Roomzor

Cookie and Storage Policy · Roomzor

Effective: 2026-10-06 · Last updated: 2026-10-06 · English

1. Provider

Operator and data controller: Roomzor; legal form: KB Sole Trader — TODO_LEGAL_CONFIG: confirm proprietor and registered legal form; registered address: TODO_LEGAL_CONFIG: full registered address (Hungary, EU supplied); tax number: 888 88 88 — TODO_LEGAL_CONFIG: verify supplied test value; registration number: 666 66 66 — TODO_LEGAL_CONFIG: verify supplied test value; registering authority: Hungary, RA — TODO_LEGAL_CONFIG: identify registering authority. Contact: support@roomzor.com. DPO: TODO_LEGAL_CONFIG: confirm whether a DPO is appointed.

Entries marked TODO_LEGAL_CONFIG await operator confirmation. This document describes the current test installation and features that may be enabled later.

2. Necessary cookies and storage

These items support authentication, request security, access to a password-protected portal and the recording of your privacy choice. They do not require an optional tracking choice to operate.

NameProvider/categoryPurpose/typeLifetimeThird party
roomzor.session (including chunk suffixes if needed)Roomzor / necessaryProtected, HttpOnly authentication cookie; Secure on this server, SameSite=LaxSession when Remember me is off; 14-day sliding ticket/remembered cookie otherwiseNo
roomzor.csrfRoomzor / necessaryHttpOnly security cookie paired with an in-memory request token; SameSite=StrictBrowser sessionNo
roomzor.portalRoomzor / necessaryProtected HttpOnly portal unlock cookie, scoped to the requested portal API; SameSite=Strict8 hoursNo
roomzor.consentRoomzor / necessarylocalStorage record of category choices, policy version and timestamp; no advertising identifier180 days, then a new choice is requestedNo
roomzor.workspaceRoomzor / necessarylocalStorage workspace ID selected for the requested application; never determines permissionUntil sign-out or browser deletionNo
roomzor.draft.<floorId>Roomzor / necessarylocalStorage recovery of unsaved edits to the plan you are editingUntil saved/discarded, 14-day expiry, or sign-outNo

3. Optional preferences and tracking

NameProvider/categoryPurpose/typeLifetimeThird party
roomzor.portal.nameRoomzor / preferencesRemember an entered portal guest name in localStorageUntil consent withdrawal, sign-out or browser deletionNo
roomzor.companion.projectRoomzor / preferencesRemember the last selected photo-upload project in localStorageUntil consent withdrawal, sign-out or browser deletionNo
roomzor.texture-detailRoomzor / preferencesRemember the texture detail (1K, 2K or 4K) chosen for the 3D view in localStorageUntil consent withdrawal, sign-out or browser deletionNo
roomzor-shell, roomzor-assets; /sw.jsRoomzor / preferencesOptional service-worker CacheStorage for static app files and an offline page; API/private responses are excludedUntil consent withdrawal or browser deletion; obsolete hashed files are removed on activationNo
_ga, _ga_<ID>Google / analytics, only if enabled and consentedAnalytics cookies for visits to public pagesConfigured to 180 days, renewed by permitted activityYes
_gcl_au, _gcl_aw and related Google Ads identifiersGoogle / marketing, only if enabled and consentedAdvertising attribution identifiersTypically up to 90 days; verify actual account settings before enablementYes

The current test installation has no active Google tags. No optional Google script, pixel or consent-mode ping is sent before a selected category is enabled. Browser settings and provider changes may affect actual identifiers; the operator must rescan when adding a service. No IndexedDB database, remote font embed, third-party video embed or browser fingerprinting tracker was found in the audited app.

4. Your choices

The first choice offers Accept all, Reject optional and Settings equally. Optional categories start off. Cookie settings in every page footer lets you change or withdraw each category. Necessary items remain active. A choice is recorded locally for 180 days with the policy version and timestamp. If storage is unavailable, your choice applies only to the open page.

Withdrawal stops optional integrations, removes optional Roomzor data and accessible Google cookies, unregisters the Roomzor worker and removes its caches. When an already loaded tracker must be stopped, the page reloads. Third-party records already lawfully received are governed by their retention and deletion procedures. Clear browser data on a shared computer; sign-out removes Roomzor drafts and remembered personal identifiers.

5. External recipients and questions

Google Analytics/Ads may involve data transfers outside the EEA when enabled. The Privacy Policy explains the approval and safeguard requirements. Only the relevant consented category is configured; private project URLs, portal tokens and account details are excluded from tracking. Provider contract, transfer mechanism and configured retention are TODO_LEGAL_CONFIG items before any production enablement. Contact support@roomzor.com for questions.