Effective July 1, 2026 · Last updated August 25, 2026 · Version 2026-08-25
Cookies are small text files placed on your device by websites you visit. They are widely used to make websites and apps work, or work more efficiently, and to provide information to the site owners. Cookies are stored either in your browser’s memory (session cookies) or on your device’s storage (persistent cookies). Consistent with Bumble’s cookie description, “a cookie is a small file placed on your device or internet browser that allows us to recognise and remember your preferences.”
In addition to cookies, we and our third-party partners may use other tracking technologies including:
Pixel Tags / Web Beacons: Tiny invisible images embedded in web pages or emails that allow us or third parties to track whether a page was viewed or an email was opened
Local Storage: A technology built into browsers that allows websites to store information locally on your device, similar to cookies but with larger storage capacity
Session Storage: Similar to local storage but cleared when you close your browser session
Software Development Kits (SDKs): Code embedded in our mobile application that allows third-party analytics and service providers to collect data about app usage
Device Fingerprinting: Collecting technical information about your device to create a unique identifier. We use this only for fraud prevention and security, not for advertising
Log Files: Automatically recorded information about your interactions with the Platform, including IP address, browser type, pages visited, and timestamps
References to “cookies” in this Policy include all of the above technologies unless otherwise specified.
First-party cookies are set by YKnot directly and can only be read by us. Third-party cookies are set by external companies whose services are embedded in our Platform (such as analytics providers). Third-party cookies may be read by those companies when you visit other websites as well.
We use four categories of cookies, as defined by the International Chamber of Commerce (ICC) Cookie Guide and consistent with the categorization used by Bumble, Meetup, and Meta. Bumble’s cookie policy discloses the use of “strictly necessary cookies, performance cookies, functional cookies and targeting cookies.” We use the first three categories; we do not use targeting cookies.
These cookies are essential for the Platform to function. They cannot be disabled. No consent is required to use these cookies under the ePrivacy Directive or GDPR. This approach is consistent with Meetup’s, Bumble’s, and Facebook’s treatment of strictly necessary cookies.
Strictly necessary cookies enable core functions including:
Keeping you logged in to your account
Maintaining your session as you navigate between pages
Processing payments securely
Enabling security features, including fraud detection and CSRF protection
Routing requests to the correct server
Remembering your cookie consent preferences
These cookies allow the Platform to remember your preferences and provide enhanced, personalized features. They may be set by us or by third-party providers whose services we have added to our Platform.
Functional cookies enable features including:
Remembering your language and locale preferences
Remembering your notification and communication preferences
Saving your display name and profile settings between sessions
Enabling social media features such as Apple Sign-In and Google Sign-In
Storing your location preferences
These cookies collect information about how you use the Platform. They help us improve how the Platform works and measure the effectiveness of features. The information collected is aggregated and anonymized where possible and is not used to identify individual users for advertising purposes.
Analytics cookies may collect:
Pages visited and features used
Time spent on each page or screen
Click paths and navigation patterns
Error messages encountered
Device type, browser type, and operating system
General geographic location (country or region level, derived from IP address)
These cookies help us detect and prevent fraud, protect account security, and maintain the integrity of the Platform. They are considered strictly necessary for security purposes but are listed separately for transparency.
Detecting unusual login patterns or suspicious account activity
Preventing cross-site request forgery (CSRF) attacks
Rate limiting to prevent automated abuse
Detecting and blocking spam and fake accounts
WE DO NOT USE COOKIES FOR CROSS-SITE BEHAVIORAL ADVERTISING. WE DO NOT SELL COOKIE DATA TO THIRD PARTIES. WE DO NOT USE TARGETING OR ADVERTISING COOKIES. UNLIKE MEETUP (WHICH USES COOKIES FOR ADVERTISING NETWORKS INCLUDING FREESTAR), YKNOT DOES NOT SERVE THIRD-PARTY ADVERTISING AND DOES NOT USE COOKIES TO BUILD ADVERTISING PROFILES OF OUR USERS.
