PRIVACY

Privacy Policy

How your data is handled and protected.

This page exists to protect both you and the integrity of this experience.

This privacy policy applies to the Last Hour Experience and all online content on lasthourexperience.com.

I take your privacy seriously. The Last Hour Experience is a personal reflection experience.

I only collect the data necessary to deliver this experience safely and correctly.

This policy explains what data I process, why I process it, how I protect it and what your rights are.

The Last Hour Experience is operated by Vita Florentis, which acts as the legal data controller.

The plain-language explanation of what happens to your words lives on Your words.

The Last Hour Experience processes as little personal data as possible. I only process:

  • your name
  • your email address
  • a free-text message if you choose to use the Voices contact form
  • an optional answer about what brought you to the Early Access form, if you choose to provide one
  • your answers inside the experience (temporarily)
  • your farewell letters and the first names of the people you write to (temporarily)
  • optional Vita Flow workbook answers, held only in your browser's memory while the page is open
  • your preferences within the experience
  • anything you separately choose to submit as a public message or testimonial
  • up to 50 one-way hashed reservation email addresses stored on your device to recognize an existing reservation
  • payment and transaction data when you place an order
  • purchase, access and content-free delivery status
  • clean public page paths and language for the cookieless page count
  • your cookie choice and a random consent-decision ID used only to honor withdrawal of consent for server-side marketing measurement
  • campaign source fields and a pseudonymous visitor ID only where available and permitted
  • content-free product status and fixed technical error codes
  • public-message IDs stored on your device after you light a candle, plus a salted one-way server hash used to prevent duplicate candles or reports
  • basic technical data such as device and browser for delivery, security, fraud prevention and, where you consent, analytics or marketing measurement

I do not ask for special-category personal data in lead forms. Please do not include health data, religious or political beliefs, or similarly sensitive information in the optional Early Access reason. Reflection content may be deeply personal and is handled as described below.

Everything you write remains yours. Your answers are processed temporarily for the purposes described here, including to:

  • save and resume your active hour
  • generate your personal PDF
  • make it available to you as a secure download in your own account
  • email you a secure link to that download
  • act on a choice you make to publish a wall message or testimonial
  • send a first-deed reminder only when you explicitly switch that reminder on

Your reflections can touch on religious or philosophical beliefs, on your health, or on other sensitive personal data about yourself, because they are about your life. I never ask for any of it; nothing is read or analyzed to infer anything about you, and nobody is segmented or targeted based on it. Before the experience opens, you give separate, explicit consent for the sensitive personal data about yourself that you choose to write, and you withdraw that consent by erasing your words.

People you mention. People in your life may appear in your reflections and letters. I receive that information from you. It may include their name, their relationship to you, events and what you write about them. I process ordinary personal data about these people solely for my legitimate interest in providing your personal experience and delivering your document to you. I do not use the content to assess, profile or contact them, and I never deliver anything to them. I do not inform each person individually: doing so would require me to read your confidential text, identify them and obtain contact details even though none of that is needed to provide your experience, and it would intrude on your privacy and theirs. Write from your own experience; medical information, allegations or other highly sensitive details about identifiable people do not need to be there unless they are part of your story. This content follows the retention period for your words. A person you mention may submit a privacy request using the contact details below. I do not confirm or deny, in response to a general request, whether someone appears in private text; if that person provides enough specific information to locate data without a broad content search, I reassess the request and also take your rights and confidentiality into account.

During an active hour, a resume draft containing your answers, letters and message is also stored in this browser’s local storage on the device you are using. This device copy is not encrypted at rest by Last Hour Experience. Someone with access to your unlocked device or browser profile may therefore be able to read it.

The local resume draft is removed when you complete the experience. It is also configured to expire 30 days after its last local save: if the page remains open it is removed automatically, otherwise the site removes it on your first visit after expiration. Clearing this site’s browser data removes it sooner.

Vita Flow is a separate workbook. Anything you type there exists only in your browser's memory while the page is open and is not sent to Last Hour Experience. You can create a completed PDF or HTML file locally in your browser and choose where to save it. That file is readable by anyone who can open it.

