Cookie Policy
Photodex uses browser storage and, in the proposed production image system, a Cloudflare delivery cookie. "Cookies" here includes similar storage and access technologies such as localStorage. This Policy is read with the Privacy Policy. The precise analytics and supplier inventory must be checked on the production domains before publication; the table distinguishes known application storage from planned delivery behaviour.
1. Storage used to provide requested functions
| Technology | Provider and purpose | Status | Duration known from audit |
|---|---|---|---|
base44_access_token, legacy token | Base44 authentication tokens in first-party localStorage; these are not HttpOnly cookies | Audited application | Persistent until logout, clearing or token expiry; exact expiry to confirm |
base44_app_id, base44_from_url, base44_functions_version, base44_app_base_url | Base44 routing, redirect and version configuration in localStorage | Audited application | Persistent; exact expiry to confirm |
Image-delivery session cookie at cdn.photodexapp.com | Cloudflare Worker validates a short-lived capability to serve authorised images and originals; planned Secure, HttpOnly and SameSite=Lax | Intended after migration; verify flags, scope, lifespan and revocation | Approximately one hour proposed, not yet verified |
| Checkout storage | Stripe may use cookies and other technologies to secure and complete embedded checkout | Provider configuration unverified | Inspect at checkout and confirm Stripe's actual names and lifetimes |
Authentication and a delivery session are intended to be strictly necessary for the requested Account and image access. Browser storage differs from a cookie: localStorage is not automatically sent with each request. The planned Cloudflare cookie would be used on the image subdomain, not as a replacement for the Base44 Account token.
2. Analytics and choices
The audited Base44 client enables built-in analytics by default and has no consent banner or opt-out gate. Whether its technology qualifies for the UK PECR statistical-purpose exception is not established: that depends on its actual purpose, data flows, recipients and a clear, simple, free way to object. If it does not qualify, any analytics storage/access requiring consent must be blocked until valid consent is given. Merely describing analytics here does not make current use compliant. Photodex must implement and test the correct control before this Policy is published, or disable the non-exempt analytics.
We do not currently describe advertising or cross-site profiling cookies as part of Photodex, but that must be checked against deployed scripts and provider tools. If we add them, we will give the required information and choice before deployment. Browser controls can clear or block storage; blocking essential authentication or image delivery may prevent features working. [Insert the verified analytics consent/objection control and location once implemented.] Contact info@photodexapp.com about these technologies.
3. Changes
We will update the inventory when Base44, Stripe, Cloudflare or our own code changes what is placed on or read from a visitor's device. The live implementation and this notice must agree, including on Public Link and checkout pages.