We use cookies
We use analytics to see how CheckInOS is used and make it better. Nothing runs unless you accept — see our Cookie Policy for details.
Last updated September 7, 2026
CheckInOS uses strictly necessary cookies to authenticate users and secure the Services. We do not require a cookie consent banner for those authentication cookies where they qualify as strictly necessary under applicable ePrivacy rules. We use PostHog (EU Cloud) for privacy-focused event and page-view analytics, but only after you affirmatively accept analytics cookies in our cookie consent banner — see MANAGING PREFERENCES below. Nothing from PostHog loads, and no PostHog cookie or browser storage is set, until you accept.
Cookies are small text files stored on your device. We also use browser storage (such as localStorage) for certain in-app preferences.
Strictly necessary cookies (including authentication session and CSRF cookies) may be used without consent where legally exempt.
For personal data processed through these technologies, we rely on GDPR/UK GDPR bases including contract necessity, legitimate interests (where appropriate), and legal obligations. See our Privacy Policy.
| Category | Provider | Identifiers | Purpose | Consent | Retention |
|---|---|---|---|---|---|
| Strictly necessary (authentication) | Auth.js / NextAuth | Session token, CSRF token, callback URL cookies (names may include __Secure- or __Host- prefixes) | Sign-in, session security, CSRF protection, OAuth redirects | Not required where strictly necessary; no separate banner required for these cookies alone | Session / configured expiry |
| Local storage (non-cookie) | CheckInOS app | attendee-filters-${eventId}, resetOnboarding | Saved filter preferences and onboarding UI state | Functional preference storage for logged-in users; not used for cross-site advertising | Until cleared by user or app |
| Analytics (opt-in) | PostHog (EU Cloud) | ph_<project_api_key>_posthog (cookie and/or localStorage, PostHog's default persistence) | Page-view and product usage event analytics only — no session replay, no heatmaps | Required — only set after you accept analytics cookies in the cookie consent banner or preferences | Up to 1 year, or immediately cleared on decline/withdrawal |
Identity providers (Google, Microsoft, Apple) may set their own cookies during OAuth sign-in. See our Subprocessor List and provider privacy notices.
Analytics (PostHog, EU Cloud). With your consent, we use PostHog to record page views and product usage events so we can understand how CheckInOS is used and improve it. PostHog is hosted on PostHog's EU Cloud infrastructure. We only capture events and page views — we do not use session replay, heatmaps, or any other PostHog feature. PostHog is loaded and its cookie/localStorage identifier is only set after you click "Accept" in the cookie consent banner or in your cookie preferences; if you decline or have not yet decided, no PostHog script, cookie, or request occurs. See the table above for the exact identifier PostHog sets.
We do not use Vercel Analytics, advertising cookies, or retargeting cookies on the Services.
localStorage for checkinos.com.Blocking strictly necessary cookies will prevent sign-in. Declining or withdrawing analytics consent only stops PostHog — it never affects sign-in or core functionality.