Cookies Policy
Last updated: 13 August 2026
1. Who we are
This Cookie Policy explains how Planify uses cookies and similar technologies on planify.team, related Planify websites, and the application at app.planify.team.
Planify is a personal project operated by Chereji Ionuț, an individual based in Timișoara, Romania. Planify is not yet a registered company. Until incorporation, that individual is the operator and the data controller for cookie-related data on these sites.
Contact: ticket@planify.team
This policy should be read with the Privacy Policy and the GDPR Compliance page. It follows GDPR and the EU ePrivacy rules (Directive 2002/58/EC as amended), as applied in Romania.
2. What cookies are
Cookies are small text files stored on your device when you visit a website. Similar technologies include local storage, session storage, and pixels. We use “cookies” here to cover all of these.
Cookies may be:
- First-party — set by Planify on our own domains;
- Third-party — set by a provider we use (for example Paddle at checkout), on their domain;
- Session — deleted when you close the browser;
- Persistent — kept until they expire or you delete them.
3. How we use cookies
We use cookies to:
- keep you logged in and protect accounts (session, CSRF);
- run the WordPress website and the Laravel application;
- remember interface choices you make (for example light/dark appearance in the app);
- complete paid checkout through Paddle, when you start a payment;
- measure site usage only if an analytics tool is enabled and you have given consent.
We do not use cookies for advertising, retargeting, or selling data. We do not run marketing pixels for ads. Planify WhatsApp messages are operational, not marketing, and are not driven by website cookies.
4. Legal basis and consent
- Strictly necessary cookies do not require prior consent. They are needed to provide a service you requested (opening the site, logging in, security, checkout). Legal basis: ePrivacy exception for strictly necessary storage; GDPR Article 6(1)(b) (contract) and/or 6(1)(f) (security).
- Non-essential cookies (analytics, optional tracking) are used only after you opt in through a consent banner, where such a banner is shown. Legal basis: consent (GDPR Article 6(1)(a) and ePrivacy Article 5(3)). You may refuse or withdraw consent at any time. Refusal does not block access to the public site or to login; it only blocks that optional tool.
If no analytics or other optional tool is active, we may not show a banner. Essential cookies can still be set.
5. Cookies we use
Names can vary slightly after software updates. This list is the current, typical set.
5.1 Website (planify.team — WordPress) — strictly necessary
| Cookie | Purpose | Duration |
|---|---|---|
wordpress_test_cookie |
Checks that the browser accepts cookies | Session |
wordpress_[hash] |
Authenticates logged-in users in /wp-admin/ |
Session, or up to 14 days if “Remember me” is used |
wordpress_logged_in_[hash] |
Shows that you are logged in and who you are | Session, or up to 14 days if “Remember me” is used |
wp-settings-[UID] / wp-settings-time-[UID] |
Stores admin interface preferences for logged-in users | Up to 1 year |
wp_lang |
Stores language on the login screen | Session |
comment_author_* (only if comments are used) |
Remembers name/email if you leave a comment | Up to 1 year |
Anonymous visitors to the public website typically receive no WordPress login cookies. Those cookies are set when you log in to manage the site or, if comments exist, when you comment.
5.2 Application (app.planify.team) — strictly necessary
| Cookie | Purpose | Duration |
|---|---|---|
Session cookie (name ends in _session) |
Keeps you logged in; stores the server session | About 2 hours of inactivity, unless you stay signed in |
XSRF-TOKEN |
Protects forms against cross-site request forgery | Same as the session |
5.3 Application — functional / preference
These store appearance choices you make in the app (theme, colour). They do not profile you for advertising. They are treated as needed for the interface you requested.
| Cookie (typical names) | Purpose | Duration |
|---|---|---|
front-mode, admin-mode |
Light / dark / system appearance | Persistent (until changed or deleted) |
front-colorPref, admin-colorPref, front-primaryColor, admin-primaryColor |
Colour preference in the interface | Persistent (until changed or deleted) |
customize_skin, customize_semi_dark |
Layout/skin preference | Persistent (until changed or deleted) |
5.4 Payments (Paddle) — strictly necessary for checkout
If you start a paid subscription, checkout is handled by Paddle as merchant of record. Paddle may set its own cookies on its domains so the payment can be completed, fraud checked, and tax calculated. Those cookies are required for the payment you requested. They are governed by Paddle’s own terms and privacy information, including the Paddle Buyer Terms.
If you never open checkout, we do not set Paddle cookies for you on the Planify marketing site.
5.5 Analytics — consent required, not used for ads
We do not use advertising cookies. If we enable a first-party or privacy-oriented analytics tool on the website, it will:
- load only after you accept analytics in the consent banner;
- be used to understand page usage (visits, device type, approximate region), not to show ads;
- be listed here and in the banner by name when it is actually switched on.
Until such a tool is enabled, no analytics cookies are placed by Planify.
6. How to manage cookies
- Consent banner (when shown) — accept, refuse, or change non-essential categories. You can withdraw consent the same way.
- Browser settings — block or delete cookies. Blocking strictly necessary cookies may stop login, forms, or checkout.
- Paddle — cookies on Paddle’s checkout are managed through Paddle and your browser.
Browser help: Chrome, Firefox, Safari, and Edge each include a cookies/privacy section in Settings.
7. Data, retention, and transfers
Cookie data is used only for the purposes above. Session and security cookies last as stated in Section 5. We do not sell cookie data.
Hosting is with maghost.com in the EU. Paddle and (if used for WhatsApp, not for site ads) Meta process data under their own terms; those providers may transfer data outside the EU/EEA using Standard Contractual Clauses or another valid GDPR mechanism.
Your GDPR rights (access, erasure, objection, complaint to ANSPDCP) are described in the Privacy Policy.
8. Changes
We will update this page if we add, remove, or change cookies or tools. The date at the top is the latest revision. Material changes will be communicated where required (banner, email, or in-app notice).
9. Contact
Related: Privacy Policy, GDPR Compliance, Terms and Conditions.