Current use
The current website uses only first-party technologies needed for security, forms, session continuity and authenticated Admin access. It does not currently use analytics, advertising, remarketing, behavioural tracking, session replay, marketing pixels or non-essential third-party embeds.
Because the audited website currently uses only essential technologies, it does not display an Accept/Reject banner merely for appearance. Applicable legal treatment must still be rechecked if the technology or target-market facts change.
fusionaura-studio-session
Purpose: session continuity, CSRF and security controls, form integrity, and authenticated Admin state where applicable. Category: strictly necessary / essential.
The cookie contains an opaque session identifier; associated server-side session data may include technical request information and an Admin user identifier after authentication. The configured idle lifetime is 30 minutes and may refresh during activity. It is configured HttpOnly, Secure on HTTPS, SameSite Lax and encrypted at the application level.
The exact name, expiry, domain, path and security attributes may vary with the deployed environment and can be inspected in the browser’s storage and response-header tools.
XSRF-TOKEN and form CSRF state
Purpose: protection against cross-site request forgery and preservation of form and security integrity. Category: strictly necessary / essential.
Laravel may issue the first-party XSRF-TOKEN cookie and embeds hidden CSRF state in protected forms. The token is framework security state tied to the session, not advertising or analytics data. Its intended lifetime follows the configured session window; exact production headers and deletion behavior must be verified before launch.
Related server-side security state
Rate-limit counters, duplicate-submission controls, queued-job identifiers and TOTP challenge state are maintained server-side to protect inquiries, privacy requests and Admin access. They are not browser advertising storage. TOTP secrets and recovery codes are not exposed in public cookies.
Technologies not currently active
The current audited source does not use localStorage, sessionStorage, IndexedDB, service-worker caches, analytics cookies, advertising pixels, fingerprinting, remarketing, session replay or tracking query-parameter persistence. Hostinger CDN is not activated by this application work and its real production configuration remains an account-level decision.
Before non-essential technology is added
Before analytics, Google Tag Manager analytics or advertising tags, Meta Pixel, LinkedIn Insight Tag, TikTok Pixel, Hotjar, Microsoft Clarity, session replay, remarketing, behavioural advertising, non-essential third-party embeds or comparable browser storage is enabled, FusionAura Studio must stop and repeat the storage and privacy assessment.
Where consent is required, non-essential scripts must remain off by default until a person makes a choice. The implementation must offer accessible Accept and Reject controls, granular choices where needed, easy withdrawal or change, versioned consent records where appropriate, and no deceptive interface. A tracker must never load first and ask for consent afterwards.
Browser controls and contact
Browser settings can remove or block cookies, but blocking essential session or CSRF technologies may prevent forms or Admin authentication from working correctly.
Questions about this notice can be sent to hello@fusionaurastudio.com. Privacy questions can also use the existing privacy-request process.
Changes to this notice
This notice will be reviewed whenever browser storage, tracking, embeds, infrastructure or applicable legal facts change. The public page shows when the current notice was last updated.