legal
Cookies and Local Storage Notice
This Notice explains how D.O.M. uses cookies, local storage, session storage and similar browser technologies.
About this Notice
This Cookies and Local Storage Notice explains how Deus Optimus Maximus Corporation uses cookies, local storage, session storage and similar technologies when people access or use the D.O.M. Christian multi-confessional digital ecosystem.
This Notice should be read together with the Privacy Notice and Terms of Use.
What these technologies are
Cookies are small data records stored by a browser and sent with relevant network requests. Local storage retains information in the browser until it is removed, expires through product logic or the browser data is cleared. Session storage normally remains available only for the current browser tab or session.
D.O.M. uses these technologies to authenticate users, protect accounts, remember choices, maintain communication state, continue requested workflows and, where the user has consented, support analytics or marketing functions.
Consent categories
D.O.M. groups browser technologies into the following categories:
- necessary technologies required to provide authentication, security, communication, preferences and functions actively requested by the user
- analytics technologies used to understand service use, reliability and usability
- marketing and advertising technologies used for campaign measurement, relevant promotion or advertising functions
Necessary technologies are active because D.O.M. cannot provide the requested account and service functions without them. Analytics and marketing technologies are optional and remain disabled until the user gives a valid consent where consent is required by law.
Current optional-technology status
At the effective date of this Notice, D.O.M. does not actively load analytics scripts, advertising systems or marketing pixels before optional consent.
The consent interface is already designed to record separate analytics and marketing choices so those technologies can be introduced lawfully in the future. A consent choice does not mean that every possible technology in the selected category is currently active.
Necessary cookies
D.O.M. currently uses the following first-party cookies: dom_oauth: a short-lived, signed and protected cookie used to maintain the authorization state, PKCE verification data and safe return path during sign-in or registration; it normally expires after approximately 10 minutes;
- dom_session:
- a signed, Secure, HttpOnly and SameSite session cookie used to recognize an authenticated D.O.M. session; it uses a rolling duration of up to approximately 90 days and may be refreshed while the account remains active;
- dom_consent:
- a first-party preference cookie used to remember the user’s cookie and storage choices; it is readable by the browser interface so the user can review and change those choices and normally lasts up to approximately 180 days.
Authentication through Chakloon Pass may also use cookies on Chakloon Pass or the unified authentication domain. Those cookies are governed by the relevant Chakloon Pass notice and are used to provide secure OAuth 2.0 and OpenID Connect authentication.
Necessary local storage
Depending on the functions used, D.O.M. may store the following information in local storage:
- the user’s cookie and storage preference record, including consent version, selected optional categories and decision time
- communication access state, user identifier and device identifier needed to provide synchronized D.O.M. messaging functions
- conversation-to-room mappings needed to reopen an existing direct conversation without creating duplicates
- other durable interface or service identifiers needed to preserve a user-requested function across browser sessions
Some communication access data stored in local storage may be security-sensitive. Users should sign out and clear site data when using a shared or untrusted device.
Necessary session storage
Depending on the functions used, D.O.M. may store the following information in session storage:
- a safe return path used to continue a messaging or authorization workflow
- communication synchronization tokens and temporary conversation-list cache data
- temporary booking or connection markers used to avoid repeating an action in the same tab
- short-lived interface state required to complete a user-requested process
Session-storage values normally disappear when the relevant browser tab or session is closed, although browser restoration behavior may vary.
Analytics technologies
Where a user consents, D.O.M. may use analytics technologies to measure:
- page and feature usage
- service performance and reliability
- navigation patterns and interaction events
- device, browser, language and approximate regional information
- errors, failed actions and completion rates
- aggregated trends that help improve comfort and usability
Analytics consent is optional. Refusing analytics does not prevent access to the core D.O.M. service.