If you are signed in, your answers are encrypted and stored only temporarily. The server resume copy is sent over an encrypted connection and stored with application-layer encryption. Your personal PDF is also generated and stored encrypted in your own account, ready for you to download.

The team does not routinely read your answers. This is not end-to-end encryption or a zero-access system: authorized server functions can technically decrypt the server copy to resume your hour and generate or deliver your PDF and downloads. People with strictly authorized technical system access could also technically access the content, but such access is limited to when it is needed to operate, secure or troubleshoot delivery.

That is where it stands today, and it is not where it will stay. I am building the version in which that key sits only with you. The experience does not open while that key is still mine. Once an independent security audit has confirmed that Last Hour Experience cannot read your stored words, the verified explanation will be published on the Your Words page.

Everything you write remains yours. After the hour, only an encrypted copy of your answers remains available to you. I erase it once you have saved it safely, when you delete it yourself, or after 30 days at the latest.

Your answers, letters and compiled document wait, encrypted, in your own account so you can download them. You can permanently delete them yourself at any time with one button in your account. The core copy is erased after you successfully save it through your browser's native file picker, after you explicitly confirm that a fallback download is safely stored, or after 30 days at the latest, whichever comes first, with a reminder before deletion. Then it lives only with you.

For transactional emails, your recipient address, subject and message body pass through Convex, my mail-orchestration layer, before Resend sends the email; delivery status is also processed through Convex. An answer-download email contains only a secure link, never the PDF or answers as an attachment. Only if you explicitly opt in to first-deed reminders may that opted-in deed appear in the relevant reminder email and be processed by Convex and Resend solely for delivery.

The deletion promise has four precise, optional exceptions plus one record that is deliberately kept. A public Message for the World and a published testimonial are kept only when you explicitly choose publication, separately from your answers, and can be removed on request. Private testimonial feedback is deleted within 30 days. If you opt in, I may keep only your first deed, encrypted, for your yearly reminder, and/or briefly for the one 48-hour reinforcement email. Turning off either opt-in deletes that stored deed immediately; the 48-hour copy is also deleted after sending and after 72 hours at the latest. Content-free run metadata, such as completion date, language and deletion status, is not answer content and remains only where needed to operate the account and prove deletion. Separately from all of this, proof that you gave consent before the experience opened is kept permanently: the version, the language and the moment, without your name, email address or a single word you wrote. It is the evidence that your consent was properly requested, so it has to outlive the erasure it refers to.

I process your data for the purposes described in this policy, including:

  • delivering the Last Hour Experience
  • generating your PDF and making it available as a secure download in your account
  • letting you complete Vita Flow and create your own local PDF or HTML file
  • security, fraud prevention and error detection
  • improving website stability and performance
  • managing Early Access, newsletters and the communications or reminders you choose
  • measuring public-site use and campaigns where you consent
  • publishing content only when you explicitly choose to publish it
  • payment processing, transaction records, and legally required recordkeeping
  • answering a Voices inquiry or exploring a collaboration you ask about

Your reflection answers from the experience are never used for marketing or advertising audiences, and are never shared with third parties for commercial purposes. When you make an Early Access reservation, you leave your email so I can send you the resource you requested and occasional updates about the experience, with your consent and with an unsubscribe link in every message.

The optional “What made you pause here?” answer is separate from the reflection experience. If you submit it, the text is added to the Vita Florentis lead records in Google Workspace and included in an operational notification to Vita Florentis delivered by Resend. The text is not sent to Meta or Google Analytics. After analytics consent, Google Analytics may receive only the fact that an optional reason was provided, never its content.

Cookieless public page count

On each public page load, a first-party request records a clean page path, language and server time in the Vita Florentis Supabase environment. Without analytics consent, the database row contains no visitor ID, country, query string, campaign field or cookie. It counts page loads, not unique people.

This request is never sent from account, checkout, gift-payment, access, download or experience pages.

