LEGAL DRAFT · FINAL COUNSEL APPROVAL REQUIRED
Cookies and Browser Storage Notice Draft
Draft updated: 15.08.2026
Current inventory
The public marketing pages do not currently install advertising or behavioural-analytics cookies. The codebase contains no Google Analytics, Meta Pixel or equivalent tracker, so the site does not display a misleading consent banner. Cookies and browser-storage technologies are described separately here.
Authentication storage
Supabase Auth may use browser storage in staff and customer portals to maintain a secure authenticated session; the exact key can vary by client version and project URL. It is used for login and authorisation, not advertising profiles.
Application storage
The single-use ganu.pos.return.v1 record contains no direct identity field, but is an opaque/pseudonymous security value that can be linked to an order. It is treated as sensitive, kept in sessionStorage for at most one hour and removed on a terminal result. ganu.panel.* is local-development/demo state. ganu.musteri.session and ganu.ortak.session are legacy access-code surfaces; they are not a legitimate production authentication basis and must remain disabled/fail-closed after cloud cutover.
Future optional technologies
If analytics or advertising is introduced, non-essential storage must remain off until an equal, prior choice to Accept, Reject or manage Preferences is provided, and this inventory must be updated.