We do not serve third-party advertising on the Platform
We do not use retargeting pixels for advertising on other websites
We do not share cookie data with advertising networks
We do not use targeting cookies of any kind
The following table lists the cookies and tracking technologies currently deployed on the Y🪢 Platform. We update this list as our use of cookies changes. If you have questions about a specific cookie not listed here, please contact info@yknot.love.
| Cookie / Technology | Provider | Category | Duration | Purpose | Data Collected |
|---|---|---|---|---|---|
| session_id | YKnot | Strictly Necessary | Session | Maintain logged-in session | Session token |
| auth_token | YKnot | Strictly Necessary | 30 days | Persistent login authentication | Encrypted auth token |
| csrf_token | YKnot | Strictly Necessary | Session | CSRF attack prevention | Random security token |
| cookie_consent | YKnot | Strictly Necessary | 12 months | Store cookie consent choice | Consent status |
| payment_session | Stripe | Strictly Necessary | Session | Secure payment processing | Payment session ID |
| locale_pref | YKnot | Functional | 12 months | Remember language/region setting | Language code |
| display_prefs | YKnot | Functional | 12 months | Remember UI preferences | Preference flags |
| apple_signin | Apple Inc. | Functional | Session | Enable Apple Sign-In | Apple ID token |
| google_signin | Google LLC | Functional | Session | Enable Google Sign-In | Google auth token |
| _ga | Google Analytics | Analytics | 2 years | Distinguish unique users | Anonymized user ID |
| _ga_* | Google Analytics | Analytics | 2 years | Persist session state | Session data |
| _gid | Google Analytics | Analytics | 24 hours | Distinguish users | Anonymized user ID |
| mp_* | Mixpanel (or equiv.) | Analytics | 1 year | Product analytics | Usage events |
| perf_monitor | YKnot | Analytics | Session | Performance monitoring | Page load times, errors |
| fraud_signal | YKnot / Stripe | Security | Session | Fraud detection signals | Device fingerprint hash |
| rate_limit | YKnot | Security | 1 hour | Prevent automated abuse | Request count |
* Third-party analytics providers listed above are subject to their own privacy policies. We configure them in privacy-enhancing modes where available (e.g., IP anonymization in Google Analytics, Google Consent Mode v2 for GDPR compliance). Provider names may change as we update our technology stack; cookie categories and purposes remain consistent.
Some cookies on the Platform are placed by third-party companies. We use third-party services to support analytics, authentication, and payment processing. Each third party operates under its own privacy policy.
We use Google Analytics to understand how users interact with the Platform. We have enabled IP anonymization in Google Analytics and use Google Consent Mode v2 to comply with GDPR requirements — meaning analytics cookies are only placed after consent is obtained from EEA/UK/Swiss users.
Provider: Google LLC
Privacy Policy: policies.google.com/privacy
Opt-Out: tools.google.com/dlpage/gaoptout (browser add-on)
Google Consent Mode v2: Implemented for GDPR compliance
We use Stripe to process payments. Stripe may place cookies or use other tracking technologies to prevent fraud and ensure secure payment processing.
Provider: Stripe, Inc.
Privacy Policy: stripe.com/privacy
If you use Apple Sign-In or Google Sign-In to create or access your account, those providers may use cookies or tokens as part of their authentication service. Those providers’ privacy policies apply to their use of cookies.
We may use product analytics tools to understand how users interact with specific Platform features. Data collected is anonymized and used solely for product improvement. Analytics providers do not receive your name, email, or payment information.
We do not currently use any third-party advertising networks on the Platform. We do not embed advertising pixels (such as the Meta Pixel, TikTok Pixel, or Google Ads conversion tags) on the Platform. We do not share cookie data with advertising networks for any purpose. This is a deliberate and significant departure from platforms like Meetup, which use advertising cookies from networks such as Freestar. If we introduce advertising in the future, we will update this Cookie Policy and obtain any necessary consent before deploying advertising cookies.
This section applies specifically to California residents under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).
Cookies and similar technologies on the Y🪢 Platform may collect the following categories of personal information as defined under the CCPA:
Identifiers: IP address, device identifiers, cookie IDs, session tokens
Internet or other electronic network activity: Pages visited, features used, clicks, session duration
Geolocation data: General location derived from IP address (country or region level only; not precise GPS)
Inferences: Inferences drawn from usage data to understand how you use the Platform
We do not sell personal information collected via cookies to third parties for monetary consideration. We do not share personal information collected via cookies for cross-context behavioral advertising. If this changes, we will provide notice and an opt-out mechanism as required by the CCPA/CPRA.
