Cookie policy
This policy explains how the ELALAN customer account uses cookies and similar browser-storage technologies. It should be read with the Privacy notice.
If you block the essential ELALAN session cookie, sign-in, protected account pages and secure form actions may not work correctly.
1. What are cookies and similar technologies?
Cookies are small values stored by a browser for a website. Similar technologies include local storage and session storage, which allow a web application to remember limited information in the browser without using a traditional cookie.
In this policy, "browser storage" refers collectively to cookies, local storage and session storage where the distinction is not important.
2. Essential ELALAN session cookie
The portal uses a server-side PHP session cookie to maintain the secure browser session. The deployment name can be configured; the default application session name is elalan_frontend.
| Storage | Purpose | Typical duration | Category |
|---|---|---|---|
| ELALAN session cookie | Maintains signed-in state, onboarding/session state and server-side security context. | Browser session by default; server-side session lifetime is deployment-controlled. | Strictly necessary |
The application configures the session cookie as HTTP-only, uses cookie-only sessions, applies a SameSite setting (Lax by default), and marks the cookie Secure when the portal is served over HTTPS. Security-sensitive values such as the CSRF token are held in the server-side session rather than exposed as a readable JavaScript cookie.
3. Locale and preference-related storage
The portal can read language/locale cookie names such as hl, lang and locale when they are present, so the application can resolve an appropriate interface language. Availability and duration depend on how the locale is set in the deployed portal.
Where ELALAN adds other preference storage in the future, it will be described here or in the applicable consent controls.
4. Featured-content engagement storage
For signed-in customer content placements, the current portal uses browser storage to support engagement sessions:
| Key | Technology | Purpose | Duration |
|---|---|---|---|
elalan_placement_visitor | Local storage | Creates a pseudonymous browser identifier so ELALAN can avoid double-counting and understand engagement with featured account content. | Persists until browser storage is cleared or replaced. |
elalan_placement_session | Session storage | Connects featured-content impressions/interactions within the current browser tab/session to an engagement session. | Normally until the browser tab/session storage is cleared. |
Engagement events may include whether featured content was displayed, opened or dismissed, together with the placement/content reference, landing path, referrer where available, device class and basic viewport/page metadata. This data is used for account-content delivery, measurement and service improvement; it does not determine authoritative property, reservation, assignment or payment status.
5. Temporary session cache
The portal also uses session storage to cache limited customer-journey summary information for smoother navigation within the current browser session. This reduces repeated calls for the same navigation summary. The cache is temporary and is removed or replaced as the account state changes or the browser session ends.
6. Third-party resources
The customer interface may load technical resources such as icon libraries or other frontend dependencies from service providers. A third-party service may process connection information such as IP address and browser headers when your browser requests that resource. Their processing is governed by the applicable service arrangement and, where relevant, their own privacy information.
The current customer portal does not require third-party advertising cookies for its core account functions. If ELALAN introduces non-essential advertising or additional analytics technologies, this policy and any required consent controls should be updated before or at the time those technologies are deployed.
7. Your browser controls
You can remove or block cookies and browser storage using your browser settings. You can also clear local or session storage for the ELALAN site. Be aware that:
- blocking the essential session cookie can prevent sign-in and protected account functions;
- clearing local storage may reset the pseudonymous featured-content visitor identifier;
- clearing session storage may cause temporary account summaries or engagement sessions to be re-created; and
- browser privacy modes may automatically remove some storage when the window is closed.
8. Changes and contact
We may update this policy when browser-storage technologies or legal requirements change. Material additions of non-essential tracking will be accompanied by the controls required under applicable law.
For questions about cookies or browser storage, contact info@elalan.com or use Contact ELALAN.