Legal

Cookies & local storage

PartyPPL sets six cookies of its own and keeps a few things in your browser and in the app, so you stay logged in and your tickets work without a signal. No trackers, no ad networks. Everything is below, with purpose and duration.

Last updated: 1 October 2026

1Why you see no cookie banner

Cookies and other storage on your device need consent, except in two cases (article 11.7a(3) of the Dutch Telecommunications Act): when they are strictly necessary for the service you ask for yourself, and when they only serve to measure how the service works, with no or little effect on your privacy.

Almost everything below is strictly necessary: staying logged in, your preferences, your tickets offline. Two things are measurement: the `ppl_inv` cookie, which counts whether an invitation led to a sign-up, and the report of how long a page was on screen. Both without an id of you, only as totals, only for us and not combined with other data.

For the personal data involved, such as your IP address, the basis is our legitimate interest (article 6(1)(f) GDPR). You can object through the privacy statement.

If anything is ever added that does need consent, such as third-party analytics or an ad pixel, we ask first and only set it afterwards. Refusing will then be as easy as accepting.

2The six cookies

All from partyppl.nl itself. No third-party cookies. Functional means: it remembers a choice you made yourself, so the site does what you asked; that counts as strictly necessary.

`__Host-ppl_session` · staying logged in · strictly necessary
Only when you are logged in. A random token; the database only knows its hash. httpOnly, Secure, SameSite=Lax. At most 30 days, and expired after 14 days without use. On a development server without https it is called `ppl_session`.
`ppl_prefs` · preferences · functional
Your language, your chosen cities and your theme. No identification. SameSite=Lax, 1 year.
`ppl_text` · text size · functional
Only when you choose larger text in the app: "normal" or "larger". Gone as soon as you switch back to the system setting. 1 year.
`ppl_org` · portal · functional
Only for organiser team members: which organisation you picked in the portal. 1 year.
`ppl_inv` · invitation · measurement
The code of the last invitation you opened. With it we count per invitation how often it was opened and whether an account came from it; whoever invited sees only those totals. No id of you. httpOnly, 30 days. The counts themselves expire after 400 days.
`ppl_apple` · signing in with Apple · strictly necessary
A random code that ties the step at Apple to your browser. httpOnly, Secure, 10 minutes, and gone once you are in.

The short address pppl.app sets nothing: it sends you straight on to partyppl.nl.

3Local storage in your browser

This data stays on your device, with two exceptions: what you do offline is sent on once you are back online, and the pairing of a door scanner goes along with every scan.

`ppl_geo`
Your last position, only if you tapped "near me" and your browser allowed it. To sort by distance.
`ppl.recent-searches`
Your last five searches.
`ppl:trip:<event>`
The amounts in a night's trip planner.
`ppl:checklist:<event>`
Your checklist. If you are logged in, we also keep it with your account.
`ppl:warmed`, `ppl:festival`, `ppl:page:*`, `ppl:cache-owner`, `ppl:persist`
Which nights and pages are ready for offline, a backup copy of page data (with your tickets), whose they are and whether your browser allowed persistent storage. If another account logs in, we wipe it all.
`ppl:review:asked`, `ppl:review:going`
Only in the iPhone app: counters for the request to rate the app.
`ppl-admin-nav`, `ppl-portal-nav`
Whether the admin or portal sidebar is collapsed.
`ppl.door.label`, `ppl.door.sound`, `ppl.door.scanner`
Settings of a door computer. The pairing with a scanner goes along with every scan.
`ppl:chat:at` (sessionStorage)
Where you were in a chat, until you close the tab.
`ppl-outbox` (IndexedDB)
"I'm going", "Interested" and ticket alerts you gave without a connection. We send them on once you are back online.
`ppl-pages` (IndexedDB)
Page data for offline, if your browser lacks the ordinary cache.