The California Privacy Protection Agency’s regulations under the CPRA require that “Accept” and “Reject” options on cookie consent interfaces must have equal prominence — the same size, color weight, and number of clicks required. Refusing cookies must be as easy as accepting them. We design our cookie consent interface to comply with this requirement. We also do not use dark patterns of any kind in our cookie consent interface.
Right to Know: You may request information about the categories of personal information collected via cookies and the purposes for which it is used
Right to Delete: You may request deletion of personal information collected via cookies (subject to legal retention obligations)
Right to Opt-Out of Sale or Sharing: We do not sell or share cookie data; no opt-out is currently required
Right to Non-Discrimination: Exercising your cookie rights will not result in discrimination
Although we do not sell or share personal information, we provide a “Do Not Sell or Share My Personal Information” link in our website footer, consistent with CCPA/CPRA requirements, for users who wish to confirm this status or exercise their rights.
This section applies to users in the European Economic Area (EEA), United Kingdom, and Switzerland under the GDPR, UK GDPR, and EU ePrivacy Directive (the “Cookie Law”).
Legal basis: Legitimate interests (Article 6(1)(f) GDPR) and/or performance of a contract (Article 6(1)(b) GDPR). Strictly necessary cookies do not require your consent under the ePrivacy Directive as they are essential for the Platform to function.
Legal basis: Your consent (Article 6(1)(a) GDPR). We obtain your consent via our cookie consent banner before placing functional or analytics cookies on your device. You may withdraw consent at any time. Consistent with 2025 GDPR enforcement standards, we implement Google Consent Mode v2 and block all non-essential cookies until explicit consent is obtained — merely displaying a banner without blocking cookies does not satisfy consent requirements.
Legal basis: Legitimate interests (Article 6(1)(f) GDPR) in preventing fraud and maintaining Platform security.
When you first access the Platform from the EEA, UK, or Switzerland, we display a cookie consent banner. Consistent with 2025 GDPR enforcement standards and the European Data Protection Board’s cookie banner taskforce findings:
The banner uses clear, plain-language explanations — no legal jargon
Accept and Reject options have equal visual prominence — same size, color weight, and number of clicks (no dark patterns)
Optional cookie categories are not pre-ticked
Refusing cookies is as easy as accepting them
All non-essential cookies are technically blocked until consent is obtained — not merely disclosed
Consent preferences are stored and honored on subsequent visits
You may change your preferences at any time via the “Cookie Preferences” link in the website footer
We do not use dark patterns in our cookie consent interface. We do not make the reject option harder to find, require more clicks, or display it in a smaller font than the accept option.
You may withdraw your cookie consent at any time by:
Clicking the “Cookie Preferences” link in the footer of our website
Using your browser settings to delete cookies (see Section 7)
Contacting us at info@yknot.love
Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Some third-party cookies (e.g., Google Analytics) may transfer data to the United States. Where such transfers occur, we rely on Standard Contractual Clauses (SCCs) or other appropriate safeguards as described in our Privacy Policy. By consenting to analytics cookies, you also consent to the associated data transfers.
We retain cookie data only as long as necessary for the purposes described in this Policy. Specific retention periods are listed in the cookie inventory table in Section 3. Session cookies are deleted when you close your browser. Persistent cookies expire on the date specified in the inventory or when you delete them manually.
You have several options for controlling how cookies are used when you visit the Platform. Note that disabling certain cookies may limit the functionality of the Platform.
On our website, you can manage your cookie preferences at any time by clicking the “Cookie Preferences” or “Manage Cookies” link in the footer of any page. This allows you to accept or decline analytics and functional cookies, view your current consent status, withdraw consent for optional cookie categories, and reset your preferences to defaults.
