This policy explains how we use cookies and similar technologies on our website to enhance your browsing experience and provide personalized content.
A public, logged-out audit of stage.onereference.com found no readable cookies, local-storage keys or session-storage keys before login and no visible consent banner. The page loaded first-party assets plus Google Fonts, Bunny Fonts and Cloudflare-hosted Font Awesome / international telephone-input libraries. The authenticated service and payment/verification flows were not accessible in that audit, so this policy does not invent cookie names or server-side vendors.
| Category | Rule and default retention |
|---|---|
| Strictly necessary | Used only where essential for security, authentication, session continuity, load balancing, fraud prevention, consent choices or a service expressly requested. No consent is required under the applicable exception, but information must still be provided. Session to 12 months depending on purpose. |
| Preferences / appearance | Remember choices. Use consent unless a current statutory exception clearly applies and its transparency/objection conditions are met. Usually 6–12 months. |
| Analytics / statistics | Off by default unless valid consent is obtained, or a current statistical exception clearly applies with required information and an easy objection. Maximum 13 months; aggregate thereafter. |
| Marketing / advertising | Off by default and requires consent. Six months by default, never more than 13 months without a documented justification. |
| Consent receipt | Pseudonymised proof of choice for 24 months or until replaced by a newer receipt, whichever is shorter unless legal need requires longer. |
| Technology/provider | Purpose/status |
|---|---|
| OneReference / Hostinger first-party session and security technologies | Expected for authenticated operation, CSRF protection, server sessions, fraud prevention and security. Exact deployed names, domains and lifetimes must be entered from production configuration before launch. |
| Google reCAPTCHA | Bot and abuse protection on protected forms. It may use cookies or similar device signals and receive IP, browser and interaction data. Load only where necessary, disclose it clearly and record the exact production keys and durations. |
| Google Fonts / Google static font delivery | Font delivery observed on the public page; may receive IP address and request metadata. No cookie was observed in the logged-out audit. |
| Bunny Fonts | Font delivery observed; may receive IP address and request metadata. No cookie was observed in the logged-out audit. |
| Cloudflare CDN libraries | Font Awesome and international telephone-input assets observed via cdnjs.cloudflare.com; may receive IP address and request metadata. No cookie was observed in the logged-out audit. |
| Other confirmed service providers | OneReference private email server, Twilio (SMS), Stripe and PayPal (payments), and ClamAV (server-side upload scanning). They are not listed as browser cookies unless the relevant user journey actually loads their technology. |
| Analytics / advertising | No analytics or advertising cookie was observed on the audited public page. Do not deploy these technologies until the register, consent control and policy are updated. |
Where consent is required, Reject and Accept must be equally accessible and non-essential technologies must remain blocked until a positive choice. Users must be able to reopen Cookie Settings and withdraw consent as easily as giving it. Browser controls may also delete or block technologies, although necessary features may then fail.