Document version 1.0. Reviewed 2026-10-05. Effective 2026-10-05. Native CMS revision and publication history are retained separately for this document.

Saved items: vendorclue.saved.v1 is a sessionStorage key for saved product references. It is scoped to the browser origin and tab session. You can remove saved items in the interface or clear site data. Browser session restoration can restore a tab and its session storage; this is not a server-side reader account.

CMS authentication: Payload uses the payload-token cookie for staff login. The configured token lifetime is 3,600 seconds; the production cookie is Secure and SameSite=Strict. This cookie authorizes CMS operations and is not an analytics identifier. Public reading does not require staff authentication.

Google consent storage: the external Google CMP can manage consent information when it operates. Exact cookies, keys and lifetimes depend on the delivered Google configuration and browser state. The forced preview has not been verified, so no specific Google storage lifetime is asserted here. The presence of a TCF API alone does not prove a user saw or accepted a message.

Turnstile: optional email forms use Cloudflare bot checks when enabled. The production widget is configured with no_clearance, so it is not configured to issue a pre-clearance cookie. Other Cloudflare security functions may use their own cookies depending on account configuration; see Cloudflare’s cookie documentation rather than treating a provider example as an observed site cookie.

GA4 and advertising serving remain disabled. VendorClue does not currently authorize GA4 cookies or manual ad requests through its application. The Google publisher bootstrap still contacts Google on eligible public pages. Legal pages exclude that bootstrap and analytics.

Email preferences, confirmation status and delivery records are server-side D1 state, not email-consent cookies in your browser. Confirmation and unsubscribe links use token hashes on the server; they do not establish a browser advertising preference.

Browser consent and email subscription are separate choices. Accepting a browser consent message does not subscribe you to mail. Unsubscribing from email does not change browser consent. Where the Google message is available, use Privacy choices to revisit it; an unavailable message does not grant consent.

You may block or delete site storage in your browser. This removes Saved items and can end a staff session or reset provider preferences. Blocking scripts can prevent optional challenges from completing. The site does not set a replacement analytics preference store when Google is unavailable.

Provider-controlled storage references: https://www.cloudflare.com/cookie-policy/ ; https://www.cloudflare.com/turnstile-privacy-policy/ ; https://policies.google.com/technologies/cookies . These references describe provider practices; they are not an inventory of cookies observed on every VendorClue visit.

Operator: IT SERVICES MAREK PIETKIEWICZ, Polish sole proprietorship, NIP 5542598947, REGON 341623872. Address: ul. Irysowa 16, 86-031 Osielsko, Poland. Jurisdiction: Poland. VendorClue is the service name of this operator.

Support and editorial corrections: support@magoflow.com. Privacy and data rights: privacy@magoflow.com. Legal notices: legal@magoflow.com.

Cookies & storage