Most web browsers allow you to control cookies through their settings preferences:
Google Chrome: Settings > Privacy and Security > Cookies and other site data
Mozilla Firefox: Settings > Privacy & Security > Cookies and Site Data
Apple Safari: Preferences > Privacy > Manage Website Data
Microsoft Edge: Settings > Cookies and site permissions > Cookies and site data
Opera: Settings > Advanced > Privacy & security > Site Settings > Cookies
iOS (iPhone/iPad): Settings > Privacy & Security > Tracking (to limit ad tracking across apps)
Android: Settings > Privacy > Ads > Opt out of Ads Personalization
Y🪢 app: Deny or revoke location access through your device’s app permissions settings
Google Analytics: Download the Google Analytics Opt-out Browser Add-on at tools.google.com/dlpage/gaoptout
Mixpanel: Visit mixpanel.com/optout/ to opt out of Mixpanel tracking
Some browsers include a “Do Not Track” (DNT) feature that signals to websites that you do not want to be tracked. Because there is no accepted standard for how websites should respond to DNT signals, we do not currently alter our practices in response to DNT signals.
We recognize the Global Privacy Control (GPC) signal as a valid opt-out of the sale or sharing of personal information under the CCPA/CPRA, to the extent applicable to our data practices. Since we do not currently sell or share personal information for advertising, GPC signals do not change our data practices at this time. Consistent with Colorado’s privacy law and other state laws requiring Universal Opt-Out Mechanism (UOOM) support, we honor GPC as an opt-out signal where required. We will update this Policy if our practices change.
By mid-2025, more than a dozen US states had enacted comprehensive privacy statutes with cookie-related obligations. This section addresses the most significant state-specific requirements affecting Y🪢 users.
Users in Texas (TDPSA), Colorado (CPA), Virginia (VCDPA), and Connecticut (CTDPA) have the right to opt out of targeted advertising. Since we do not use cookies for targeted advertising, no opt-out action is required. Users in these states also have the right to opt out of the sale of personal data via cookies, which we do not engage in.
Minnesota’s comprehensive privacy law, effective July 31, 2025, applies to controllers processing personal data of at least 100,000 consumers. Users in Minnesota have the right to opt out of targeted advertising, the sale of personal data, and certain profiling. Y🪢 does not engage in these activities via cookies. Consent is required for processing sensitive data, which we obtain through our cookie consent banner for applicable processing.
Colorado and other states require platforms to honor Universal Opt-Out Mechanisms (UOOM), which include the Global Privacy Control (GPC) signal. We honor GPC signals as described in Section 7.6. We do not require users to submit separate opt-out requests when a valid UOOM signal is received.
In accordance with Apple’s App Tracking Transparency (ATT) framework, we will request your permission before tracking your activity across other companies’ apps and websites. We currently do not engage in cross-app tracking for advertising purposes and therefore do not request ATT permission for advertising. Our app is listed in the Apple App Store with a Privacy Nutrition Label disclosing data collected by the app.
Our app discloses data collection and sharing practices in the Google Play Data Safety section. This disclosure is updated whenever our data practices change.
Analytics SDK: Collects anonymized usage events to help us understand how users interact with app features
Crash Reporting SDK: Collects crash logs and performance data to help us fix bugs
Payment SDK (Stripe): Enables secure payment processing within the app
Authentication SDKs (Apple, Google): Enable Sign-In with Apple and Google Sign-In
We do not use advertising or attribution SDKs in the mobile app.
Cookie data is retained for the periods specified in the cookie inventory in Section 3. In general:
Session cookies: Deleted automatically when you close your browser or end your app session
Persistent cookies: Retained until their expiration date, or until you delete them manually
Analytics data: Aggregated analytics data may be retained for up to 26 months for trend analysis, after which it is deleted or anonymized
Server logs containing IP addresses: Retained for 90 days for security purposes
We may update this Cookie Policy from time to time to reflect changes in our use of cookies, changes in applicable law, or changes in our technology partners. When we make material changes, we will update the “Last Updated” date at the top of this Policy, display a notice on the Platform, and for EEA/UK users, re-obtain consent for any new categories of cookies that require consent.
If you have questions or concerns about our use of cookies or this Cookie Policy, please contact us:
YKnot Love Incorporated
Attn: Privacy Team
55 South Kukui Street, Suite 2414
Honolulu, HI 96813
Email: info@yknot.love · subject: Cookie Policy Inquiry
Data Protection Officer: info@yknot.love · subject: DPO Inquiry
EU/UK Representative: info@yknot.love · subject: EU/UK Privacy
For EEA and UK users who are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.
YKnot Love Incorporated · 55 South Kukui Street, Suite 2414, Honolulu, HI 96813 · info@yknot.love
© 2026 YKnot Love Incorporated. All rights reserved.