$ cat cookies.md

Cookie policy

Last updated: August 17, 2026

sha256 · cookies.ts

595927aa0cb35bef27e3aaeb5d1d60f06bf4f20705c1c75d179af7404ec14070

What are cookies?

When you visit ench.ro, small pieces of data may be stored on your device. These include browser cookies (set by HTTP responses) and web storage entries (written directly by our scripts via the Web Storage API). Both mechanisms are regulated by the ePrivacy Directive (2002/58/EC as amended) and, where personal data is involved, by Regulation (EU) 2016/679 (GDPR). Storage that is strictly necessary for the site to function does not require your consent. All other storage is only activated after you explicitly accept it.

  • –Session cookies — exist only for the duration of your browser session and are deleted when you close the tab or window
  • –Persistent cookies — remain on your device until their expiry date or until you delete them
  • –localStorage entries — stored indefinitely in your browser until you clear site data; never sent to our servers
  • –sessionStorage entries — exist only for the duration of the browser tab or window; deleted automatically when you close it; never sent to our servers
  • –First-party storage — set directly by ench.ro
  • –Third-party cookies — set by external services (e.g. Google Analytics) that operate under their own privacy policies

Strictly necessary storage

The following entries are exempt from the consent requirement under Art. 5(3) ePrivacy Directive because they are essential for the transmission of a communication or strictly required to provide a service you have explicitly requested. They cannot be disabled.

  • –ench_cookie_consent — records your cookie consent decision (accepted / rejected / not yet given); type: localStorage (first party); expires: no fixed expiry — persists until you clear browser storage; legal basis: exempt — storing the consent record itself cannot require prior consent
  • –ench_contact_last_submit — records the timestamp of your last contact form submission to enforce a per-browser cooldown and prevent accidental duplicate submissions; no personal data is stored — only a Unix timestamp (integer); type: localStorage (first party); expires: no fixed expiry — persists until you clear browser storage; legal basis: exempt — strictly necessary to provide the contact functionality you have explicitly requested
  • –scroll_pos — stores the scroll position (a pixel offset integer) for up to 8 recently visited pages so the browser back button returns you to the same position on the previous page; no personal data is stored; type: sessionStorage (first party); expires: automatically deleted when the browser tab or window is closed; legal basis: exempt — strictly necessary to replicate the native scroll-restoration behaviour of a standard multi-page website within this single-page application
  • –explored — a single yes/no flag recording whether you have scrolled as far as the product overview section during this visit, so the service selection page can show you either an introduction or a link to customer reviews; stores only the value "1" — no identifiers, no browsing history, no timestamps, and it is never sent to our servers; type: sessionStorage (first party); expires: automatically deleted when the browser tab or window is closed; legal basis: exempt — strictly necessary to present the page content appropriately, and incapable of identifying or profiling you

Preference storage

These entries store choices you make to personalise your experience. They do not track you or transmit data to third parties. They are set and read exclusively within your browser.

  • –ench_lang — records your selected interface language (en / ro); type: first-party cookie (Domain=.ench.ro, Path=/); expires: 1 year; mirrored in localStorage as lang for compatibility; legal basis: legitimate interest (Art. 6(1)(f) GDPR) — necessary to deliver the language you have chosen across page loads and subdomains
  • –promo — records that a one-time discount code has already been shown to you, so the same offer is never displayed twice; stores only the value "1" and is set exclusively after you have accepted cookies; scoped to ench.ro only (not shared with subdomains); type: first-party cookie (Path=/); expires: 1 year; legal basis: consent (Art. 6(1)(a) GDPR) — set only where you have accepted cookies, and withdrawable via "manage preferences" below
  • –plan_clicked — a single yes/no flag recording whether you have opened a hosting plan during this visit, used only to avoid interrupting you with a promotional message while you are choosing a product; stores only the value "1" — it does not record which plan, when, or anything else, and is never sent to our servers; written only after you accept cookies; type: sessionStorage (first party); expires: automatically deleted when the browser tab or window is closed; legal basis: consent (Art. 6(1)(a) GDPR)
  • –visit_start — the time at which your current visit began, stored as a single number, used only to avoid showing a promotional message to someone who has just arrived; no identifiers and no browsing history are stored, and it is never sent to our servers; written only after you accept cookies; type: sessionStorage (first party); expires: automatically deleted when the browser tab or window is closed; legal basis: consent (Art. 6(1)(a) GDPR)

Security cookies (Cloudflare Turnstile)

The contact form on ench.ro can use Cloudflare Turnstile, an anti-bot challenge operated by Cloudflare, Inc. (United States). The Turnstile script (challenges.cloudflare.com) loads only after you accept cookies in our banner — the same choice that enables analytics. When active, Cloudflare may set cookies and process technical signals (including IP address and browser data) to verify that you are human. If you decline cookies, you can still reach us at [email protected]. International transfers to the United States are covered by Cloudflare's EU Data Processing Addendum and standard contractual clauses (Art. 46(2)(c) GDPR). Legal basis: consent (Art. 6(1)(a) GDPR) for loading the third-party widget.

