Cookie Policy
This website uses cookies and similar technologies (local storage). Some are necessary for the site to work; others are used only with your consent. You choose in the cookie banner when you first visit and can change your choice at any time via the “Cookie settings” link in the footer.
WHO WE ARE
The website is operated by Apriory Apartmants Kft. (Apriory Apartmants Korlátolt Felelősségű Társaság), registered seat 1073 Budapest, Erzsébet körút 18. földszint U1., tax number 25147478-2-42, company registration number 01-09-202577, e-mail ilove@dolcevitaflowers.app, phone +36 30 169 0303. Questions about cookies and personal data: ilove@dolcevitaflowers.app. See also our Privacy Policy.
NECESSARY COOKIES (NO CONSENT NEEDED)
They keep the site working and are set by us:
dvf_consent — your cookie choice and the version of this policy you agreed to (12 months).
dvf_currency — the currency you chose for prices, HUF or EUR (12 months).
dvf_gate — access to the preview site before launch (30 days, HttpOnly; removed at launch).
The language is part of the page address (/hu, /uk, /ru), so no cookie is needed for it.
dvf_checkout — the checkout you are in: the key of the order being placed (HttpOnly; 24 hours).
dvf_subscribe — the subscription checkout you are in: the key of the subscription being set up (HttpOnly; 24 hours; deleted once the subscription is created).
dvf_order — the key of the order you have placed, so you can pay for it and see its status after returning from the bank (HttpOnly; 24 hours).
dvf_order_signed_out — set only if your sign-in expired while you were placing an order, so the order was placed without your account: the order’s identifier, so that the confirmation page can tell you this; nothing else (HttpOnly; 24 hours).
dvf_cart — your cart on this device: the items, quantities and greeting card texts you chose (local storage; kept until you empty the cart or clear the site data).
dvf_wishlist — your wishlist on this device: only the addresses of the bouquets you saved with the heart, no prices and nothing about you (local storage; kept until you empty the wishlist or clear the site data).
dvf_pickup — the boutique you chose with “Pick up here”, so that checkout opens with pickup there: only the boutique’s code, nothing about you (local storage; kept until you clear the site data).
dvf_last_order — the items, quantities and greeting card texts of your last order, so that if the time to pay runs out you can place it again with one button (local storage; 24 hours, replaced by your next order and removed once you use it).
dvf_scroll — where you were on the pages you opened, so that “Back” returns you to the same place: only page addresses and scroll positions, search pages are not kept (session storage, the last 20 pages; deleted when you close the tab).
dvf_session — you are signed in to your account: the short-lived access token (HttpOnly; up to 15 minutes).
dvf_refresh — keeps you signed in without asking for the password again, even after you close the browser (HttpOnly; 180 days, renewed on every visit); signing out or changing the password ends it.
dvf_session_hold (1 minute) and dvf_session_strike (10 minutes) — short technical marks that stop the site from asking to renew an expired session over and over.
dvf_visitor — protects the “send a hint” form from abuse: a random identifier with no name, email or address in it (HttpOnly; 30 days).
The promo bar you close is remembered in your browser for the tab only (session storage, dvf_promo_closed) and is never sent to us.
ANALYTICS (WITH YOUR CONSENT)
With your consent we use PostHog (servers in the European Union) to understand how the site is used: pages visited, steps of the order, errors. The data is pseudonymous and is not used for advertising. Without consent no analytics cookie is set and no event is sent. After consent PostHog stores ph_<project token>_posthog — a pseudonymous visitor identifier and session data (cookie and local storage, 12 months). From your IP address PostHog derives an approximate location — country, region, city, postal code, time zone and approximate coordinates with an accuracy radius (city level, not your address) — and stores it with the event; the IP address itself is not stored. Withdrawing consent stops collection and deletes the identifier and data from your browser; events already sent, including the approximate location, are kept for up to 7 years as described in the Privacy Policy, and you can ask us to erase them.
PAYMENT
When you pay, Stripe sets cookies needed to process the payment and prevent fraud. They are set on the payment page by Stripe Payments Europe, Ltd.: __stripe_mid — the payer’s device identifier for fraud prevention (12 months); __stripe_sid — the same within one payment session (30 minutes). Both are set by Stripe’s script on our domain and are needed for the payment itself, so they appear only on the payment page and only when you go there. Stripe’s own list of cookies is at stripe.com/cookie-settings.
CHAT
The chat widget writes nothing to your browser until you open it. After that it uses local storage (kept until you clear the site data) only for what you do in the chat:
dv_bubble_seen — a mark that you have opened the chat.
dolce_chat_v1 — your conversation with Dolce the bear, the last 40 messages (kept only here, not on the server).
dv_uid_v2 — the identifier of your conversation with the team, issued by the chat server when you open that conversation or leave a contact, and sent to the chat server with your messages to the team and when checking for new replies.
dv_op_last — the number of the last message of your conversation with the team shown in your browser.
dv_op_consent — the version of the chat notice in force when you sent a message to the team.
dv_name — the name you gave.
dv_name_asked, dv_contact_left, dv_tips_left — marks that we have already asked your name, that you left a contact and that you left an e-mail for tips, so that we do not ask again.
dv_lang — the chat language, only if you choose it in the chat (otherwise the language of the page is used).
The bin icon “Delete my chat history” removes all of these except dv_bubble_seen and dv_lang; the ↻ “New conversation” button in the conversation with Dolce clears dolce_chat_v1.
The chat server runs on Cloudflare; what it stores is described in the Privacy Policy.
STAFF AREA
The staff area at staff.dolcevitaflowers.app is used only by the shop’s employees; visitors of the shop do not receive these cookies. It sets only necessary cookies, all HttpOnly and sent only over HTTPS:
dvf_staff — the employee’s sign-in, which stays open even after the browser is closed (180 days, renewed while the employee works in the staff area; signing out or revoking the employee’s access ends it; sent only to the staff area pages).
dvf_staff_renew — a technical mark that the sign-in period of dvf_staff was checked with the server less than an hour ago, so that it is not checked on every page (1 hour; sent only to the staff area pages).
dvf_staff_bind_code — the one-time code for linking the employee’s Telegram to the staff bot, kept so that it can be shown once on the employee’s own page (2 minutes; sent only to that page).
dvf_courier_bind_code2 — the same for linking a courier’s Telegram, shown on that courier’s card (1 minute; sent only to that card).
Before launch the staff area is also behind the preview login (dvf_gate, see above).
HOW TO MANAGE COOKIES
Use the banner or the “Cookie settings” link in the footer to give or withdraw consent. You can also delete cookies in your browser settings; necessary cookies will be set again on your next visit. Withdrawing consent does not affect processing that took place before.
CHANGES
We update this page when the cookies we use change. Last updated: 2026-10-07.