Cookie Policy
Last updated: 25 July 2026
WeefyBox sets a small number of cookies across three distinct surfaces: this marketing site, the venue-management app, and the guest-facing captive portal. Each is listed below with its purpose.
Marketing site (weefybox.com)
- Session cookie — strictly necessary, used to maintain basic session state (e.g. CSRF protection on the contact form). Expires when the browser closes.
- Theme preference — remembers light/dark mode choice. Strictly necessary for the feature to work; no consent banner is required for this one under PECR/ePrivacy since it's not used for tracking.
- Google Ads and Analytics tags — used on WeefyBox-branded pages to understand site usage and whether an advertisement leads to a registration, venue activation or paid subscription. Google may use browser identifiers or cookies according to the visitor's browser and consent settings. These tags are not loaded on white-label partner domains or guest captive portals.
Venue-management app
- Authentication session cookie — strictly necessary, keeps a logged-in Account Holder user signed in.
- CSRF token — strictly necessary, protects form submissions from cross-site request forgery.
- Google Ads conversion measurement — the WeefyBox-branded billing return page loads the same Google Ads tag so a completed subscription can be attributed to the advertisement that introduced the customer. White-label partner accounts are excluded.
Guest captive portal
- weefy_device — a long-lived (1 year), signed, http-only cookie used to recognise a returning guest's device across visits so a return visit can be attributed without asking the guest to re-enter their details. Declining it means each visit may be treated as a new guest.
Because iOS and Android captive-portal browsers block or sandbox most third-party requests and JavaScript, the splash page itself sets no other cookies or trackers beyond weefy_device.
Managing cookies
You can control or delete cookies through your browser settings. Disabling the weefy_device cookie on the captive portal will not prevent you from getting online, but it can prevent the venue from recognising the device as returning on a later visit.