Cookies & browser storage
Updated 8 October 2026
CardinalDL currently uses essential browser storage for sign-in, your selected package and encrypted chat. We do not load advertising, analytics or social tracking scripts. Fonts and product screenshots are served with the website. The same storage rules can apply to cookies and to technologies such as local storage.
Only essential storage is used.
Optional tracking is disabled and no optional category is currently available. You can review the local storage inventory and clear saved data in storage settings.
Storage inventory
| Item | Use | Lifetime |
|---|---|---|
cardinaldl.storage.notice Local storage, first party | Remember that you dismissed this version of the essential-storage notice. This is not consent to tracking. | Until you clear site data. The notice is shown again when its version changes. |
cardinaldl.website.session Local storage, first party | Keep your requested account session and rotate access credentials. | Removed on sign-out or when invalid credentials are cleared. Access tokens are valid for 120 seconds; refresh tokens for 30 days, renewed on rotation. A stale local entry can remain until the site clears it or you remove it. |
cardinaldl.checkout Local storage, first party | Preserve your configured package while you sign in and send it to sales. | Until the selection is submitted, replaced or cleared. No automatic timed deletion. |
cardinaldl.chat.backup:<account> Local storage, first party | Store your passphrase-encrypted chat key backup created when setting up chat. | Until you clear the local copy or browser data. Signing out does not erase it. |
cardinaldl.chat.pin:<account>:<contact> Local storage, first party | Remember trusted contact safety codes and detect a changed chat identity. | Until you clear trusted codes or browser data. Signing out does not erase them. |
The unlocked chat key is held in browser memory and is locked when you sign out or close that browsing context. Session coordination between open tabs uses browser messaging and locks; it is not an advertising identifier. The application does not set an HTTP cookie for these functions.
EU storage rules and consent
Storage strictly necessary to deliver a service you requested may be used without optional cookie consent under applicable ePrivacy rules. The account session is written when you sign in, the package draft when you submit a selection, and chat material when you request chat setup or trust a contact. These functions are not permission for unrelated tracking.
If non-essential storage is introduced, it must stay off until you give a specific, informed choice. Rejecting it must be as accessible as accepting it, and you must be able to change or withdraw that choice without losing access to the public website. Continuing to browse or closing a notice is not consent. Necessary personal-data processing is explained separately in the privacy notice .
Clearing local data
Use Storage settings to remove the saved package and review the local inventory. Sign out to remove the current session; revoke other sessions through the account portal. Your browser provides controls to inspect, block or remove site storage, including chat recovery material and trust codes. Blocking all storage can prevent persistent sign-in, package handoff or contact safety checks from working.
Keep an encrypted chat recovery file and your passphrase before clearing chat data. Removing safety codes means you must verify contacts again. Clearing browser storage does not erase your account, server-side messages, licence records or an encrypted key backup held by the account service. You can request erasure under the conditions in the privacy notice.
More information: EU guidance on online privacy and cookies .