Marketing and advertising technologies
Where a user consents, D.O.M. may use marketing or advertising technologies to:
- measure campaign effectiveness
- understand whether a promotion resulted in a visit or registration
- limit repeated advertising
- support relevant promotion of D.O.M., its events, charitable initiatives, fundraising campaigns or related services
- measure advertising or outreach performance
Marketing consent is optional. D.O.M. will not activate marketing pixels or comparable non-essential tracking before the legally required consent is obtained.
Fundraising and donation campaigns may use measurement technologies only under the same consent rules. A user’s decision not to accept marketing technologies does not prevent the user from making a donation or using core D.O.M. functions.
Registration choices
Registration requires a separate confirmation of agreement to the Terms of Use and a separate confirmation that the Privacy Notice has been read.
Optional consent to analytics and marketing technologies is not required to register, is not selected in advance and may be refused without losing access to the core service.
D.O.M. records the applicable document version and the registration confirmations for accountability and legal compliance.
How choices are stored
D.O.M. stores the user’s consent version, necessary-category status, analytics choice, marketing choice and decision time in first-party browser storage and a first-party preference cookie.
These records allow the interface to respect the choice, prevent repeated banners and determine whether optional technologies may be activated.
D.O.M. may also retain an account-linked audit record of registration confirmations or consent where necessary for compliance, dispute resolution and protection of rights.
Changing or withdrawing consent
Users may reopen Cookie settings from the persistent control displayed by D.O.M.
A user may accept or reject optional categories independently and may withdraw optional consent at any time. Withdrawal must be as easy as giving consent and takes effect for future processing.
Withdrawing consent does not make processing carried out before withdrawal unlawful. Previously stored third-party data may require additional deletion steps described by the relevant provider or browser.
Browser controls
Users may delete or block cookies and browser storage through browser settings. Doing so may:
- sign the user out
- interrupt registration or authorization
- remove communication synchronization state
- reset language or interface preferences
- cause the consent banner to appear again
- prevent some requested functions from operating correctly
Necessary technologies cannot be disabled through the D.O.M. preference panel, but users may block them through the browser and stop using the affected functions.
Third-party technologies
Some D.O.M. functions may rely on separate infrastructure or external services. Those services may set their own cookies or browser-storage values when the user actively accesses the relevant function.
D.O.M. will identify material third-party analytics, advertising or marketing technologies in this Notice or the consent interface before activating them where required by law.
Retention
Cookie and storage durations depend on purpose:
- authorization-state data normally lasts up to approximately 10 minutes
- authenticated D.O.M. sessions may last up to approximately 90 days on a rolling basis
- consent preferences normally last up to approximately 180 days
- session-storage values normally last for the browser tab or session
- communication and device identifiers in local storage may remain until sign-out, product cleanup or manual browser-data deletion
- analytics and marketing data, when introduced, will use the duration disclosed in the consent interface or updated technology register
Security
D.O.M. protects authentication cookies using controls such as signatures, Secure transmission, HttpOnly restrictions where appropriate and SameSite settings.
Browser-readable preference storage cannot be given HttpOnly protection because the interface must read and update it. Users should protect access to their device and browser profile.
No browser-storage mechanism can guarantee absolute security. D.O.M. limits storage to information reasonably necessary for the relevant purpose and reviews security risks when functions change.
Legal basis
Necessary technologies are used where required to provide a service requested by the user, perform the Terms of Use, protect security or pursue a legitimate operational interest permitted by applicable law.
Analytics, advertising and marketing technologies are used on the basis of consent where consent is required. In jurisdictions where another lawful basis is available, D.O.M. will still respect the choices shown in its consent interface unless a different legally compliant notice is provided.
Changes to this Notice
D.O.M. may update this Notice when technologies, purposes, providers or legal requirements change.
Material changes to optional tracking will be reflected in the consent interface. Where required, D.O.M. will request a new choice before activating materially changed optional technologies.
Contact
Questions about cookies, browser storage and consent choices may be sent to the contact form linked from the Legal Notice.