LEGAL & COMPLIANCE · V1.2
THIS COST ME
HomeTermsPrivacyReport
ENRO
ON THIS PAGE
1. Legal rule2. TCM storage rule3. Current implementation inventory4. Storage inventory5. Consent interface specification6. Stripe / external checkout7. Contact
LEGAL

COOKIE & TERMINAL-STORAGE POLICY

Version 1.2 · Last updated 3 October 2026 · Effective date: 18 August 2026

COOKIE & TERMINAL-STORAGE POLICY

Last updated: 3 October 2026

This policy covers cookies, local storage, session storage, pixels, SDK identifiers and similar technologies that store information on, or access information from, a user's device.

1. Legal rule

Under the Romanian ePrivacy framework, terminal storage/access generally requires prior clear information and consent, except where the operation is technically necessary for transmitting a communication or strictly necessary to provide an information-society service expressly requested by the user.

2. TCM storage rule

TCM will operate necessary-first:

  • strictly necessary security, session, checkout-continuity and preference storage may operate where the legal exception applies;
  • analytics, attribution, advertising, retargeting and behavioural technologies must remain off until valid consent where consent is required;
  • refusing non-essential storage must be as easy as accepting it;
  • no pre-ticked or implied opt-in for non-essential categories;
  • users can reopen settings and withdraw consent.

3. Current implementation inventory

The current product uses browser sessionStorage for composer and checkout continuity, localStorage for sender-side recovery of a private recipient link, and a short-lived first-party HttpOnly cookie so the buyer can recover the paid private recipient link if the Stripe redirect returns without the browser session context. The HttpOnly recovery credential is scoped to the private-claim endpoint, bound to the Checkout Session, cleared after successful use and unavailable to frontend JavaScript.

4. Storage inventory

Necessary / functional storage currently used by TCM:

  • tcm.composer.v8272 — first-party session storage used to preserve composer state during the requested flow; lifetime: browser session.
  • tcm.checkout.<session_id> — first-party session storage used to reconcile the Stripe return and private-link delivery context; lifetime: browser session.
  • tcm.sender-recovery.v1 — first-party local storage containing sender-side recovery context for a generated private recipient link; automatically treated as expired by the frontend after up to 90 days and removable by the sender through the recovery controls.
  • __Secure-tcm-claim-* — first-party HttpOnly cookie used as a secure fallback to recover the paid private recipient link after Stripe checkout; maximum lifetime 24 hours and cleared after successful claim.
  • Stripe and Cloudflare may use provider-specific storage required for payment, security, fraud prevention or infrastructure operation under their own applicable notices.

Optional storage: Google Analytics 4 is configured for product and acquisition measurement and loads only after the user grants analytics consent. Meta Pixel is configured for Facebook/Instagram campaign measurement and attribution and loads only after the user grants marketing-measurement consent. Neither tool loads before its applicable consent choice.

5. Consent interface specification

Banner/control: ACCEPT ALL | REJECT NON-ESSENTIAL | MANAGE. No visual coercion. “Manage” shows each optional purpose and provider. The current optional purposes are Analytics — Google Analytics 4 (Google LLC) and Marketing measurement — Meta Pixel (Meta). The choice is stored with consent version/timestamp and is changeable later through COOKIE SETTINGS.

6. Stripe / external checkout

When the user is redirected to Stripe, Stripe may use its own technologies under its own notice. TCM must accurately disclose the redirect and not classify Stripe's independent storage without reviewing the actual production integration.

7. Contact

Questions: /legal/privacy-about-you/#request.

IMPLEMENTATION INVENTORY — 3 OCTOBER 2026
TCM uses first-party session storage for composer/checkout continuity, sender-recovery local storage, and a server-set first-party HttpOnly checkout-recovery cookie. Google Analytics 4 is configured for consent-aware product/acquisition measurement. Meta Pixel is configured for consent-aware Facebook/Instagram campaign measurement. The Google tag and Meta Pixel are not loaded until the user grants the corresponding optional consent.
Name / keyProviderPurposeLifetimeClassification
tcm.composer.v8272THIS COST MEComposer continuityBrowser sessionStrictly necessary / functional
tcm.checkout.<session_id>THIS COST MEStripe return and private-link delivery continuityBrowser sessionStrictly necessary / functional
tcm.sender-recovery.v1THIS COST MESender-side recovery of a generated private recipient linkUp to 90 daysStrictly necessary / functional
__Secure-tcm-claim-*THIS COST ME (HttpOnly)Secure fallback recovery after checkoutUp to 24 hours; cleared after claimStrictly necessary / functional
tcm.analytics-consent.v1THIS COST MEStores optional analytics and marketing-measurement consent choices, version and timestampUntil changed/cleared by the user or consent version changesStrictly necessary / preference
_ga, _ga_*Google Analytics 4 / Google LLCOptional analytics and product-funnel measurement after consentProvider-defined; commonly up to 2 yearsOptional analytics
_fbp, _fbc (where set)Meta Pixel / MetaOptional Facebook/Instagram campaign measurement and attribution after marketing consentProvider-defined; see Meta's current cookie noticeOptional marketing measurement
Stripe / Cloudflare storageThird-party infrastructurePayment, security, fraud prevention and infrastructureProvider-specificProvider-specific / necessary where applicable
On this page1. Legal rule2. TCM storage rule3. Current implementation inventory4. Storage inventory5. Consent interface specification6. Stripe / external checkout7. Contact
THIS COST ME
IF IT MATTERS, MAKE IT COST.
TermsPrivacyCookiesRefunds & WithdrawalContent RulesReport ContentLegal NoticeDMCATake It DownIf someone wrote about you
GHERVAN CĂTĂLIN PERSOANĂ FIZICĂ AUTORIZATĂ · CUI 55120454 · TRADE REGISTER F2026034031001 · EUID ROONRC.F2026034031001
NEPLĂTITOR DE TVA · EMAIL: LEGAL@THISCOSTME.COM · PHONE: +40 745 658 615