LEGAL & COMPLIANCE · V1.0
THIS COST ME
HomeTermsPrivacyReport
ENRO
ON THIS PAGE
1. Legal rule2. TCM launch rule3. Current implementation inventory to verify4. Required production inventory5. Consent interface specification6. Stripe / external checkout7. Contact
LEGAL

COOKIE & TERMINAL-STORAGE POLICY

Version 1.0 · Last updated 12 August 2026 · Effective date: pending real-money go-live
PRE-LAUNCH LEGAL DRAFT. REAL-MONEY LIVE IS NOT CLEARED WHILE P0 ITEMS REMAIN OPEN.

COOKIE & TERMINAL-STORAGE POLICY

Last updated: 12 August 2026

This policy covers cookies, local storage, session storage, pixels, SDK identifiers and similar technologies that store information on, or access information from, a user's device.

1. Legal rule

Under the Romanian ePrivacy framework, terminal storage/access generally requires prior clear information and consent, except where the operation is technically necessary for transmitting a communication or strictly necessary to provide an information-society service expressly requested by the user. [S5]

2. TCM launch rule

TCM will operate necessary-first:

  • strictly necessary security, session, checkout-continuity and preference storage may operate where the legal exception applies;
  • analytics, attribution, advertising, retargeting and behavioural technologies must remain off until valid consent where consent is required;
  • refusing non-essential storage must be as easy as accepting it;
  • no pre-ticked or implied opt-in for non-essential categories;
  • users can reopen settings and withdraw consent.

3. Current implementation inventory to verify

The current product uses browser sessionStorage for composer and checkout continuity. It also sets a short-lived, first-party, HttpOnly recovery cookie after Checkout creation so the buyer can recover the paid private recipient link if the Stripe redirect returns without the browser session context. The recovery credential is scoped to the private-claim endpoint, bound to the Checkout Session, cleared after successful use and unavailable to frontend JavaScript. These mechanisms are functionally tied to the user's requested purchase/delivery flow and should be documented as strictly necessary only to the extent the implementation truly needs them. The production audit must also inspect Cloudflare, Stripe and any analytics libraries for additional cookies/storage.

4. Required production inventory

Before live, populate a table for every technology: name/key, provider, category, purpose, first/third party, lifespan, data accessed, legal basis, transfer location, and whether it loads before consent.

Necessary (draft placeholder):

  • tcm.composer.* / equivalent session storage - preserve composer during the requested flow - session - Pending before live: confirm exact key.
  • tcm.checkout.* / equivalent session storage - reconcile return from payment flow - session - Pending before live: confirm exact key.
  • __Secure-tcm-claim-* first-party HttpOnly cookie - securely recover the paid private recipient link after the Stripe redirect - maximum 24 hours; cleared after successful claim - strictly necessary checkout/delivery continuity, production legal review pending.
  • security/rate-limit/load-balancer storage - Pending before live: inventory exact provider/key.

Optional:

  • analytics - Pending before live: NONE ENABLED UNTIL CMP + inventory approved.
  • advertising/retargeting - Pending before live: NONE ENABLED UNTIL explicit approval + consent implementation.

5. Consent interface specification

Banner/control: ACCEPT ALL | REJECT NON-ESSENTIAL | MANAGE. No visual coercion. “Manage” shows each optional purpose and provider. The choice is stored with consent version/timestamp and is changeable later.

6. Stripe / external checkout

When the user is redirected to Stripe, Stripe may use its own technologies under its own notice. TCM must accurately disclose the redirect and not classify Stripe's independent storage without reviewing the actual production integration.

7. Contact

Questions: /legal/privacy-about-you/#request.

V8.26.1 IMPLEMENTATION AUDIT — 13 AUGUST 2026
No analytics, advertising pixels, marketing SDKs, external script tags, localStorage writes or frontend document.cookie writes were found. Two first-party sessionStorage families and one server-set, first-party HttpOnly checkout-recovery cookie were identified for the requested composer/checkout/private-delivery flow. No optional tracking is enabled, so this build does not add a consent banner that would falsely imply optional tracking is present.
Name / keyProviderPurposeLifetimeClassification
tcm.composer.v826THIS COST ME (first party)Preserve composer state during the requested flowBrowser sessionStrictly necessary — production legal review pending
tcm.checkout.<session_id>THIS COST ME (first party)Reconcile the return from Stripe and recover PRIVATE delivery contextBrowser sessionStrictly necessary — production legal review pending
__Secure-tcm-claim-*THIS COST ME (first party, HttpOnly)Fallback recovery of the paid private recipient link; session-bound and cleared after claimUp to 24 hoursStrictly necessary — production legal review pending
Stripe / Cloudflare storageThird party / infrastructureMust be inventoried against the deployed production configurationProvider-specificP0 inventory required before live
On this page1. Legal rule2. TCM launch rule3. Current implementation inventory to verify4. Required production inventory5. Consent interface specification6. Stripe / external checkout7. Contact
THIS COST ME
IF IT MATTERS, MAKE IT COST.
TermsPrivacyCookiesRefunds & WithdrawalContent RulesReport ContentLegal NoticeDMCATake It DownIf someone wrote about you
GHERVAN CĂTĂLIN PERSOANĂ FIZICĂ AUTORIZATĂ · CUI 55120454 · TRADE REGISTER F2026034031001 · EUID ROONRC.F2026034031001
PUBLIC SUPPORT EMAIL · PHONE · VAT WORDING · DSA CONTACTS: P0 DATA REQUIRED BEFORE REAL-MONEY LIVE.