Optional analytics

If you consent to analytics, a public-page record may also contain a random pseudonymous visitor ID, country, broad first-touch category and selected engagement events such as scroll depth, FAQ opens and CTA clicks. Google Analytics 4 and Cloudflare Web Analytics/RUM may then measure public-page usage and technical performance.

These tools are not loaded on private pages and never receive your reflection answers, letters or messages.

Messages and Voices are public community pages, so optional analytics there follows the same consent rules. Content-free wall views, permalink views and shares are recorded only after analytics consent and never contain message text, reflection answers or an email address. Lighting a candle or reporting a message remains functional without analytics consent.

Voluntary conversion attribution

When you voluntarily submit a lead form or start an order, the first-touch category and available UTM source, medium, campaign, content and ad-set values from that visit may be stored with the lead or order. Without analytics consent, these fields are used only for that voluntary conversion and do not create a persistent visitor ID or browsing profile.

Marketing and analytics scripts do not run on private experience, account, login and authentication, checkout and payment-return, access and redemption, pass-it-on, private Voice-invitation or admin routes. Messages and Voices remain public, consent-gated pages; no message, answer or letter content is sent to Google or Meta.

First-party measurement

After analytics consent, the public website stores a random visitor identifier and one coarse first-touch source (direct, ad, wall or Voice) for up to 12 months. No click ID, UTM value, IP address, answer or message is stored in those cookies.

Meta Pixel and Conversions API

After marketing consent, Meta Pixel and the Meta Conversions API may receive advertising-measurement events for public page views and voluntary conversions such as signups and purchases. Depending on the event, this can include a cleaned public-page URL or referrer, language, IP address, browser information, Meta browser identifiers, one-way hashed email or name, and purchase value, currency and product type.

Reflection answers, letters and messages are never sent to Meta. No Meta browser script loads on private pages; after payment, a consented Purchase event may be sent server-side.

If you withdraw marketing consent before a pending purchase event is sent, a first-party revocation request disables that pending event. The random consent-decision ID is not used as a visitor ID or browsing profile.

Content-free product reliability

To operate the experience reliably, the service records when a run starts and completes, derives the time between those moments, and records a fixed technical error code and stage when an identified run operation fails. These operational metrics contain no answers, letters, messages or other reflection content and are not used for advertising.

Essential public-wall interactions

Reading the public wall does not require analytics consent. If you light a candle or report a public message, the service must prevent duplicate or abusive actions. This browser therefore stores the public message IDs for your candle choices. The server creates a salted one-way deduplication hash from your account ID when signed in, or otherwise from a truncated IP network and coarse browser category. The candle or report record stores that hash, not the underlying account ID or raw IP address. Non-functional wall-view, permalink and share measurement is recorded only after analytics consent.

I review every Message for the World and testimonial submitted for publication myself before it goes public. That text is not sent to an AI model for moderation.

YouTube

Embedded videos stay behind a local placeholder until you deliberately click to load one. The video then loads through YouTube's privacy-enhanced player and YouTube may receive technical request data.

I use appropriate technical and organizational measures, including:

  • encrypted connections (SSL)
  • application-layer encryption for server-stored resume drafts and generated documents
  • a separate local browser resume draft, disclosed above, that is not encrypted at rest by Last Hour Experience
  • deletion of the core answer copy after a successful native save, after you confirm a fallback download, when you delete it yourself, or within 30 days
  • separate, encrypted first-deed reminder records only after explicit opt-in, with the 48-hour copy deleted within 72 hours and the yearly copy deleted on opt-out or when the account lifecycle ends
  • a self-service button to permanently delete your answers at any time
  • Convex and Resend for transactional email delivery; the answer PDF is never sent as an attachment, and reflection content appears only in an optional first-deed reminder you explicitly enabled
  • limited access to systems and logs
  • automatic deletion of temporary data

Your data is shared with:

