Cookie Policy
This page lists every cookie TodoMore uses by name: who sets it, how long it lasts and what it does. None of the non-essential ones run without your consent.
Last updated: 30 August 2026
1.What Are Cookies and Why We Use Them
A cookie is a small text file saved to your browser when you visit a site. The same rules apply to data written to the browser's local storage; this policy covers both.
On the TodoMore marketing site we use cookies for two things: making the site work (your language, security verification, your preferences) and — only if you allow it — measuring which pages are useful.
We use no cookies for advertising, profiling or selling data to third parties.
2.How Consent Works
No non-essential cookie runs before you consent. This is not a promise but the site's technical behaviour:
- Before you consent, not a single request is sent to analytics providers; their scripts are never downloaded to your browser.
- Rejecting is as easy as accepting — the “Essential only” button in the banner is a single click with no extra steps.
- You can change your decision at any time; withdrawing is as easy as giving.
- Your decision is asked again after 12 months, so an old consent is never treated as valid indefinitely.
3.Consent Record
The law requires us to be able to demonstrate that consent was given (GDPR Art. 7(1)). For that we keep a record only when you accept: the date of the decision, the categories you approved, the policy version, your browser type and an irreversible hash of your IP address.
Nothing is recorded when you reject — there is no need to prove a rejection, because no processing took place on that basis. The record never stores your raw IP address and is not linked to any account of yours.
Records are kept on our own infrastructure (Supabase, Frankfurt, Germany) and are never sent to a third-party consent management provider.
4.Essential Cookies
Required for the site to work; they cannot be disabled and do not require consent. Without them your language preference is not remembered and security verification cannot run.
- Name
- NEXT_LOCALE
- Provider
- TodoMore — 1st party
- Type
- Cookie
- Duration
- 1 year
- Purpose
- Remembers your chosen interface language so the site opens in it on your next visit.
- Name
- tdm-consent-v1
- Provider
- TodoMore — 1st party
- Type
- Local storage
- Duration
- 12 months (then asked again)
- Purpose
- Stores your cookie preferences and the date of your decision. If deleted, your choices are lost and the banner reappears.
- Name
- __cf_bm
- Provider
- Cloudflare, Inc. — 3rd party
- Type
- Cookie
- Duration
- 30 minutes
- Purpose
- Distinguishes bot traffic from real visitors; blocks automated request floods and abuse.
- Name
- cf_clearance
- Provider
- Cloudflare, Inc. — 3rd party
- Type
- Cookie
- Duration
- Up to 1 year
- Purpose
- Records that you passed a security challenge so you are not re-challenged on every page. Written only if a challenge was shown.
- Name
- Cloudflare Turnstile
- Provider
- Cloudflare, Inc. — 3rd party
- Type
- No cookie
- Duration
- —
- Purpose
- Protects the contact form against automated submissions. Sets no cookie of its own; only the verification script is loaded. (Contact page only)
| Name | Provider | Type | Duration | Purpose |
|---|---|---|---|---|
| NEXT_LOCALE | TodoMore — 1st party | Cookie | 1 year | Remembers your chosen interface language so the site opens in it on your next visit. |
| tdm-consent-v1 | TodoMore — 1st party | Local storage | 12 months (then asked again) | Stores your cookie preferences and the date of your decision. If deleted, your choices are lost and the banner reappears. |
| __cf_bm | Cloudflare, Inc. — 3rd party | Cookie | 30 minutes | Distinguishes bot traffic from real visitors; blocks automated request floods and abuse. |
| cf_clearance | Cloudflare, Inc. — 3rd party | Cookie | Up to 1 year | Records that you passed a security challenge so you are not re-challenged on every page. Written only if a challenge was shown. |
| Cloudflare Turnstile | Cloudflare, Inc. — 3rd party | No cookie | — | Protects the contact form against automated submissions. Sets no cookie of its own; only the verification script is loaded. (Contact page only) |
5.Analytics Cookies (consent-based)
Runs only with your explicit consent. Measures, in aggregate, which pages are visited and how fast they load; never used to identify you or show you ads.
No analytics provider is currently configured on this site; even if you accept analytics, there is no script to load.
6.Marketing Cookies
We do not use any. There are no ad networks, pixels or profiling cookies on this site. If any are added later they will run only with your separate, explicit consent and this table will be updated.
7.Inside the App (app.letstodomore.com)
This policy covers the marketing site. Inside the app you log into, no analytics or marketing tracker runs at all; only the strictly necessary storage that keeps you signed in is used (the Supabase session key, in your browser's local storage).
That is why no cookie banner is shown in the app: there is no cookie that requires consent.
8.Managing and Withdrawing Your Consent
You can open your preferences from the “Manage my cookie preferences” link at the bottom of every page and change them category by category. When you withdraw consent the provider is disabled immediately.
You can also delete or block cookies in your browser settings. Blocking essential cookies means your language preference is not remembered and security verification is repeated.
9.Your Rights and How to Reach Us
Your rights under KVKK Art. 11 and GDPR Art. 15-22 apply to data processed through cookies. See the KVKK Disclosure Notice and the Privacy Policy for detail, or write to info@letstodomore.com.