Cookie Policy

This page explains how we use cookies and browser storage for strictly necessary functions and optional features.

Data Controller Information

lackora.

Maistraße 45, 80337 München, Deutschland

Represented by: lackora. Team Germany

Commercial Register ID: Registergericht: Munich, Registernummer: 8220-25-16738

VAT ID: DE458354536

Responsible for content according to § 55 of the Interstate Broadcasting Treaty: Tetiana Mitreva

Privacy Contact

info@lackora.com

(IT-lead lackora Team) David Moussaviabnavi — data protection / privacy contact (Datenschutzkontakt) Tel. +49 176 88474603 E-Mail: info@lackora.com Maistraße 45, 80337 München, Deutschland

Strictly Necessary Cookies

These cookies are required to support authentication, security, and essential platform functionality. We use secure settings (such as Secure, HttpOnly, and SameSite) to protect your sensitive session data.

Preference Cookies

Preference storage helps us remember your cart contents and interface settings between visits.

Maps and Location

Map functionality relies on browser APIs and local storage to provide you with location-based features and salon discovery.

Push Notifications

When enabled, we register this browser with our notification service so you can receive booking and account alerts, including when the site is closed.

Open notification settings

Manage Your Choices

Consent Storage Key: lackora-cookie-consent

Policy Version: 2026-06-v2

You can open your Cookie Settings at any time from the link in the footer to review or update your choices.

Cookie and Storage Inventory

This inventory reflects the operational use of cookies and local storage currently active in this application.

next-auth.pkce.code_verifier (Cookie)

Necessary

Purpose: OAuth PKCE security during social login flow.

Required: Yes

Retention Period: Up to 60 minutes (aligned with access-token validity window)

next-auth.state (Cookie)

Necessary

Purpose: OAuth state validation and CSRF protection.

Required: Yes

Retention Period: Up to 60 minutes (aligned with access-token validity window)

lackora-cookie-consent (localStorage)

Necessary

Purpose: Stores the user cookie-consent choices and policy version.

Required: Yes

Retention Period: Persistent until user updates consent choices

cart_{branchId} (localStorage)

Preferences

Purpose: Stores cart items per branch for continuity between visits.

Required: Operationally required (current implementation)

Retention Period: Persistent (updated when cart changes; not auto-deleted)

currentBranchId (localStorage)

Preferences

Purpose: Stores current selected branch for booking/cart restoration.

Required: Operationally required (current implementation)

Retention Period: Persistent (updated when branch changes; not auto-deleted)

global-theme / mantine-theme (localStorage)

Preferences

Purpose: Stores selected UI theme preferences.

Required: No (UX only)

Retention Period: Persistent until user changes preference or clears browser storage

cartSelections_{branchId} (sessionStorage)

Preferences

Purpose: Stores temporary booking selections during checkout session.

Required: Operationally required (checkout continuity)

Retention Period: Browser session

accessToken / refreshToken (application auth lifecycle) (Auth session lifecycle)

Necessary

Purpose: Maintains authenticated session for secure account access.

Required: Yes

Retention Period: Access token: 60 minutes, Refresh token: 90 days

navigator.geolocation permission (Browser Permission)

Maps

Purpose: Allows user-location features for map view and nearby salons.

Required: User-granted

Retention Period: Managed by browser/OS permission settings

Web Push subscription (service worker) (Push subscription)

Notifications

Purpose: Registers this browser to receive push alerts from our notification service.

Required: User-granted

Retention Period: Until removed in device management or browser push settings