  • –Cloudflare may set various cookies as part of the Turnstile flow. See cloudflare.com/privacypolicy and cloudflare.com/cookie-policy for current details
  • –The contact form security check is unavailable until you accept cookies (or use email instead)

Analytics cookies (Google Analytics 4)

We use Google Analytics 4 (GA4), operated by Google LLC (United States), to understand how visitors interact with our site. The Google tag script is not loaded until you accept cookies in our banner. After acceptance, GA4 may set cookies and send usage data (page URL, device/browser signals, truncated IP) to Google. Data is transferred under standard contractual clauses (Art. 46(2)(c) GDPR). If you decline, no Google Analytics script runs and no analytics cookies are set. Legal basis: consent (Art. 6(1)(a) GDPR). You may withdraw consent via "manage preferences" on the cookies page.

  • –_ga — distinguishes unique users by assigning a randomly generated client ID; type: persistent browser cookie (first party, written by Google's gtag.js); expires: 2 years from last activity
  • –_ga_<MEASUREMENT_ID> — stores and updates the session state for the specific GA4 property; type: persistent browser cookie (first party, written by Google's gtag.js); expires: 2 years from last activity
  • –_gid — distinguishes users over a short window for same-day session deduplication; type: persistent browser cookie (first party, written by Google's gtag.js); expires: 24 hours
  • –_gat — throttles the rate of requests sent to Google's collection endpoint; type: persistent browser cookie (first party, written by Google's gtag.js); expires: 1 minute
  • –IP addresses are truncated by Google before storage — the last octet (IPv4) or last 80 bits (IPv6) are zeroed out and never recorded
  • –Note: some browsers block Google Analytics by default due to built-in privacy settings — Brave (Shields), Firefox (Enhanced Tracking Protection set to Strict), and Edge (Tracking prevention set to Strict) will prevent these cookies from being set entirely, regardless of your consent choice here.

Client area (client.ench.ro)

Signing in to the client area sets additional storage needed to run an authenticated account: to keep you logged in, protect forms against cross-site request forgery, remember your cart, and open server consoles. These are strictly necessary to deliver a service you have explicitly requested and cannot be disabled while you use the client area. Some are set by third parties described below.

  • –paymenter_session — identifies your signed-in session; type: first-party cookie; expires: on session expiry or sign-out; legal basis: exempt — strictly necessary for authentication
  • –paymenter_remember — keeps you signed in between visits when you choose "remember me"; type: first-party cookie; expires: up to 1 year; legal basis: exempt — strictly necessary to provide the sign-in option you selected
  • –XSRF-TOKEN — protects forms and requests against cross-site request forgery; type: first-party cookie; expires: with the session; legal basis: exempt — strictly necessary security measure
  • –cart — remembers the items in your shopping cart between page loads; type: first-party cookie; expires: with the session; legal basis: exempt — strictly necessary to provide the ordering functionality you requested
  • –is-logged-in — a single flag letting the interface render the signed-in state without waiting for a server round-trip; contains no identifier; type: first-party cookie; legal basis: exempt — strictly necessary for correct interface rendering
  • –PVEAuthCookie — a short-lived authentication ticket issued when you open the noVNC console for your virtual server; required by the virtualisation platform to authorise the console session; type: first-party cookie (Domain=.ench.ro); expires: when the browser session ends; legal basis: exempt — strictly necessary to provide console access you explicitly requested
  • –theme / theme_mode — your light/dark/system interface preference; type: localStorage (first party); expires: until you clear browser storage; legal basis: exempt — strictly necessary to render the interface as you chose
  • –collapsedGroups, isOpen, isOpenDesktop — which sidebar groups you have collapsed and whether the sidebar is open; interface state only, no identifiers; type: localStorage (first party); expires: until you clear browser storage; legal basis: exempt — strictly necessary to preserve your interface layout

Third-party services in the client area

Operating accounts, payments and infrastructure involves a small number of external providers that set their own cookies. They act under their own privacy policies, and we do not control the contents of their cookies.

  • –cf_clearance — set by Cloudflare, Inc. after a bot/DDoS protection check, to avoid re-challenging you on every request; type: cookie (Domain=.ench.ro); expires: up to 1 year; legal basis: exempt — strictly necessary to protect the service against attack and abuse. See cloudflare.com/privacypolicy
  • –__stripe_mid — set by Stripe, Inc. for payment fraud prevention when a payment form is loaded; type: cookie; expires: 1 year; legal basis: exempt — strictly necessary to process payments securely and prevent fraud. See stripe.com/privacy
  • –gravatar, gravatar-user-profile-survey — set by Automattic (Gravatar) when your account avatar is loaded from gravatar.com, based on your email address; type: third-party cookies on the gravatar.com domain; legal basis: legitimate interest (Art. 6(1)(f) GDPR) — displaying account avatars. See automattic.com/privacy

Managing your preferences

You can review or withdraw your consent at any time. Withdrawing consent does not affect the lawfulness of any processing that took place before withdrawal.

  • –Manage preferences — click the "Manage cookie preferences" button below to reopen the consent banner and change your choice
  • –Browser cookie settings — Chrome: Settings → Privacy and security → Cookies and other site data; Firefox: Settings → Privacy & Security → Cookies and Site Data; Safari: Settings → Privacy → Manage Website Data; Edge: Settings → Privacy, search, and services → Cookies and site permissions
  • –Clearing preferences — delete the ench_lang cookie and/or localStorage entries ench_cookie_consent and lang from your browser settings or developer tools (Application → Storage)
  • –Google Analytics opt-out — you can also install the Google Analytics opt-out browser extension available at tools.google.com/dlpage/gaoptout

Want to update your cookie preferences?

Questions? Contact us at [email protected]