Necessary cookies and local preference currently identified
| Storage | Purpose | Observed controls |
|---|---|---|
| ripodoc_session | Authenticated workspace session. | HttpOnly, SameSite=Strict, Secure in production, path /, maximum age eight hours. |
| ripodoc_csrf | Same-origin state-change and CSRF defense. | SameSite=Strict, Secure in production, path /, maximum age one hour; used for double-submit validation. |
| localStorage: ripodoc-cookie-preferences-v1 | Remembers an accept or reject choice for optional categories that are not currently active. | Stored only in the visitor’s browser; records the choice, version, timestamp, and fixed false values for analytics and marketing. It does not enable a provider or transmit report data. |
Optional categories and settings
The public site currently has no active analytics, advertising, session-replay, marketing-pixel, support-chat, or experimentation SDK. The site presents accept, reject, and cookie-settings controls so a visitor can record a choice and reopen the settings from the footer. Necessary security cookies cannot be disabled where a visitor uses a private workspace.
Non-essential technology change control
Before any non-essential technology is enabled, RipoDoc must update this page, assess jurisdiction-specific consent requirements, identify the provider and data flow, apply the required consent and withdrawal control, and confirm the new technology does not activate before the applicable choice.
What remains pending
- 01
Final targeted jurisdictions and cookie-law assessment.
- 02
Confirmed RipoDoc hosted environment products, tag managers, analytics, advertising, chat, experiments, and session-replay configuration.
- 03
Owner-approved consent, withdrawal, retention, and provider-data-use process if a non-essential technology is introduced.