1. Assetora storage
assetora_cookie_consent — purpose: stores consent version and category choices; category: necessary; typical retention: up to 12 months. assetora_locale — purpose: remembers language preference; category: preference; typical retention: up to 12 months. assetora-theme or equivalent theme storage — purpose: remembers display theme; category: preference; retention depends on implementation.
Authentication/session identifiers may be stored by the configured authentication provider rather than under an Assetora-specific cookie name. Their exact production names and retention must match the deployed authentication configuration.
2. Third-party providers
Supabase or the configured authentication/database provider may use storage required for authentication and session security. Stripe or another configured payment provider may use fraud-prevention and payment-related technologies during checkout. Cloudflare Turnstile or another anti-bot provider may use limited storage or device signals for abuse prevention. Embedded-media providers may use cookies only when their content is loaded.
3. Production verification
This table must be kept synchronized with the technologies actually deployed. Before commercial launch and after any material provider change, the administrator should verify browser cookies, local storage and third-party requests in production and update this table so names, purposes, providers and retention periods are accurate.
Document control
Permanent URL: /legal/cookie-table. Previous versions: 1.0.