  • Supabase (for accounts, temporary encrypted content, first-party page views, content-free product-health metrics and the canonical Early Access and newsletter CRM records, including contact details, consent, segments, mail status and suppression)
  • ElevenLabs (legacy only: before the human-only release, bare participant and recipient first names could be sent for pronunciation; no participant or recipient name is sent after this release).
  • Stripe (for checkout, payments, refunds and legally required transaction records)
  • Convex (the Vita Florentis Mainframe mail hub, which processes the recipient address, subject and message body before Resend and records delivery status; reflection content appears only in a first-deed reminder you explicitly enabled)
  • Resend (for sending transactional emails, usually containing only secure links. If you explicitly enable a first-deed reminder, that email quotes only that chosen sentence. Resend also delivers the optional Early Access reason in an operational notification and Voices contact messages to Vita Florentis. Resend also holds the Early Access and newsletter addresses as a sending list, because that is how my own mail system sends; that list follows the same consent, unsubscribe and deletion rules as the CRM record)
  • Cloudflare (for hosting and security; Web Analytics/RUM on public pages only after analytics consent)
  • Meta Platforms (Pixel and Conversions API for advertising measurement and audiences, only after marketing consent. For these tools, Meta and Vita Florentis are joint controllers: Vita Florentis decides whether they load at all, which is only after your marketing consent, and Meta decides how it processes what it receives under its own terms. You can exercise your rights with either of us)
  • Google Analytics (for website statistics on public pages, only after analytics consent)
  • Google/YouTube (the privacy-enhanced video player is contacted only after you deliberately click its local placeholder; Google may then receive your IP address and browser or device information and may use its own cookies or local storage)
  • Google Workspace / Google Sheets (a temporary one-way observation mirror for Early Access and newsletter submissions during the controlled cutover; it is not the canonical record. It also stores an optional reason you choose to submit and, only after the relevant cookie consent, limited source and interaction fields)

Personal reflection answers are processed only by the technical service providers required to run the experience and carry out the choices you make. Apart from the one first-deed sentence in a reminder you explicitly enable, reflection content is not included in transactional emails. It is never shared for advertising, profiling, commercial purposes or AI training.

Some providers listed above are international and may process personal data outside the European Economic Area. Where this happens, Vita Florentis uses the transfer mechanism available in the provider agreement, such as an applicable adequacy decision or the European Commission’s Standard Contractual Clauses, and limits the data sent to what is needed for that service. Provider locations and mechanisms can change; you can ask for current information using the contact address below. You can also request a copy of the applicable Standard Contractual Clauses using the contact details at the end of this notice.

  • Your answers and letters: encrypted until you delete them yourself, successfully save them through your browser's native file picker, explicitly confirm that a fallback download is safely stored, or 30 days pass, whichever comes first
  • Legacy name-pronunciation records and generated name audio: no new records are created after the human-only release. Existing records in the private pronunciation library are deleted automatically after 24 months without use; a valid deletion request may remove them sooner
  • Legacy ElevenLabs name processing: names and generated audio from before the human-only release may remain in the provider history. The current API does not expose a fixed automatic deletion period, so no shorter provider retention period is promised here. No new participant or recipient names are sent after this release
  • Optional first-deed yearly copy: only that one chosen sentence, stored separately with encryption until you turn the opt-in off, delete your account or replace it with a newer opted-in deed
  • Optional 48-hour first-deed copy: encrypted until the email is sent, you turn the opt-in off, a refund is issued or account deletion occurs, or 72 hours pass, whichever comes first
  • Public Messages for the World: retained based on your explicit choice to make them public and removable on request
  • Local browser resume draft: configured to expire 30 days after it was last saved and removed while the site remains open or on the next site visit after expiry; removed sooner when you complete the experience or clear this site’s browser data
  • Local reservation recognition: up to 50 one-way email hashes remain on your device until you clear this site’s browser data
  • Public-wall candles: up to 5,000 public message IDs remain on your device until you unlight them or clear this site’s browser data. The corresponding salted server deduplication hash remains while that candle or report record and the public message exist; an account-derived candle hash is also removed when the account is deleted
  • Post-hour testimonials: kept separately from your answers; published only with your explicit consent and removable on request. Private feedback without publication consent is deleted within 30 days
  • Technical delivery data: only as long as needed for delivery, security and error handling
  • Temporary checkout handoff data, hashed consent-decision IDs and Meta browser identifiers: deleted automatically within 30 days
  • Minimal campaign fields attached to a completed lead or order: kept with that lead or order only as long as needed for its stated purpose and applicable recordkeeping requirements
  • Account and purchase contact details: while the account or purchase relationship exists and as long as applicable recordkeeping rules require
  • Early Access and newsletter contact details: until you unsubscribe or withdraw consent; a minimal suppression record may remain where needed to honor the opt-out or comply with a legal requirement
  • Voices contact messages: only as long as reasonably needed to answer your inquiry, explore the collaboration you requested and keep any resulting necessary business records
  • Limited refund anti-abuse identity record: normalized email plus Stripe customer and payment-method references, retained only as long as needed to enforce the once-per-person satisfaction promise
  • Server and provider-status logs: kept for as short a time as reasonably possible for security, reliability, delivery and troubleshooting
  • Website measurement records: the visitor identifier and country are removed after 180 days; the page count itself stays, without anything that points to a person
  • Consent evidence: kept permanently in an immutable form, containing only the consent version, language, and time. It contains no name, email address, or reflection content, and it remains after your writing and account are deleted because it proves that consent was properly requested

