1. Storage categories we use
Keeps Halal Ticketin' functioning by remembering your consent choice, keeping you signed in, securing account and invitation flows, and preventing duplicate purchase tracking. This runs on every visit.
Lets event organisers measure event page and checkout performance using Google Analytics. After you opt in, Google Analytics tooling may load only on public event and checkout pages where an organiser has configured a GA4 Measurement ID.
Lets event organisers understand how people find their events using advertising tools such as Meta Pixel, TikTok Pixel, and Google Ads. After you opt in, we only initialise organiser destinations and send tracking events on public event and checkout pages.
2. Our first-party cookie
ht_consent
Remembers whether you opted into analytics and marketing storage so optional scripts stay on/off across visits in this browser. For signed-in users, we also sync consent to your account preferences.
Retention: 180 days
3. Essential browser storage (non-cookie)
localStorage — sb-{project-ref}-auth-token
Stores your Supabase session payload so social login callbacks and session refresh can complete.
Until sign-out, session expiry, or manual browser-storage clearing.
localStorage — halal-ticketin-access-token
Stores your Halal Ticketin' API token so you remain signed in without needing cookies.
Cleared when you sign out or manually clear browser storage.
localStorage — halal-ticketin-refresh-token
Renews your sign-in session when access tokens expire, so you stay signed in without interruptions.
Cleared when you sign out or manually clear browser storage.
localStorage — halal-ticketin:last-organizer-id
Remembers the organiser workspace you last selected so dashboards open to the right team.
Until you switch organisers or clear browser storage.
localStorage — halal-ticketin:exchange-rates
Caches exchange rates for up to 30 minutes to avoid unnecessary API calls.
Automatically refreshed every 30 minutes or when you clear browser storage.
localStorage — auth:last_used
Remembers the last sign-in method (password or Google) to streamline future sign-in flows.
Until replaced with a new value or cleared from browser storage.
localStorage — halal-ticketin:pending-invite
Temporarily stores invitation context so account creation/sign-in can continue into invitation acceptance.
Automatically removed after use or expiry (up to 7 days).
localStorage — halal-ticketin:pending-organizer-avatar
Temporarily stores a draft organizer avatar during registration until upload completes.
Removed after upload attempt or manual browser-storage clearing.
sessionStorage — halalticketin:pending-draft
Temporarily holds a drafted event while you move between creation screens in the same tab.
Removed when you close the tab or finish the draft.
sessionStorage — halalticketin:event-edit-recovery:{eventId}
Temporarily stores unsaved event edits in the current browser tab so organisers can recover work after refreshes, route reloads, or tab visibility changes.
Removed when you close the tab, discard the recovered edits, or save/publish the event.
sessionStorage — checkout_draft_{eventId}
Temporarily stores in-progress public checkout form details per event to support tab refresh recovery.
Expires after 30 minutes in-tab or when checkout completes.
sessionStorage — ht_embed_consent
Stores consent preference for embedded checkout/event experiences in the current tab session.
Removed when the embed tab is closed.
localStorage — ht_purchase_tracked:{orderId}
Legacy flag that stops duplicate Meta Pixel “Purchase” events by remembering which orders already fired.
One legacy flag per order that stays until you clear browser storage.
localStorage — ht_purchase_tracked:{provider}:{orderId}
Stops duplicate optional purchase events by remembering which provider already received a purchase event for an order.
One flag per order that stays until you clear browser storage.
localStorage — ht_data_layer_purchase_tracked:{orderId}
Stops duplicate first-party data layer purchase events by remembering which orders already pushed a purchase event.
One flag per order that stays until you clear browser storage.
4. Optional analytics and marketing technology
Google Analytics 4
Allows organisers to measure event page views, checkout starts, and purchases in their own Google Analytics property.
Provider: Event organisers via Google · Host: https://www.googletagmanager.com
Cookies placed: _ga, _ga_{container-id} · The Google tag library can load after you enable analytics or marketing storage. We configure GA4 and send GA4 events only after analytics storage is enabled and only where an organiser has configured a GA4 Measurement ID.
Category: Analytics storage
Meta Pixel
Allows organisers to attribute their ad spend by measuring page views, checkout starts, and purchases.
Provider: Event organisers via Meta · Host: https://connect.facebook.net
Cookies placed: _fbp, _fbc · Loaded after you enable marketing storage; we only initialise a pixel and send Meta events on public event and checkout pages where an organiser has configured a Meta Pixel ID.
Category: Marketing storage
TikTok Pixel
Allows organisers to measure event page views, checkout activity, and purchases for TikTok advertising attribution.
Provider: Event organisers via TikTok · Host: https://analytics.tiktok.com
Cookies placed: _ttp, _tt_enable_cookie · Loaded after you enable marketing storage; we only initialise a pixel and send TikTok events on public event and checkout pages where an organiser has configured a TikTok Pixel ID.
Category: Marketing storage
Google Ads
Allows organisers to measure completed ticket purchases as conversions in their own Google Ads account.
Provider: Event organisers via Google · Host: https://www.googletagmanager.com
Cookies placed: _gcl_au, _gcl_aw · Loaded after you enable marketing storage; we only configure and send purchase conversions where an organiser has configured a Google Ads conversion ID and purchase label.
Category: Marketing storage
5. Server-side marketing conversion events
Some organiser marketing tools do not place cookies from your browser. Instead, Halal Ticketin may send a completed-purchase event from our backend to the organiser's configured provider after marketing storage is accepted.
Meta Conversions API
Allows organisers to measure completed purchases in Meta Events Manager when browser tracking is blocked or unavailable.
Provider: Event organisers via Meta · Endpoint: https://graph.facebook.com
Data shared: Purchase event details, order and ticket identifiers, purchase value and currency, hashed attendee email, browser identifiers where present, IP address, user agent, and event page URL.
Only after marketing storage is accepted, only for completed purchases, and only where the organiser has configured a Meta Pixel ID and Conversions API token.
TikTok Events API
Allows organisers to measure completed purchases in TikTok Events Manager when browser tracking is blocked or unavailable.
Provider: Event organisers via TikTok · Endpoint: https://business-api.tiktok.com
Data shared: Purchase event details, order and ticket identifiers, purchase value and currency, hashed attendee email, browser identifiers where present, IP address, user agent, and event page URL.
Only after marketing storage is accepted, only for completed purchases, and only where the organiser has configured a TikTok Pixel ID and Events API token.
6. Your choices
You can change analytics and marketing storage at any time using the “Manage cookies” control in our site footer. In embedded event/checkout views, the same controls are available in the cookie banner.
Choosing “Reject optional” keeps Halal Ticketin running but stops optional analytics and marketing tracking. Clearing cookies or browser storage in your browser settings will also sign you out and reset cached data described above.
7. Legal basis
For EEA users, optional cookies and similar technologies are managed under the ePrivacy rules and GDPR consent standards. Essential storage is always on because it is necessary to provide requested services and secure key account flows.
If you are in regions such as California where ad-related identifiers can be treated as data-sharing for advertising, you can keep optional marketing storage disabled at any time through our cookie controls. Analytics storage is separately controlled and can also stay disabled.
8. Updates & contact
We update this policy whenever our storage inventory changes and will note the new effective date.
Questions? Email us at info@halalticketin.com or contact support.