Cookie Policy & Client-Side Storage Protocol
Operating Entity: Mountain49 LLC • Effective Date: January 1, 2026 • Framework: EU ePrivacy Directive
1. OPERATING ENTITY & DATA ETHICS DECLARATION
This Cookie Policy ("Policy") describes how Mountain49 LLC ("Company," "we," "us," or "our"), an enterprise registered in the State of Wyoming, United States, utilizes browser cookies, local storage entities, and related client-side technologies on the WaypointKit electronic storefront.
Our core commercial standard is built around Privacy-First Architecture: We reject invasive behavioral tracking, cross-site advertising re-targeting pixels, and persistent data harvesting. We deploy only strictly necessary operational cookies and privacy-respecting client preferences required to maintain your expedition cart, secure payment checkout, and language settings.
This Policy complies with the European Union Directive 2002/58/EC (ePrivacy Directive), the General Data Protection Regulation (GDPR), and statutory California privacy requirements.
2. WHAT ARE COOKIES & LOCAL STORAGE MECHANISMS?
A cookie is a compact alphanumeric text snippet transmitted by a web server and stored on your device's browser directory. Cookies enable web servers to recognize your specific browsing session across sequential page views.
Local Storage (HTML5 Web Storage) is a high-capacity client-side browser repository that preserves state data locally on your device without transmitting telemetry headers on every subsequent HTTP request. WaypointKit utilizes localStorage to keep your expedition shopping cart synchronized smoothly without requiring a remote database account.
3. EXHAUSTIVE INVENTORY OF CLIENT-SIDE STORAGE
WaypointKit maintains strict transparency regarding every client-side token set by our domain:
Category: Functional / Preference Storage
Purpose: Remembers your selected language interface preference (English 'en' or French 'fr') to prevent resetting upon navigation.
Category: Strictly Necessary
Purpose: Retains your selected Field Kits, quantities, and pricing in Euro (€) within your local browser sandbox so you do not lose your expedition pack when navigating pages.
Category: Strictly Necessary Security & Fraud Prevention
Purpose: Deployed directly by Stripe, Inc. to detect fraudulent automated card testing, brute-force bots, and unauthorized transactions during Stripe Checkout execution.
Category: Strictly Necessary
Purpose: Secures authenticated administrative sessions and prevents cross-site request forgery (CSRF) across form dispatches.
4. ZERO THIRD-PARTY ADVERTISING & TRACKING NETWORKS
Mountain49 LLC enforces a strict ban on third-party behavioral tracking networks:
- We do NOT embed Meta / Facebook Tracking Pixels.
- We do NOT embed Google AdSense, DoubleClick, or Google Remarketing Tags.
- We do NOT deploy invasive biometric mouse-movement tracking (e.g. Hotjar or FullStory).
- We do NOT sell or monetize your browsing paths to data aggregators.
Our business model is 100% transparent: We design premium digital travel systems and sell them directly to customers in Euro (€). We do not monetize your personal attention or travel destinations.
5. LEGAL BASIS UNDER EDPB GUIDELINES & EPRIVACY DIRECTIVE
Under European Data Protection Board (EDPB) guidelines and Article 5(3) of the ePrivacy Directive:
Cookies and local storage keys designated as Strictly Necessary (such as maintaining cart contents during checkout and preventing payment fraud via Stripe Radar) do not require advance affirmative consent because they are technically essential to provide the digital service expressly requested by the user.
Functional cookies (such as remembering your language choice via `wpk_lang`) are deployed based on legitimate interest in providing a seamless multilingual interface (EN / FR) without impairing user privacy.
6. USER CONTROLS & BROWSER PURGING INSTRUCTIONS
You possess complete technical sovereignty over the cookies and local storage records stored on your personal machine:
Please note: Disabling strictly necessary cookies in your browser settings may prevent Stripe Checkout from authenticating payment cards or cause your cart items to disappear between pages.
7. DO NOT TRACK (DNT) & GLOBAL PRIVACY CONTROL (GPC)
WaypointKit naturally respects Do Not Track (DNT) and Global Privacy Control (GPC) signals broadcast by your browser. Because we do not engage in third-party ad tracking, user fingerprinting, or profiling, our site operates in full harmony with all GPC privacy extensions by default.
8. TRANSIENT SERVER LOGGING & CYBERSECURITY
When you connect to WaypointKit, our web application server logs standard technical requests (including IP address, browser type, requested endpoint, and HTTP response code) solely for cybersecurity auditing, bot mitigation, and error diagnosis. These technical server logs are automatically rotated and purged after 90 days.
9. POLICY AMENDMENTS & REGULATORY AUDITING
Mountain49 LLC conducts bi-annual technical audits of all scripts and dependencies running on the WaypointKit domain to verify that zero unauthorized telemetry trackers have been introduced.
Any updates to this Policy will be reflected immediately with an updated Effective Date. Continued use of the Store signifies acceptance of current technical storage configurations.
10. TELEMETRY & PRIVACY INQUIRIES
For questions regarding our client-side storage architecture or data minimization standards, contact:
Mountain49 LLC — Telemetry Compliance
Commercial Division: WaypointKit Operational Systems
State of Incorporation: Wyoming, USA
Contact Email: support@mountain49.com
Commercial Standard: Strictly Euro (€ / EUR)