Cookie Policy & Browser Storage Inventory
Last updated: September 2026 • Luggage Storage 193, Naples, Italy
1. Zero Non-Essential Cookies & Why No Consent Banner Is Shown
Pursuant to Article 122(1) of the Italian Privacy Code (Legislative Decree No. 196/2003, implementing Directive 2002/58/EC) and the Guidelines on Cookies and Other Tracking Tools issued by the Italian Data Protection Authority (Garante per la protezione dei dati personali, Resolution of 10 June 2021, Doc. Web No. 9677876), prior consent banners are permitted and required only when a website installs non-essential analytics, preference, or marketing/profiling trackers.
RUNTIME AUDIT CLASSIFICATION: CASE A — ZERO PUBLIC TRACKERS / TECHNICAL ONLY
Our public website (/, /reserve/, /it/, /it/prenota/) does not set advertising or profiling cookies; a technical LS193_PAYMENT_RETURN cookie is set only when payment begins, does not use localStorage for tracking, but uses limited sessionStorage for language preference and booking recovery, registers 0 service workers, and loads 0 third-party analytics or advertising SDKs (no Google Analytics, Meta Pixel, TikTok Pixel, Hotjar, or Clarity). Accordingly, we do not interrupt your browsing or booking flow with an unnecessary cookie popup.
2. Verified Cookie & Storage Inventory
The table below reflects the actual runtime storage behavior across the public website, the hosted payment handoff, and the restricted internal staff administration console:
| Name / Mechanism | Scope & Domain | Purpose | Duration | Classification & Consent |
|---|---|---|---|---|
| Public Website Cookies / Web Storage | First-party public routes (luggagestore193.com) | No advertising cookies. A payment return cookie is set only after starting checkout. The selected language is saved in sessionStorage as preferred-language. The booking lookup may save the reference and email in sessionStorage as ls193_booking_recovery until the browser session ends. Reservation draft tokens (Draft-Access-Token) and Smart Location coordinates are held exclusively in volatile JavaScript memory (React state) and discarded when you close or reload the page. | Browser session for preference and lookup; 0s for coordinates | Functional session storage and strictly necessary volatile memory • No consent required |
| LS193_PAYMENT_RETURN | First-party payment API path only | HttpOnly, SameSite=Lax return token used to check payment status after hosted checkout. Set when payment is initiated. | Up to 2 hours | Strictly necessary payment security cookie |
| Stripe Hosted Checkout Cookies | Third-party hosted checkout (checkout.stripe.com) | Executed only after you explicitly click “Pay €5.00 reservation deposit” and navigate to Stripe’s hosted payment page. Used by Stripe for payment session integrity, 3D Secure authentication, and fraud prevention. | Per Stripe Cookie Policy | Technical payment & anti-fraud (checkout.stripe.com) • No pre-checkout tracking on our site |
| LS193_ADMIN_SESSION | First-party internal staff console only (/api/v1/admin/**) | Server-managed authenticated session identifier for authorized internal operators (HttpOnly, SameSite=Lax, Secure in production). Never set for public visitors. | 30 minutes idle timeout (or immediate on logout) | Strictly necessary technical security cookie • Exempt (Art. 122(1)) |
| ADMIN-XSRF-TOKEN | First-party internal staff console only (/api/v1/admin/**) | Synchronizer/Double-Submit Cross-Site Request Forgery (CSRF) defense token echoed in the X-ADMIN-XSRF-TOKEN header on state-changing staff operations. Never set on public endpoints. | Session duration | Strictly necessary technical security cookie • Exempt (Art. 122(1)) |
3. Smart Location & Browser Geolocation Permission
When you click “Use my location” on our homepage, your browser asks for permission to read your coordinates once via navigator.geolocation.getCurrentPosition(). Neither the coordinates nor the recommended branch are written to document.cookie, localStorage, or sessionStorage. You can revoke browser geolocation permission at any time using the site permissions icon in your browser’s address bar.
4. How to Manage Cookies in Your Browser
Because our public website does not set cookies, blocking first-party cookies in your browser will not impair your ability to browse our pages or create a reservation draft. If you proceed to Stripe Checkout to pay the €5.00 reservation deposit, Stripe requires technical session cookies on checkout.stripe.com to process your payment securely.
For full details on how we process personal data and how to exercise your GDPR rights, please read our Privacy Policy.