Cookie Notice
Version 2026-09-26 · Last updated 26 September 2026 · Movibyte Studio
The store app is the scanner. The Vondi Market app launches soon. Buying, boosts and messages stay closed until shipping works here. No date.
This Cookie Notice explains which cookies and similar technologies Vondi Market uses on vondi.co. It is part of the contract you accept at the country gate together with the Terms of Use and the Privacy Policy. Operator: Movibyte Studio, info@movibytestudio.com.
A cookie is a small text file stored on your device. This website also uses first-party cookies set by our own origin. We do not use advertising cookies, social pixels, or third-party analytics products (no Google Analytics, Meta Pixel, Hotjar or similar). We do not write to localStorage or sessionStorage on this site.
1. Legal basis
In the EU/EEA, storing or reading information on your device is governed by the ePrivacy Directive as implemented in the Netherlands in Article 11.7a of the Telecommunications Act (Telecommunicatiewet), together with the GDPR. Cookies that are strictly necessary to provide a service you explicitly request may be placed without a separate opt-in. All other cookies require consent.
The country gate asks you to tick three boxes (cookies, privacy, terms) before we write the acceptance cookie and let you into the catalogue. Preference cookies for language and theme are written only when you change those settings. Stripe may set its own cookies on Stripe’s domains when you start checkout or Connect onboarding; those are Stripe’s, not ours.
2. How we set first-party cookies
The four Vondi cookies below are set by the Next.js server with path /, SameSite=Lax, Max-Age of 365 days, and Secure in production. The server cookie API also marks them HttpOnly (they are not readable by page JavaScript). Values are short codes or version strings — not your password, card number or TIN.
3. Cookies this website sets
| Name | When | Purpose | Life | Class |
|---|---|---|---|---|
vondi_country | You submit the country gate (including “not listed”) | ISO country (or OTHER / GB for the UK) so we show the correct market pool and refuse countries we do not ship | 365 days | Strictly necessary |
vondi_legal | Gate submit after you tick cookies, privacy and terms, and your country is in a pool | Stores the accepted document version (currently 2026-09-26). If we publish a new version, this value no longer matches and you must accept again | 365 days | Strictly necessary (record of acceptance) |
vondi_signup_ok | You tick the sign-up boxes and then choose Apple or Google | Carries your acceptance through the Apple/Google sign-in so it can be recorded on the new account; deleted as soon as you return | 15 minutes | Strictly necessary (record of acceptance) |
vondi_lang | You change language in account settings | UI locale: en, nl, de, fr, es, it, pl or pt. Terms, privacy and this notice are issued in the same eight languages | 365 days | Functional (you asked for it) |
vondi_theme | You change appearance in account settings | light, dark or omitted / system so the layout can render without a flash | 365 days | Functional (you asked for it) |
sb-… (Supabase Auth) | You log in or the session is refreshed | Signed-in session for the same Supabase project as the Vondi app. Names start with sb- and may be split into chunks. There is no anonymous auth user for browsing; these cookies appear only after a real login | Session / refresh, set by Supabase SSR | Strictly necessary after login |
Honesty about order: if you pick a country and submit the gate without ticking all three boxes, the server may still write vondi_country and then send you back to tick the boxes. vondi_legal is written only after all three boxes and a supported pool. That country cookie is still a strictly necessary pool cookie, not an advertising cookie.
The cookie panel stores your choice in vondi_consent (necessary or preferences, 365 days, first party). Necessary covers vondi_country, vondi_legal and the login session. Preferences covers vondi_lang and vondi_theme. We do not set statistics or advertising cookies, so those switches stay off.
4. Third-party and infrastructure cookies
- Stripe — checkout, payment methods and Connect onboarding run on Stripe domains (
js.stripe.com,hooks.stripe.com, Stripe Checkout / Connect hosts). Stripe may set cookies there under its own policy (stripe.com/privacy and stripe.com/legal/cookies). We do not read those cookies. - Cloudflare — when vondi.co is proxied through Cloudflare for DNS, TLS and DDoS protection, Cloudflare may set a bot-management cookie (commonly
__cf_bm) or a challenge cookie. Those are Cloudflare’s, typically for a short period, and are used to distinguish humans from automated traffic. - Fonts — Inter and Space Grotesk are bundled at build time via
next/font. The browser does not call Google Fonts at runtime, so that path does not set a Google cookie. - Carriers and image-review providers — used server-side for labels or photo review. They do not set cookies on vondi.co.
5. What we do not use
- Advertising or retargeting cookies;
- Cross-site tracking or a “share” pixel for behavioural ads;
- First-party product analytics cookies;
- An anonymous Supabase guest session cookie (the previous web draft was wrong);
- Local storage keys on this website.
6. Consent, refusal and withdrawal
You may refuse the gate. Without a supported country and a current vondi_legal value, middleware keeps you off catalogue pages (home, legal pages, login and the auth callback stay reachable). You cannot browse the live pool without the strictly necessary country and acceptance cookies.
To withdraw: clear site cookies in your browser, or use the control that clears country (it deletes vondi_country and vondi_legal). Signing out ends the Supabase session cookies. Language and theme cookies remain until you clear them or overwrite them in settings. After withdrawal you will see the gate again.
Browser settings can block cookies generally. If you block all cookies, login and the gate will fail because the session and acceptance records cannot be stored.
7. Transfers and more information
Cookie values themselves are processed on our hosting (including Supabase and, if enabled, Cloudflare). Combined with an IP address used for rate limiting, they are personal data as described in the Privacy Policy. Questions: info@movibytestudio.com.
8. Changes
If we add a non-necessary cookie (for example a first-party analytics cookie), we will update this Notice, bump the legal version, and ask for a fresh tick. The table above is the complete first-party list for this website as of 26 September 2026.