Cookie Policy
An inventory of the technologies required for the cart, authentication, checkout, and security, together with the rules for any optional analytics or tracking.
1. What cookies and local storage are
Cookies are small values sent to the browser, while localStorage is local space controlled by the browser. The platform uses these mechanisms to preserve cart continuity, provide authentication, secure checkout, and support operational functions.
This policy must be updated whenever a new analytics, advertising, support, media playback, or social tracking tool is introduced.
2. Strictly necessary storage identified in the application
The durations above describe the technical configuration observed for the current version and do not, by themselves, justify longer retention in other systems. Session cookies are set with measures such as HttpOnly, SameSite, and Secure under the production configuration.
Sessions and checkout
- euphoria_customer_session - customer account session; configured technical duration: no more than 30 days.
- euphoria_portal_session - partner portal session; configured technical duration: no more than 12 hours.
- euphoria_staff_session - authorized staff session; configured technical duration: no more than 12 hours.
- euphoria_checkout_client - technical identifier used to reserve and protect checkout; configured technical duration: no more than 90 days.
Browser storage
- euphoria.cart.v1 - locally stores the event, category, quantity, and price in the cart; it is removed after eligible completion of checkout or when browser data is cleared.
- euphoria-scanner-profile-v1 - local operational preference for authorized scanning devices; it is not intended for ordinary visitors.
3. External services and checkout
When a hosted checkout or external service is opened, the relevant provider may use its own technologies required for payment, anti-fraud measures, security, and continuity. Names, purposes, and durations must be taken from the active provider's configuration and notice rather than assumed.
Providers reached from the platform, with their own notices: Vercel (https://vercel.com/legal/privacy-policy); Supabase (https://supabase.com/privacy); Stripe (https://stripe.com/privacy); Revolut (https://www.revolut.com/legal/privacy-notice/); Resend (https://resend.com/legal/privacy-policy); Oblio (https://www.oblio.eu/politica-de-confidentialitate).
Cookies set by the platform itself, all strictly necessary: euphoria_customer_session — keeps a buyer signed in to their account and tickets; euphoria_checkout_client — ties a checkout attempt to the browser that started it; euphoria_google_oauth_state — protects the google sign-in exchange against forgery; euphoria_staff_session — keeps door and office staff signed in to internal tools; euphoria_portal_session — keeps an organizer signed in to the partner portal. Card payment runs on the provider's hosted checkout, so any payment cookies belong to that provider's domain rather than this one.
4. Analytics, advertising, and other non-essential technologies
If technologies for non-essential analytics, advertising, remarketing, or social tracking are introduced, they will be disabled by default until the user makes a choice, to the extent required by Law No. 506/2004 and the GDPR.
The preference mechanism must provide clear options to accept, refuse, and configure by category, without making a purchase conditional on accepting marketing.
5. How they can be managed
- Non-essential preferences may be changed through the consent mechanism once it has been implemented and validated.
- Cookies and localStorage may be cleared through browser settings.
- Blocking strictly necessary storage may prevent authentication, cart retention, checkout, or portal access.
- Settings must be repeated in each browser or device and may be lost when local data is cleared.
6. Legal basis, duration, and updates
Storage necessary for the service to function is assessed separately from optional technologies. For optional technologies, evidence of the choice and the version of the notice are retained, and withdrawal must be as easy as giving consent.
The duration of each item must be limited to its purpose and reviewed periodically. Every change to the inventory receives a new version of this policy.
7. Contact and questions
For questions about technical storage, management@euphorictickets.ro may be used. The operator is ART STUDIOS MANAGEMENT S.R.L., Tax ID (CUI) 53262231, registered in Romania.
Personal data requests must be submitted through the /gdpr procedure, not by publishing session identifiers, authentication links, or QR codes.

