Storage in use

localStorage · aluminosischeck:analytics-consent:v1 · keeps the analytics choice until it is revoked or the site data is cleared. It contains no address, reference, token or personal identifier.

sessionStorage · aluminosischeck:screening:v1 · allows the private progress to be resumed temporarily until it expires. sessionStorage · housingfax:payment:v1 · during payment, stores the request's capability so the order can be followed when returning from the payment form; it is deleted when payment ends and within 3 hours at most.

Cookie hf_locale · first-party · created only when you choose a language in the language selector; it stores that language so that the website opens in it the next time you arrive through the main address. It lasts one year and contains no address, reference, token or personal identifier. It is a technical user-interface customisation cookie chosen by the user, exempt from consent under article 22.2 of the Spanish Information Society Services and Electronic Commerce Act (Ley 34/2002, LSSI).

Stripe cookies (__stripe_mid, __stripe_sid and those of its form) · set by Stripe as a third party · created only when the payment form at the “Payment” step is opened; they are used to process the payment securely and to prevent fraud, last at most one year and 30 minutes respectively, and are technical cookies, necessary for the payment service requested and exempt from consent under the same article 22.2 of the LSSI. Their use is described in Stripe's cookie policy (stripe.com/cookies-policy/legal).

Google Analytics cookies (_ga and _ga_8KLNCYLR54) · set by Google as a third party · created only if you accept analytics; they store a pseudonymous identifier to distinguish visits and sessions on public pages. They last at most 13 months and are deleted when analytics is revoked. Their use is described in Google's privacy policy (policies.google.com/technologies/cookies).

Optional analytics

Only after acceptance is a normalised public route and the page_view event sent to our own endpoint. Private routes, parameters, fragments, addresses, references, documents and tokens are discarded. Aggregates live for at most 24 hours in process memory and create no profiles.

Only after acceptance is Google Analytics (Google Ireland Limited) also loaded; it receives the address of each public page visited without parameters (except utm_ campaign parameters), its title, the referring site and technical data about the browser and the device. It is not loaded, or remains disabled, in the analysis wizard and in reports. Google signals and ad personalisation are disabled, and event data is kept for 2 months (data linked to the pseudonymous identifier, for 14 months from the last visit). Details of recipients and transfers are in the privacy policy.

Accept, decline or revoke

Accepting and keeping it disabled have the same prominence and are not a condition of use. The “Privacy settings” control allows the choice to be changed at any time.

Clearing the site storage removes preferences and drafts. Revoking stops new events and deletes the Google Analytics cookies; aggregates that are already anonymised do not allow a person to be identified.