4The service worker and the offline cache

On the website and as a web app a service worker runs with five caches:

`ppl-v4`
The app itself: scripts, styles, fonts, the offline page and the icons.
`ppl-pages-v2`
Pages you visited. Gone on every change you make and when you log out.
`ppl-festival-v1`
Nights ready for offline: the event page, artists, the venue, the site map, the checklist and your tickets. Say "I'm going" to a night within 30 days and we get it ready; two days after the night it goes.
`ppl-media-v1`
Images you saw, at most 200; the oldest go first.
`ppl-pages`
Page data the app keeps itself for offline.

Never cached: payments, what you send, the chat connection and our API, except the site maps.

On a new version the service worker clears old caches itself. Under Tickets you see what is ready and remove it.

5What the apps keep on your device

Page data
The iPhone app keeps the data of your tickets, your nights and their artists for offline, as above. Another account wipes it all.
Widgets
A token (kept by us only as a hash, valid 30 days) and the latest widget data, with the ticket code of your next night so the QR works offline too. In the app's shielded storage; gone when you log out.
Apple Watch
The QR of your next ticket, from your iPhone. Gone when you log out.
Spotlight
Your upcoming nights, so you can search for them on your iPhone. Only on your device.
Alarms
Set by your iPhone itself, with AlarmKit.
Apple Wallet
A pass you add sits in Wallet and is yours until you remove it.

6How we count without a cookie

We want to know how many people use the agenda, without knowing who you are:

  • per day we count page views per route pattern (routepatroon), so `/e/:id` and not the address itself. For nights, artists, venues and organisations we also count per day how often the page was opened and how long it was on screen, as a total per page;
  • for unique visitors we make a hash of the day, IP address, browser and a secret key, shorten it to ten characters and keep only that;
  • the day is in the hash, so visits cannot be linked across days;
  • those hashes expire after 48 hours. We do not keep the IP address or browser. Per day we count at most 5,000 unique visitors; after that only views keep counting;
  • the page reports every two minutes and on closing how many seconds it was visible, without a cookie and without an id. From that we count how long visits lasted, on which kind of device and system. Administrators are not counted.

Not counted: our API, files, the admin, the portal, ticket scans, requests your browser makes ahead of time, and bots. Counts per page are deleted after 100 days, the rest after 400 days, every day, automatically.

Basis: measuring how the service works, with little effect on your privacy (article 11.7a(3) of the Dutch Telecommunications Act), and our legitimate interest (article 6(1)(f) GDPR). Nothing goes to a third party.

7Third-party content

Map (OpenFreeMap)
Tiles come from tiles.openfreemap.org as soon as you see a map. That service sees your IP address. No cookies.
YouTube, SoundCloud and Mixcloud
A player only loads when you tap play; YouTube then through youtube-nocookie.com. The preview image of a YouTube video does already come from YouTube as soon as you see the page, so Google sees your IP address then. After your tap, that service's rules apply.
Paying (Stripe)
Checkout happens on Stripe's page. Stripe's cookies and rules apply there.
Spotify
If you link Spotify, you log in on Spotify's site.

Fonts and scripts come from our own server. Most images do too.

8Managing it yourself

You wipe or block cookies and site data in your browser. If you block everything, you can still browse, but not stay logged in, and we do not remember your language.

Logging out wipes the page cache. If you want everything gone, clear the site data for partyppl.nl or remove the app.

More about what we do with data: the privacy statement.

What changed

  • Six cookies instead of two: `ppl_text`, `ppl_org`, `ppl_inv` and `ppl_apple` were missing.
  • Every key in local storage, IndexedDB and the service worker's five caches, with what does reach the server.
  • New: what the apps keep on your device (widgets, Apple Watch, Spotlight, alarms, Wallet).
  • Corrected: the YouTube preview image loads before you tap play.
  • Each cookie now says whether it is strictly necessary, functional or measurement, and on what ground we work without a banner.
  • The statistics clear themselves every day; the invitation counts expire after 400 days.

Back to top