Cookie Policy
This page explains how we use cookies and browser storage for strictly necessary functions and optional features.
Data Controller Information
Maistraße 45, 80337 München, Deutschland
Represented by: lackora. Team Germany
Commercial Register ID: Registergericht: Munich, Registernummer: 8220-25-16738
VAT ID: DE458354536
Responsible for content according to § 55 of the Interstate Broadcasting Treaty: Tetiana Mitreva
Privacy Contact
info@lackora.com
(IT-lead lackora Team) David Moussaviabnavi — data protection / privacy contact (Datenschutzkontakt) Tel. +49 176 88474603 E-Mail: info@lackora.com Maistraße 45, 80337 München, Deutschland
Strictly Necessary Cookies
These cookies are required to support authentication, security, and essential platform functionality. We use secure settings (such as Secure, HttpOnly, and SameSite) to protect your sensitive session data.
Preference Cookies
Preference storage helps us remember your cart contents and interface settings between visits.
Maps and Location
Map functionality relies on browser APIs and local storage to provide you with location-based features and salon discovery.
Push Notifications
When enabled, we register this browser with our notification service so you can receive booking and account alerts, including when the site is closed.
Manage Your Choices
Consent Storage Key: lackora-cookie-consent
Policy Version: 2026-06-v2
You can open your Cookie Settings at any time from the link in the footer to review or update your choices.
Cookie and Storage Inventory
This inventory reflects the operational use of cookies and local storage currently active in this application.
next-auth.pkce.code_verifier (Cookie)
Purpose: OAuth PKCE security during social login flow.
Required: Yes
Retention Period: Up to 60 minutes (aligned with access-token validity window)
next-auth.state (Cookie)
Purpose: OAuth state validation and CSRF protection.
Required: Yes
Retention Period: Up to 60 minutes (aligned with access-token validity window)
lackora-cookie-consent (localStorage)
Purpose: Stores the user cookie-consent choices and policy version.
Required: Yes
Retention Period: Persistent until user updates consent choices
cart_{branchId} (localStorage)
Purpose: Stores cart items per branch for continuity between visits.
Required: Operationally required (current implementation)
Retention Period: Persistent (updated when cart changes; not auto-deleted)
currentBranchId (localStorage)
Purpose: Stores current selected branch for booking/cart restoration.
Required: Operationally required (current implementation)
Retention Period: Persistent (updated when branch changes; not auto-deleted)
global-theme / mantine-theme (localStorage)
Purpose: Stores selected UI theme preferences.
Required: No (UX only)
Retention Period: Persistent until user changes preference or clears browser storage
cartSelections_{branchId} (sessionStorage)
Purpose: Stores temporary booking selections during checkout session.
Required: Operationally required (checkout continuity)
Retention Period: Browser session
accessToken / refreshToken (application auth lifecycle) (Auth session lifecycle)
Purpose: Maintains authenticated session for secure account access.
Required: Yes
Retention Period: Access token: 60 minutes, Refresh token: 90 days
navigator.geolocation permission (Browser Permission)
Purpose: Allows user-location features for map view and nearby salons.
Required: User-granted
Retention Period: Managed by browser/OS permission settings
Web Push subscription (service worker) (Push subscription)
Purpose: Registers this browser to receive push alerts from our notification service.
Required: User-granted
Retention Period: Until removed in device management or browser push settings