RedPatron legal
Cookie & Tracking Inventory
The fail-closed inventory of permitted browser storage and tracking technologies.
Effective date: 4 August 2026
Document version: 1.0
This inventory is intentionally fail-closed. Only the entries below may exist in production. Any additional cookie, local-storage key, SDK beacon, pixel or fingerprinting operation must be reviewed and added before deployment.
| Name/pattern | Provider | Purpose | Category | Duration | Consent |
|---|---|---|---|---|---|
rp_session |
RedPatron | Authenticated session | Strictly necessary | Session / maximum 24 hours | No |
rp_csrf |
RedPatron | Request-forgery protection | Strictly necessary | Session | No |
rp_consent |
RedPatron | Store consent selections and policy version | Strictly necessary | 12 months | No |
rp_locale |
RedPatron | User-requested language | Preference | 12 months | Yes where required |
rp_age_gate |
RedPatron | Store minimised adult-access result/reference | Strictly necessary | Country-rule maximum; no raw ID | No |
No analytics, marketing, advertising or third-party social pixel is approved in this version. Their code must not ship or make a request before a completed inventory, legal basis, consent configuration and vendor approval. A production scanner must compare observed technologies against this table on every release; an undeclared item blocks release.