Cookie Policy

Effective: 11 June 2026 · Pursuant to § 25 TTDSG and Art. 6 GDPR

This Cookie Policy explains what cookies and similar technologies Healtown uses, why, and how you can control them. It supplements our Privacy Policy.

§ 1 — What Are Cookies?

Cookies are small text files stored on your device (computer, tablet, or phone) by a website you visit. They allow the website to recognise your device on subsequent visits and store information between page loads, such as login state or preferences.

Similar technologies include localStorage (browser storage), sessionStorage, and HTTP headerssuch as Bearer tokens. Where we refer to "cookies" in this policy, we include all such similar storage mechanisms.

§ 2 — Legal Framework

Under German and EU law, storing cookies on or accessing data from a user's device requires either:

(a) the cookie being strictly necessary for the service explicitly requested by the user (§ 25 Abs. 2 Nr. 2 TTDSG), in which case no consent is required; or

(b) the user's prior, informed, freely given, specific, and unambiguous consent (§ 25 Abs. 1 TTDSG, Art. 6(1)(a) GDPR).

Healtown has designed its cookie use to rely only on strictly necessary cookies for core Platform functions. No advertising, cross-site tracking, or profiling cookies are currently in use.

§ 3 — Cookies We Use

3.1 Strictly Necessary Cookies (No Consent Required)

These cookies are essential for the Platform to operate. Without them, core features such as login, booking, and account management cannot function. They are set automatically when you use the Platform.

sb-auth-token
Set by: Supabase Auth. Purpose: Maintains your authenticated session — proves to the server that you are logged in. Without this cookie, you would be logged out on every page. Duration: Session / until logout. Type: Strictly necessary.
sb-refresh-token
Set by: Supabase Auth. Purpose: Refreshes your session in the background without requiring you to log in again. Duration: Up to 7 days (rolling). Type: Strictly necessary.
healtown-cookie-consent
Set by: Healtown (localStorage). Purpose: Records your cookie preference so we do not ask again. Duration: 1 year. Type: Strictly necessary (manages consent state).

3.2 Optional Cookies (Consent Required)

Healtown currently does not use any optional, analytical, marketing, or third-party tracking cookies. If we introduce them in the future, we will request your explicit consent through the cookie consent banner before setting them.

Categories that would require your consent if introduced in future:

Analytics cookies
Would track page views and navigation paths to improve UX. Example providers: Plausible Analytics, PostHog.
Marketing cookies
Would track ad campaign performance. Not currently in use.
Personalisation
Would remember preferences beyond session. Not currently in use.

§ 4 — Third-Party Cookies

Some features of the Platform involve third-party services that may set their own cookies:

Stripe
When processing payments, Stripe may set cookies on its payment pages for fraud prevention purposes. These are governed by Stripe's Cookie Policy: stripe.com/cookies-policy/legal.
Jitsi Meet (video calls)
If you use the in-platform video session feature, the Jitsi infrastructure may set functional cookies for the duration of the call. These are session-scoped and strictly necessary for the call to function.
DiDit (identity verification)
During the identity verification flow, DiDit may use session-level storage for the verification process. This is strictly necessary for the verification service.

Healtown has no control over third-party cookies. Please refer to each provider's own cookie and privacy policies for details.

§ 5 — Managing Your Cookie Preferences

5.1 Cookie Consent Banner

On your first visit to Healtown, a cookie consent banner is displayed. You can accept or decline optional cookies. Your choice is stored in localStorage and respected on subsequent visits.

5.2 Withdrawing Consent

You can change or withdraw your cookie consent at any time by clearing the healtown-cookie-consentkey from your browser's localStorage (via browser developer tools → Application → Local Storage → healtown.net). The consent banner will then reappear on your next visit.

5.3 Browser Settings

You can also manage cookies through your browser settings. Note that disabling strictly necessary cookies will prevent you from logging in or using core Platform features.

Browser guides for cookie management:

5.4 Do Not Track (DNT)

Some browsers offer a "Do Not Track" (DNT) signal. As Healtown does not engage in cross-site tracking, DNT signals do not change our cookie behaviour, but we acknowledge them.

§ 6 — Changes to This Cookie Policy

Healtown may update this Cookie Policy when new cookies or technologies are introduced. Material changes will be communicated via the cookie banner and, for registered Users, by email. The current version is always available at healtown.net/cookies.

§ 7 — Contact

For questions about our use of cookies or to exercise your rights:
privacy@healtown.net

Version 1.0 — Effective 11 June 2026