COOKIE & TERMINAL-STORAGE POLICY
Last updated: 12 August 2026
This policy covers cookies, local storage, session storage, pixels, SDK identifiers and similar technologies that store information on, or access information from, a user's device.
1. Legal rule
Under the Romanian ePrivacy framework, terminal storage/access generally requires prior clear information and consent, except where the operation is technically necessary for transmitting a communication or strictly necessary to provide an information-society service expressly requested by the user. [S5]
2. TCM launch rule
TCM will operate necessary-first:
- strictly necessary security, session, checkout-continuity and preference storage may operate where the legal exception applies;
- analytics, attribution, advertising, retargeting and behavioural technologies must remain off until valid consent where consent is required;
- refusing non-essential storage must be as easy as accepting it;
- no pre-ticked or implied opt-in for non-essential categories;
- users can reopen settings and withdraw consent.
3. Current implementation inventory to verify
The current product uses browser sessionStorage for composer and checkout continuity. It also sets a short-lived, first-party, HttpOnly recovery cookie after Checkout creation so the buyer can recover the paid private recipient link if the Stripe redirect returns without the browser session context. The recovery credential is scoped to the private-claim endpoint, bound to the Checkout Session, cleared after successful use and unavailable to frontend JavaScript. These mechanisms are functionally tied to the user's requested purchase/delivery flow and should be documented as strictly necessary only to the extent the implementation truly needs them. The production audit must also inspect Cloudflare, Stripe and any analytics libraries for additional cookies/storage.
4. Required production inventory
Before live, populate a table for every technology: name/key, provider, category, purpose, first/third party, lifespan, data accessed, legal basis, transfer location, and whether it loads before consent.
Necessary (draft placeholder):
tcm.composer.*/ equivalent session storage - preserve composer during the requested flow - session - Pending before live: confirm exact key.tcm.checkout.*/ equivalent session storage - reconcile return from payment flow - session - Pending before live: confirm exact key.__Secure-tcm-claim-*first-party HttpOnly cookie - securely recover the paid private recipient link after the Stripe redirect - maximum 24 hours; cleared after successful claim - strictly necessary checkout/delivery continuity, production legal review pending.- security/rate-limit/load-balancer storage - Pending before live: inventory exact provider/key.
Optional:
- analytics - Pending before live: NONE ENABLED UNTIL CMP + inventory approved.
- advertising/retargeting - Pending before live: NONE ENABLED UNTIL explicit approval + consent implementation.
5. Consent interface specification
Banner/control: ACCEPT ALL | REJECT NON-ESSENTIAL | MANAGE. No visual coercion. “Manage” shows each optional purpose and provider. The choice is stored with consent version/timestamp and is changeable later.
6. Stripe / external checkout
When the user is redirected to Stripe, Stripe may use its own technologies under its own notice. TCM must accurately disclose the redirect and not classify Stripe's independent storage without reviewing the actual production integration.
7. Contact
Questions: /legal/privacy-about-you/#request.