COOKIE & TERMINAL-STORAGE POLICY
Last updated: 3 October 2026
This policy covers cookies, local storage, session storage, pixels, SDK identifiers and similar technologies that store information on, or access information from, a user's device.
1. Legal rule
Under the Romanian ePrivacy framework, terminal storage/access generally requires prior clear information and consent, except where the operation is technically necessary for transmitting a communication or strictly necessary to provide an information-society service expressly requested by the user.
2. TCM storage rule
TCM will operate necessary-first:
- strictly necessary security, session, checkout-continuity and preference storage may operate where the legal exception applies;
- analytics, attribution, advertising, retargeting and behavioural technologies must remain off until valid consent where consent is required;
- refusing non-essential storage must be as easy as accepting it;
- no pre-ticked or implied opt-in for non-essential categories;
- users can reopen settings and withdraw consent.
3. Current implementation inventory
The current product uses browser sessionStorage for composer and checkout continuity, localStorage for sender-side recovery of a private recipient link, and a short-lived first-party HttpOnly cookie so the buyer can recover the paid private recipient link if the Stripe redirect returns without the browser session context. The HttpOnly recovery credential is scoped to the private-claim endpoint, bound to the Checkout Session, cleared after successful use and unavailable to frontend JavaScript.
4. Storage inventory
Necessary / functional storage currently used by TCM:
tcm.composer.v8272— first-party session storage used to preserve composer state during the requested flow; lifetime: browser session.tcm.checkout.<session_id>— first-party session storage used to reconcile the Stripe return and private-link delivery context; lifetime: browser session.tcm.sender-recovery.v1— first-party local storage containing sender-side recovery context for a generated private recipient link; automatically treated as expired by the frontend after up to 90 days and removable by the sender through the recovery controls.__Secure-tcm-claim-*— first-party HttpOnly cookie used as a secure fallback to recover the paid private recipient link after Stripe checkout; maximum lifetime 24 hours and cleared after successful claim.- Stripe and Cloudflare may use provider-specific storage required for payment, security, fraud prevention or infrastructure operation under their own applicable notices.
Optional storage: Google Analytics 4 is configured for product and acquisition measurement and loads only after the user grants analytics consent. Meta Pixel is configured for Facebook/Instagram campaign measurement and attribution and loads only after the user grants marketing-measurement consent. Neither tool loads before its applicable consent choice.
5. Consent interface specification
Banner/control: ACCEPT ALL | REJECT NON-ESSENTIAL | MANAGE. No visual coercion. “Manage” shows each optional purpose and provider. The current optional purposes are Analytics — Google Analytics 4 (Google LLC) and Marketing measurement — Meta Pixel (Meta). The choice is stored with consent version/timestamp and is changeable later through COOKIE SETTINGS.
6. Stripe / external checkout
When the user is redirected to Stripe, Stripe may use its own technologies under its own notice. TCM must accurately disclose the redirect and not classify Stripe's independent storage without reviewing the actual production integration.
7. Contact
Questions: /legal/privacy-about-you/#request.