Cookie and Storage Policy · Roomzor
Effective: 2026-10-06 · Last updated: 2026-10-06 · English
1. Provider
Operator and data controller: Roomzor; legal form: KB Sole Trader — TODO_LEGAL_CONFIG: confirm proprietor and registered legal form; registered address: TODO_LEGAL_CONFIG: full registered address (Hungary, EU supplied); tax number: 888 88 88 — TODO_LEGAL_CONFIG: verify supplied test value; registration number: 666 66 66 — TODO_LEGAL_CONFIG: verify supplied test value; registering authority: Hungary, RA — TODO_LEGAL_CONFIG: identify registering authority. Contact: support@roomzor.com. DPO: TODO_LEGAL_CONFIG: confirm whether a DPO is appointed.
Entries marked TODO_LEGAL_CONFIG await operator confirmation. This document describes the current test installation and features that may be enabled later.
2. Necessary cookies and storage
These items support authentication, request security, access to a password-protected portal and the recording of your privacy choice. They do not require an optional tracking choice to operate.
| Name | Provider/category | Purpose/type | Lifetime | Third party |
|---|---|---|---|---|
| roomzor.session (including chunk suffixes if needed) | Roomzor / necessary | Protected, HttpOnly authentication cookie; Secure on this server, SameSite=Lax | Session when Remember me is off; 14-day sliding ticket/remembered cookie otherwise | No |
| roomzor.csrf | Roomzor / necessary | HttpOnly security cookie paired with an in-memory request token; SameSite=Strict | Browser session | No |
| roomzor.portal | Roomzor / necessary | Protected HttpOnly portal unlock cookie, scoped to the requested portal API; SameSite=Strict | 8 hours | No |
| roomzor.consent | Roomzor / necessary | localStorage record of category choices, policy version and timestamp; no advertising identifier | 180 days, then a new choice is requested | No |
| roomzor.workspace | Roomzor / necessary | localStorage workspace ID selected for the requested application; never determines permission | Until sign-out or browser deletion | No |
| roomzor.draft.<floorId> | Roomzor / necessary | localStorage recovery of unsaved edits to the plan you are editing | Until saved/discarded, 14-day expiry, or sign-out | No |
3. Optional preferences and tracking
| Name | Provider/category | Purpose/type | Lifetime | Third party |
|---|---|---|---|---|
| roomzor.portal.name | Roomzor / preferences | Remember an entered portal guest name in localStorage | Until consent withdrawal, sign-out or browser deletion | No |
| roomzor.companion.project | Roomzor / preferences | Remember the last selected photo-upload project in localStorage | Until consent withdrawal, sign-out or browser deletion | No |
| roomzor.texture-detail | Roomzor / preferences | Remember the texture detail (1K, 2K or 4K) chosen for the 3D view in localStorage | Until consent withdrawal, sign-out or browser deletion | No |
| roomzor-shell, roomzor-assets; /sw.js | Roomzor / preferences | Optional service-worker CacheStorage for static app files and an offline page; API/private responses are excluded | Until consent withdrawal or browser deletion; obsolete hashed files are removed on activation | No |
| _ga, _ga_<ID> | Google / analytics, only if enabled and consented | Analytics cookies for visits to public pages | Configured to 180 days, renewed by permitted activity | Yes |
| _gcl_au, _gcl_aw and related Google Ads identifiers | Google / marketing, only if enabled and consented | Advertising attribution identifiers | Typically up to 90 days; verify actual account settings before enablement | Yes |
The current test installation has no active Google tags. No optional Google script, pixel or consent-mode ping is sent before a selected category is enabled. Browser settings and provider changes may affect actual identifiers; the operator must rescan when adding a service. No IndexedDB database, remote font embed, third-party video embed or browser fingerprinting tracker was found in the audited app.
4. Your choices
The first choice offers Accept all, Reject optional and Settings equally. Optional categories start off. Cookie settings in every page footer lets you change or withdraw each category. Necessary items remain active. A choice is recorded locally for 180 days with the policy version and timestamp. If storage is unavailable, your choice applies only to the open page.
Withdrawal stops optional integrations, removes optional Roomzor data and accessible Google cookies, unregisters the Roomzor worker and removes its caches. When an already loaded tracker must be stopped, the page reloads. Third-party records already lawfully received are governed by their retention and deletion procedures. Clear browser data on a shared computer; sign-out removes Roomzor drafts and remembered personal identifiers.
5. External recipients and questions
Google Analytics/Ads may involve data transfers outside the EEA when enabled. The Privacy Policy explains the approval and safeguard requirements. Only the relevant consented category is configured; private project URLs, portal tokens and account details are excluded from tracking. Provider contract, transfer mechanism and configured retention are TODO_LEGAL_CONFIG items before any production enablement. Contact support@roomzor.com for questions.