Cookie & Local Storage Policy
How browser storage and similar technologies are used.
1. What this policy covers
UK PECR rules apply not only to cookies but also to localStorage, sessionStorage, authentication storage, scripts and other technologies that store information on, or access information from, a user’s device. Where personal data is involved, the UK GDPR also applies.
2. Current storage and access register
| Technology | Purpose | Classification / control |
|---|---|---|
| Firebase Authentication / phone verification | Maintains the verified phone session and protects account functions. | Necessary authentication/security functionality. |
| reCAPTCHA / Firebase security technology | Abuse prevention and secure phone/backend requests. | Security technology; no advertising purpose is intended. |
ysl_listing_cache_v1 | Operational listing cache used by the current application for continuity and recovery while synchronising with the cloud. | Operational storage. Cloud data remains the source of truth; Admin has a clear-cache control. |
ysl-seller-profile-v1 | Legacy convenience profile from earlier builds. | Removed. Build 0.24.6 deletes this legacy key and does not recreate it. |
| Retention review decisions (Owner browser) | Remembers Owner-only manual retention review decisions. | Admin operational storage; does not delete or alter source Firestore records. |
| Session reload guard | Prevents repeated reload loops when a new deployed version is detected. | Session-only technical safety storage. |
| Local change/throttle markers | Prevents excessive repeat presence/change actions and coordinates UI refresh. | Technical/security/operational storage. |
| Advertising / behavioural tracking | Advertising, profiling or cross-site tracking. | Not intentionally enabled. |
| Optional audience analytics | Audience measurement beyond current operational needs. | Not intentionally enabled. |
3. Consent and exceptions
Storage/access that is strictly necessary for a service requested by the user, authentication or proportionate security may be used without the normal consent requirement where the PECR exception applies. Optional storage must have an appropriate legal route. YSL does not treat a general Privacy Policy or continued browsing as consent.
The optional remembered seller profile is now controlled by an explicit user choice. No advertising or behavioural tracking will be enabled without a fresh legal assessment and, where required, prior valid consent.
4. Simple user experience
YSL does not intentionally enable advertising, behavioural tracking or optional audience analytics, and it does not keep a separate seller-contact convenience profile. Therefore the current build does not display a general consent banner. Browser settings can clear site data; clearing authentication or necessary technical storage may sign the user out or affect requested functions.
5. Change control
This register must be reviewed whenever YSL adds or materially changes an SDK, analytics tool, advertising service, payment provider, authentication/security provider or other storage/access technology. Non-exempt technology must not be pre-enabled before the required consent mechanism is in place.