Cookie Policy

Photodex uses browser storage and, in the proposed production image system, a Cloudflare delivery cookie. "Cookies" here includes similar storage and access technologies such as localStorage. This Policy is read with the Privacy Policy. The precise analytics and supplier inventory must be checked on the production domains before publication; the table distinguishes known application storage from planned delivery behaviour.

1. Storage used to provide requested functions

TechnologyProvider and purposeStatusDuration known from audit
base44_access_token, legacy tokenBase44 authentication tokens in first-party localStorage; these are not HttpOnly cookiesAudited applicationPersistent until logout, clearing or token expiry; exact expiry to confirm
base44_app_id, base44_from_url, base44_functions_version, base44_app_base_urlBase44 routing, redirect and version configuration in localStorageAudited applicationPersistent; exact expiry to confirm
Image-delivery session cookie at cdn.photodexapp.comCloudflare Worker validates a short-lived capability to serve authorised images and originals; planned Secure, HttpOnly and SameSite=LaxIntended after migration; verify flags, scope, lifespan and revocationApproximately one hour proposed, not yet verified
Checkout storageStripe may use cookies and other technologies to secure and complete embedded checkoutProvider configuration unverifiedInspect at checkout and confirm Stripe's actual names and lifetimes

Authentication and a delivery session are intended to be strictly necessary for the requested Account and image access. Browser storage differs from a cookie: localStorage is not automatically sent with each request. The planned Cloudflare cookie would be used on the image subdomain, not as a replacement for the Base44 Account token.

2. Analytics and choices

The audited Base44 client enables built-in analytics by default and has no consent banner or opt-out gate. Whether its technology qualifies for the UK PECR statistical-purpose exception is not established: that depends on its actual purpose, data flows, recipients and a clear, simple, free way to object. If it does not qualify, any analytics storage/access requiring consent must be blocked until valid consent is given. Merely describing analytics here does not make current use compliant. Photodex must implement and test the correct control before this Policy is published, or disable the non-exempt analytics.

We do not currently describe advertising or cross-site profiling cookies as part of Photodex, but that must be checked against deployed scripts and provider tools. If we add them, we will give the required information and choice before deployment. Browser controls can clear or block storage; blocking essential authentication or image delivery may prevent features working. [Insert the verified analytics consent/objection control and location once implemented.] Contact info@photodexapp.com about these technologies.

3. Changes

We will update the inventory when Base44, Stripe, Cloudflare or our own code changes what is placed on or read from a visitor's device. The live implementation and this notice must agree, including on Public Link and checkout pages.