Nothing is kept longer than necessary.

Encrypted platform backups of the database run a few days behind the live system, so deleted data can briefly survive there. If a backup is ever restored, the deletions made since are applied again to the restored data.

The legal basis depends on what you choose to do:

  • Performance of a contract, or steps you request before entering into one: account creation, orders, access, delivery of the experience, secure downloads and requested steps around a possible Voices collaboration
  • Consent: Early Access and newsletter emails, an optional Early Access reason you choose to submit, optional first-deed reminders, optional analytics and marketing, and publication of a wall message or testimonial. You can withdraw consent for future processing at any time
  • Legitimate interests: security, fraud prevention, error handling, responding to contact messages, the public-page count whose measurement row stores no visitor ID, content-free product-reliability measurement and one-way deduplication of functional public-wall candles and reports. These interests are balanced against your privacy; those measurements do not contain reflection content. You may object to this processing
  • Explicit consent for special categories (art. 9(2)(a) GDPR, and art. 32 of the Dutch GDPR Implementation Act for criminal-law data): the sensitive personal data about yourself that you choose to write during the experience, such as your health or your beliefs. This consent covers only that sensitive layer; the ordinary storage and use of your reflections rest on the agreement. You give it as a separate step before the experience opens and withdraw it by erasing your words. A pseudonymous record that consent was given, with its version and time, remains as proof after erasure
  • Legal obligation: financial and transaction records that Vita Florentis must retain

You have the right to:

  • access your personal data
  • request corrections
  • request deletion
  • request restriction of processing
  • object to processing
  • request data portability
  • withdraw consent for future processing at any time
  • file a complaint with your local data protection authority

You can reach me at julian@lasthourexperience.com. You will receive a response within one month. If a request is complex, I may extend the deadline by up to two months, and I will tell you within the first month.

You can delete your product account from the account page. Removal requests for a public message, testimonial or complete cross-system record are handled within 72 hours; a complete request also covers the Supabase CRM record, the temporary Google Sheet mirror and Convex/Resend delivery records. Payment records required by law and the limited anti-abuse identity record (normalized email plus Stripe customer and payment-method references) required to enforce the once-per-person refund promise remain as limited exceptions.

This section applies if you live in a US state with a consumer privacy law, including California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Virginia and the other states whose laws are in force. It adds to the rest of this policy; it does not replace it.

What is collected and why

Using the categories these laws use, Vita Florentis may process: identifiers such as your name, email address, IP address, a random pseudonymous visitor ID and cookie or advertising identifiers; commercial information such as your order, purchase value and currency; internet or network activity such as public pages viewed, referrer, language and selected engagement events; approximate location derived from your IP address; and the content you write yourself inside the experience or in a contact or wall message. The purposes are listed above under “Why I process your data”, and the retention periods under “Data retention”.

