Cookie policy
Last updated: 05/08/2026
1. Scope
This policy covers cookies and similar browser technologies used by Elegant Render, including localStorage, sessionStorage, pixels, scripts, SDKs, IndexedDB, and measurement requests. Names can vary by browser, secure-domain prefix, provider release, and tag configuration, so the tables describe both known names and their functions.
2. Your choices
Necessary technologies support a service you request, security, sign-in, checkout, and storing your choice. Where permitted, they operate without consent. Optional analytics, marketing, and session recording are controlled separately and are off until you opt in where consent is required.
Reopen at any time. Withdrawing consent stops new optional browser collection on this site but does not reverse processing that already occurred. You can also clear site data in your browser; doing so may sign you out, remove your estimate, clear chat state, or reset your consent choice.
3. Necessary and functional technologies
Used to provide features you request, protect forms and accounts, complete checkout, and remember privacy choices. PayPal and Turnstile data is triggered only when the related feature is used and configured.
| Name | Storage | Provider | Purpose | Retention |
|---|---|---|---|---|
| authjs.session-token / __Secure-authjs.session-token | Cookie | Elegant Render (Auth.js) | Keeps an authenticated account signed in and protects portal routes. | Until logout or session expiry; normally up to 30 days |
| authjs.csrf-token / __Host-authjs.csrf-token | Cookie | Elegant Render (Auth.js) | Protects authentication requests against cross-site request forgery. | Browser session or authentication-flow expiry |
| authjs.callback-url / __Secure-authjs.callback-url | Cookie | Elegant Render (Auth.js) | Returns you to the intended page after authentication. | Browser session or authentication-flow expiry |
| er-consent | localStorage | Elegant Render | Stores the categories you accepted or refused and the decision time. | Until you change the choice or clear browser storage |
| er-checkout-quote and er-checkout-withdrawal-waived-at | sessionStorage | Elegant Render | Carries the selected estimate and withdrawal choice into checkout. | Browser-tab session; cleared after checkout where possible |
| er-chat-* and er-chat-proposal | sessionStorage + localStorage | Elegant Render | Keeps chat state, a pseudonymous chat session ID, and a proposed estimate while you navigate the site. | Messages and UI state: browser-tab session; session ID: until browser storage is cleared |
| Turnstile security data (names may vary) | Cookie + script request | Cloudflare | Checks public forms for automated abuse when Turnstile is enabled. | Controlled by Cloudflare and limited to the security purpose |
| PayPal SDK and checkout cookies | Cookie + script request | PayPal | Provides payment controls, fraud prevention, approval, and payment-status handling after you open PayPal checkout. | Controlled by PayPal; varies by cookie, account, and funding source |
4. Analytics and performance
Browser analytics and performance tools that are consent-gated where required. Limited server-side logs and aggregate, cookieless measurements may operate for security and reliability where the law permits.
| Name | Storage | Provider | Purpose | Retention |
|---|---|---|---|---|
| Vercel Web Analytics and Speed Insights | Measurement request; designed to operate without a cross-site advertising profile | Vercel | Measures aggregate page usage and real-user performance. | Under the Vercel project configuration and provider retention rules |
| ph_* and provider-generated identifiers | Cookie + localStorage | PostHog | Measures product usage, journeys, and conversion funnels after analytics consent. | Up to 12 months unless deleted sooner or the provider configuration changes |
| _ga and _ga_* | Cookie | Google Analytics 4 | Distinguishes visits and measures traffic and page usage after analytics consent. | Up to 24 months unless deleted sooner or the tag configuration changes |
| Sentry error and performance context | Script request + browser session storage where used | Sentry (Functional Software, Inc.) | Diagnoses browser errors and performance problems after analytics consent. Server-side security and error logs can also be processed independently of browser consent where necessary. | According to the Sentry project configuration and incident needs |
5. Marketing measurement
Used only after marketing consent and only when the relevant tag is configured. LinkedIn tracking is not currently active in the production code covered by this policy.
| Name | Storage | Provider | Purpose | Retention |
|---|---|---|---|---|
| Google Tag Manager | Script + dataLayer | Loads only the tags permitted by your analytics and marketing choices. Tag Manager does not itself create an advertising profile, but tags configured inside it may use identifiers. | During page load; downstream tag retention is listed separately | |
| Google Ads and conversion identifiers, including _gcl_* where configured | Cookie + script request | Attributes inquiries and paid orders to advertising and measures campaign performance after marketing consent. | Depends on the enabled Google tag and campaign configuration |
6. Session recording
Used only after separate session-recording consent. Recording configurations are intended to mask sensitive fields, but you should still avoid entering unnecessary sensitive information.
| Name | Storage | Provider | Purpose | Retention |
|---|---|---|---|---|
| PostHog session recording data | Cookie + localStorage + browser recording requests | PostHog | Records masked or redacted interaction sessions to find usability problems after separate recording consent. | Up to 12 months unless deleted sooner or the provider configuration changes |
| Sentry Replay session data | sessionStorage or IndexedDB + recording requests | Sentry (Functional Software, Inc.) | Captures replay context around technical errors after separate recording consent. | According to the Sentry Replay project configuration; normally no more than 30 days |
7. Browser privacy signals
You can always use our cookie settings to refuse optional tracking. Some browsers also send Global Privacy Control or other preference signals. Where a signal creates a legally binding opt-out and our technology can recognise it, we treat it as an opt-out from sale, sharing, and targeted advertising. Browser “Do Not Track” signals do not have one consistent legal or technical meaning, so cookie settings remain the reliable control on this site.
8. More information
The privacy policy explains the personal data, legal bases, recipients, international transfers, retention rules, and rights connected with these tools. Questions can be sent to info@elegantrender.com.
