material changes to this Policy, we may notify you through the LumeQR website, account interface, or another appropriate method.

The “Last Updated” date at the top of this page reflects the most recent revision of this Cookie Policy.

15. Contact Us

If you have any questions about this Cookie Policy or about how LumeQR uses cookies or other browser storage technologies, you may contact us using the contact information provided on the LumeQR website.