Selling and sharing

Vita Florentis does not sell personal information for money and has not done so in the past twelve months. It does “share” personal information for cross-context behavioral advertising in one specific case: after you give marketing consent, Meta Pixel and the Meta Conversions API may receive identifiers, internet or network activity and commercial information about public-page visits, signups and purchases. That is the only sharing that takes place. Your reflection answers, letters and messages are never shared, sold or used for advertising, profiling or AI training.

Personal information is disclosed to the service providers listed above under “Who your data is shared with”, each for the purpose described there.

Global Privacy Control is honored

If your browser or extension sends a Global Privacy Control signal, it is treated as a valid opt-out of sale and sharing. Marketing measurement stays off, the Meta Pixel is not loaded and any pending server-side marketing event is canceled, without any further action from you. You can see the confirmation in Your Privacy Choices, at the bottom of every page.

You can also make the choice yourself at any time through Your Privacy Choices. Opting out is exactly as easy as opting in.

Sensitive personal information

Any free-text field inside the experience can lead you to write about your health, religious or philosophical beliefs, or other sensitive personal information about yourself. It is used only to deliver the experience you asked for: to resume your hour, to build your personal document and to publish something you explicitly choose. It is never used to infer characteristics about you and never for advertising. You have the right to limit its use to those purposes, and that limit is already how the service works. If you live in Washington, the separate Consumer Health Data Privacy Policy linked in the footer applies as well.

Your rights and how to use them

  • Know what is collected, used, disclosed and shared, and get a copy in a portable format
  • Correct inaccurate personal information
  • Delete personal information, subject to legal retention duties such as tax records
  • Opt out of sale or sharing, and of targeted advertising
  • Limit the use of sensitive personal information
  • Appeal a denied request, where your state provides that right
  • Not be treated differently for using any of these rights

Email julian@lasthourexperience.com with the request and the email address you used here, so the request can be matched to your data. You get a reply within 45 days, extendable once by another 45 days if the request is complex, in which case you are told before the first period ends. An authorized agent may act for you with written permission. There is no charge unless a request is manifestly unfounded or excessive.

The Last Hour Experience is for adults. You must be 18 or older to take part. If I learn that someone under 18 has used the service, I block access and delete their reflections and account data, except for the minimal records I need for a refund, a legal obligation, misuse prevention or a legal claim.

This privacy policy is governed by the laws of the Netherlands.

This section explains how I use cookies and similar technologies on this website.

I use essential storage to make the website work and a first-party request whose measurement row stores no visitor ID to count public page loads. With your permission, I may also use analytics and marketing technologies to understand public-site use and measure campaigns.


What are cookies?

Cookies are small text files that are stored on your device when you visit a website. They help the website remember information about your visit and can support basic functionality, analytics, and marketing.


Which cookies do I use?

Essential cookies

This storage remembers your cookie and language choices, supports security and sessions, recognizes an existing reservation, remembers simple interface dismissals, and keeps an active-device resume draft. A random consent-decision ID is used only to honor withdrawal of pending server-side marketing measurement. Essential storage cannot be turned off through the cookie preferences panel.

Cookieless public page count

A first-party request counts clean public page paths and language. It sets no cookie or visitor ID, and its measurement row stores no query string or browsing profile. It counts page loads, not unique people, and is never sent from private pages. As with any web request, hosting and network providers may temporarily process request metadata such as an IP address and browser information for delivery and security.

Analytics cookies

These cookies help me understand how visitors use the website, which pages are viewed, and how the experience can be improved. I only use these cookies if you give permission.

Marketing cookies

These cookies help me measure advertising campaigns and may help me show relevant ads. I only use these cookies if you give permission.

Voluntary lead and order attribution

When you voluntarily submit a form or start an order, available first-touch and UTM source, medium, campaign, content and ad-set fields may be linked to that conversion. Without analytics consent, this does not create a persistent visitor ID or browsing profile.

