The local prototype currently has no non-essential cookies or tracking code. A decorative consent banner without an actual consent mechanism would be misleading. The final site must add a real preference control before any non-essential technology is enabled where consent is required.
1. Current prototype
As of September 1, 2026, the local static homepage and order prototype do not set cookies, use localStorage/sessionStorage, run analytics, embed advertising pixels or send form data to a server. Uploaded concept photos are previewed in browser memory only and are not transmitted.
This statement applies only to the current local files. It must not be published as an effective promise after a payment page, production intake, analytics script, chat tool, embedded media or fraud-prevention service is added without first repeating the audit.
2. Possible launch categories
The production service may require:
- strictly necessary technologies for security, load balancing, checkout state, private access, fraud prevention or a user-requested feature;
- functional technologies that remember an optional preference;
- analytics technologies that measure site use; and
- advertising technologies that support audience measurement or cross-site marketing.
Only necessary technology is part of the current launch design. Functional, analytics and advertising tools are not approved. Before any is enabled, the provider, purpose, data, duration and consent requirement must be recorded in an effective cookie table.
3. Third-party services
A hosted payment page or another third-party service may set its own cookies when a visitor chooses to open that service. The final site must identify the selected services and link to their notices without suggesting that Auromise controls every third-party cookie.
Pending final audit: Stripe checkout, Hostinger/CDN security, transactional email links, embedded media, support tools, Search Console verification and any analytics or advertising platform.
4. Consent and browser choices
Where law requires consent, a non-essential cookie or similar technology must remain disabled until the visitor makes a clear affirmative choice. Rejecting must be as accessible as accepting, optional purposes must not be bundled, and consent must be withdrawable.
Browser settings can delete or block some cookies, but browser controls are not a substitute for a site-level consent mechanism where one is legally required. Blocking necessary technology may prevent checkout or private-access features from working.
The current prototype does not alter its behavior in response to a browser “Do Not Track” signal because it contains no analytics, advertising or cross-site tracking. Before production, the actual provider behavior and any legally recognized opt-out signal, including Global Privacy Control where applicable, must be tested and accurately disclosed.
5. Required audit before launch
Before deployment, use a clean browser profile to inspect cookies, local storage, network calls, pixels, embedded resources, third-party redirects and Do Not Track/Global Privacy Control behavior on every public, checkout, intake and delivery page. Record the provider, purpose, duration, first/third-party status and legal basis for each technology.
If the audit confirms that only strictly necessary technology is present, the site may not require a consent banner in every jurisdiction, but it still needs a clear notice. The final conclusion must be checked for the actual target markets.
6. Contact and changes
Questions about cookies or tracking: [PRIVACY CONTACT EMAIL].
The effective notice must list the actual technologies in use and show a current effective date. It should be reviewed whenever a provider, embedded feature, analytics tag, advertising pixel, consent manager or checkout method changes.