This document concerns Aster’s software service and its merchant customers. Store product sales remain the responsibility of the actual merchant.
1. Scope and status
This draft applies to https://example.com and specified Platform domains operated by example; contact privacy@example.com. Cookies, localStorage, pixels and fingerprinting can all store or access information. Not every mechanism processes personal data, and the rules are not limited to third-party cookies. Actual pages and provider scripts must be audited and the technology register completed before production launch. Placeholder register entries in the preview do not mean a provider is enabled.
2. Necessary functions
Login sessions, security for purchasing or subscription flows, request protection and storage of privacy choices may operate when the specific applicable exemption is met. Necessity is assessed against a function the user expressly requests; commercial value does not make analytics or advertising necessary. Necessary entries must use proportionate lifetimes, domain scope and security attributes. Core functions that do not depend on optional entries remain usable when optional entries are refused.
3. Preferences, statistics and advertising
Language or appearance preferences and aggregate statistics require separate purposes and lifetimes. Optional statistics, advertising and cross-site tracking are disabled by default in the proposal and must not load or send requests before consent when consent is required. UK law may provide conditional exceptions for specific statistical or appearance uses with a simple objection mechanism; these may be used only after every condition is assessed and met, not for advertising or automatically in all countries. No advertising provider is assumed in this proposal.
4. Consent controls and withdrawal
When choices are needed, equally usable and comparably prominent controls must allow accepting optional uses, refusing them and selecting categories. No preselected boxes, continued-browsing consent, dismissal-as-consent or bundling optional consent into service terms is allowed. A persistent Privacy choices link permits changes or withdrawal. Withdrawal stops future related processing and removes nonessential storage within the Platform’s control while notifying applicable providers.
5. Technology register
Every actual entry must list: name example; setter example; domain example.com; purpose example; category example; first-party status example; lifetime example; associated recipients and countries example; consent or exemption justification example; and withdrawal method example. Entries with the same name but different purposes require distinct disclosure. Cookie expiration is not the same as server-side personal-data deletion; both must be explained. Unidentified or unapproved optional scripts must not be released.
6. Records, third parties and browser controls
The Platform retains necessary choice version, time and scope to demonstrate preferences and avoid repeated requests; preference identifiers must not be reused for advertising profiles. Embedded content or external payment pages may be controlled independently and must be identified with their policies before navigation or loading. Browsers can remove or block storage, which may affect necessary functions such as login. Where local law requires universal opt-out signals to be recognized, the Platform must implement them rather than rely on a textual promise.
7. Updates and contact
Before adding a purpose or provider or materially changing a lifetime, update the register, assess whether renewed consent is necessary, and preserve the prior version. Material changes are disclosed before the related scripts run. Version: draft-2026-10-10. Operative date: example. Contact privacy@example.com for questions, a register copy or withdrawal assistance. This policy does not replace each merchant store’s own Cookie configuration and notice.