If you answer the optional Early Access question about what made you pause, that text is form content, not a cookie or analytics event. Its destinations and handling are explained in the sections above.


Cookie overview

The exact cookies used may depend on your browser, device, consent choice, and the tools active on the website. The table below describes the main types of cookies and similar technologies that may be used.

CategoryExamplesPurposeUsed when
EssentialCookie consent preference (lhe_cookie_consent_v2), random consent-decision ID, language preference, basic security/session storage, signed candle-device tokenTo remember your cookie choice, display the correct language, keep the website functioning properly, honor withdrawal of pending server-side marketing measurement, and prevent a signed-out writer from being treated as a stranger to their own message. The server stores only a one-way token digest with the public message and author IDs, never the raw token, message text, answer text or email address.Always active; your choice itself is kept for 180 days, then I ask again
Essential experience resumelhe_question_session_v1: answers, letters, message and resume state in this browser’s local storageTo pause and continue on the same device. This local copy is not encrypted at rest by Last Hour Experience.During an active experience; removed on completion and configured to expire 30 days after its last save. If the site was closed at expiry, removal occurs on the next visit.
Essential reservation recognitionlhx_reserved_v1: up to 50 one-way SHA-256 hashes of lowercased reservation email addressesTo recognize on this device that an email reservation was already completed, without storing the plain email in browser storage.After a completed reservation, until you clear this site’s browser data
Essential public-wall candle memorylhe_wall_candles_v1: up to 5,000 public message IDs for which this browser lit a candleTo show and undo your candle choice on this device. The server separately uses a salted one-way deduplication hash to prevent duplicate candles and reports.After you light a candle, until you unlight it or clear this site’s browser data
Essential interface choiceslhe_signup_popup_dismissed, plus the older blog_popup_dismissed and site_signup_popup_dismissed keys if already present; lhe_reserve_cta_dismissedTo keep a dismissed signup popup closed and hide the dismissed mobile reservation bar.Your popup choice is stored persistently until you clear site data, and a session copy is kept until the session ends; the mobile-bar choice lasts until the browser session ends
Cookieless public-page countClean path, language and server time; no cookie or visitor IDTo count public page loads without identifying a visitor or building a browsing profile.Always active on public pages only
AnalyticsFirst-party lhe_visitor_id and lhe_first_touch cookies (up to 12 months), selected interactions, Google Analytics 4 (_ga and _ga_*, Google Consent Mode v2, IP anonymized), and Cloudflare Web Analytics/RUMTo understand how public pages are used and how they perform technically, preserve one coarse first-touch source (direct, ad, wall or Voice), and improve the experience. No click IDs or UTM values are stored in these first-party cookies.Only after analytics consent, on public pages only
MarketingMeta Pixel (_fbp and _fbc) and consented Meta Conversions API events for public visits, signups and purchasesTo measure campaigns and voluntary conversions without sending reflection content.Only after marketing consent
Voluntary lead/order attributionFirst-touch and available UTM source, medium, campaign, content and ad setTo attribute a form submission or order without adding reflection content.Only when you submit a form or start an order
YouTubePrivacy-enhanced youtube-nocookie.com playerTo play a video only after your deliberate click.Only after you click the local video placeholder

I do not sell personal data. I only use non-essential cookies after consent. You can change your cookie preferences at any time through Your Privacy Choices, at the bottom of every page.


Third-party technologies

The public marketing website uses Google Analytics 4 and Cloudflare Web Analytics/RUM only after analytics consent, and Meta Pixel plus Meta Conversions API only after marketing consent. These analytics and advertising tools are not loaded in private account, checkout, gift-payment, access, download or experience areas. YouTube is contacted only after you deliberately click a local video placeholder; Google may then receive request metadata such as your IP address, browser and device information and may use its own cookies or local storage. Stripe is contacted only when you enter a payment flow.

You can review or change your privacy choices for this website at any time, in any language and from any page.

Vita Florentis · Registered business address: Herengracht 320, 1016 CE Amsterdam, The Netherlands · Dutch Chamber of Commerce: 82811148 · VAT ID: NL003735337B09