Last updated: 24 August 2026
Cookies are small text files stored on your device by your browser when you visit a website. They are widely used to make websites work efficiently and to provide information to site owners.
Glenthea uses a minimal set of cookies. We do not use advertising or tracking cookies of any kind.
These cookies are strictly necessary to provide the Platform, keep it secure, remember a choice you have made, or complete a transaction. They cannot be switched off in our cookie settings.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
__Secure-authjs.session-token | NextAuth.js (first-party) | Keeps you signed in to your Glenthea account. | 14 days, refreshed each time you use your account, so an active session keeps rolling forward. It is not cleared when you close your browser. |
NEXT_LOCALE | Glenthea (first-party) | Remembers the interface language for this browser: the one you choose, or the one matched to your browser's own language settings on your first visit. | 1 year |
glenthea_pricing_plan, glenthea_verify_marker | Glenthea (first-party, HMAC-signed) | Preserves your selected plan and your email-verification status while you complete checkout. They expire automatically after 30 minutes. | 30 minutes |
glenthea_vendor_session | Glenthea (first-party) | Keeps approved vendors signed in to the vendor portal. | 7 days |
glenthea_unlock_<wedding-id> | Glenthea (first-party) | When a couple has password-protected their public wedding card, this cookie remembers that you've already typed the correct password, so you don't have to re-enter it on every page. | 24 hours |
consent | Glenthea (first-party) | Remembers whether you allowed or declined optional analytics, so you are not asked again on every page. | 1 year |
glenthea_guest_<wedding-slug> | Glenthea (first-party) | Remembers your access to a personalised wedding invitation so that you can continue browsing the invitation without reopening the original link. There is a separate one for each wedding you have been invited to. | 90 days, renewed each time you open your invitation link. |
__Host-authjs.csrf-token, __Secure-authjs.callback-url | NextAuth.js (first-party) | Two cookies set while you are signing in or out. They secure the sign-in request and return you to the page you were heading to afterwards. | Until you close your browser. |
__Secure-authjs.pkce.code_verifier, __Secure-authjs.state, __Secure-authjs.nonce, g_vendor_verifier, g_vendor_state, g_vendor_nonce | Glenthea and NextAuth.js (first-party) | Secure the Google sign-in process and prevent forged or replayed sign-in requests. Set only if you choose to continue with Google, and cleared as soon as you return. | 10 to 15 minutes, and cleared as soon as you return from Google. |
Vercel Analytics — Vercel, Inc. (third-party)
With your permission, we use Vercel Web Analytics to understand, in aggregate, how the Platform is used and to improve its performance.
Cookie-free: Vercel Web Analytics does not place analytics cookies on your device. Technical request data may nevertheless be processed by Vercel to produce aggregated usage statistics. More information about this processing is in our Privacy Policy.
Consent: Analytics stays switched off until you allow it. Declining, or making no choice at all, leaves it off, and you can withdraw your permission at any time.
Questions about this Cookie Policy? Email us at support@glenthea.com.