ToteRentalSuite legal information
Cookie Policy
- Effective date
- 2026-07-16
- Last updated
- 2026-07-16
- Version
- 2026-07-16.3
This policy applies from the effective date shown above. Mandatory rights and laws that cannot be excluded always prevail.
1. Your choices
ToteRentalSuite uses strictly necessary technologies for security and session continuity. In production, Google Consent Mode sends limited cookieless measurement signals to Google Analytics by default with analytics storage denied. Google Analytics cookies and fuller session measurement are enabled only when “Analytics” is actively accepted. Rejecting analytics does not prevent use of the Platform. Preference and marketing categories are available in the consent manager but are not currently used to load third-party trackers.
The consent banner provides equally prominent Accept all and Reject non-essential choices, granular settings, no pre-selected non-essential category, and a persistent Cookie preferences control.
2. Cookie and identifier inventory
| Name/provider | Purpose/category | Party and expiry | Routes/consent |
|---|---|---|---|
toterentalsuite_session / ToteRentalSuite (Laravel) | Authenticated and anonymous session continuity, login state, security messages. Strictly necessary. | First party; 120 minutes of inactivity (subject to browser/session settings). | Routes using Laravel web sessions, including registration, login, authenticated app and forms. No opt-in required. |
XSRF-TOKEN / ToteRentalSuite (Laravel where emitted) | Cross-site request-forgery protection. Strictly necessary. | First party; normally aligned with the session. | State-changing web/API flows where the framework emits it. No opt-in required. |
trs_cookie_consent / ToteRentalSuite | Stores categories, policy version and UTC timestamp so the site can honour the visitor’s choice. Strictly necessary for consent records. | First party; 180 days. | All pages using the common consent component. No opt-in required. |
_ga, _ga_* and identifiers set by Google Analytics | Measure visits and use. Analytics. | Google/first-party cookie context; Google’s configured lifetime, commonly up to two years, subject to Google settings. | Public, authentication, operator/admin and public-booking views that include the common analytics partial. Cookies require Analytics opt-in; denied state uses cookieless Consent Mode signals. |
No advertising pixels, session-recording cookies, chat widgets or marketing trackers were found in the audited code. Hosting, proxy or security services outside this repository may add cookies and must be checked in production.
3. localStorage and similar technologies
| Name | Purpose/category | Expiry/routes | Consent |
|---|---|---|---|
trs-platform-theme | Remembers the dark interface theme. Preference necessary to honour an explicit interface setting; the current code always selects dark. | First party, persistent until cleared; marketing and app layouts. | No separate opt-in currently required because it is limited to the requested interface state and is not used for tracking. |
trs-tab-* | Remembers the last open tab within authenticated operator pages. | First party, persistent until cleared; authenticated operator app only. | Preference; no third-party access or cross-site tracking. Can be cleared in browser settings. |
No application use of sessionStorage, IndexedDB, service workers or cached advertising identifiers was found.
4. Withdraw or change consent
Use at any time. Withdrawal prevents Analytics cookies and fuller analytics storage, updates the versioned choice and attempts to delete first-party Google Analytics cookies. Limited denied-state cookieless signals may still be sent for Consent Mode measurement. Withdrawal cannot erase data already received by a third party; contact details and further rights are in the Privacy Policy. Browser controls can also clear stored cookies and localStorage.
