DRAFT — COOKIE/STORAGE AUDIT AND PROFESSIONAL REVIEW REQUIRED.
This policy must be reconciled with an actual production browser-storage audit before publication.
Current technical design to verify
Protected customer/admin surfaces use secure authentication/session mechanisms and CSRF protection. Optional Cloudflare Turnstile may be enabled. The public site and portals should be audited for cookies, local/session storage, third-party resources, analytics, payment redirects and any future marketing tools.
Strictly necessary storage
The final policy should identify necessary authentication/security storage by name, purpose, provider, domain, duration and whether it is first- or third-party.
Non-essential storage
Do not enable analytics, advertising or other non-essential cookies/storage without completing the applicable consent and disclosure analysis. This draft does not assert that such consent is or is not required in every market.
Controls
The production policy should explain how users can manage non-essential choices where applicable and how necessary security cookies behave after logout/expiry.