Skip to content
SunRun

Cookies and local storage

This working policy describes essential first-party preferences and the conservative explicit opt-in controls for optional analytics and external maps. It documents technical behavior and is not a final legal conclusion.

Policy status
Working notice — legal review required before production freeze
Last updated
July 24, 2026

Cookies and local storage

A cookie is a small value sent between a website and a browser and may be returned with later requests. localStorage is a separate browser-side store accessed by website code. The current theme preference uses localStorage and must not be described as a cookie.

Current storage inventory

The application intentionally stores the language preference, theme preference, and versioned SUNRUN_CONSENT consent choice listed below. Provider-created storage must be inventoried with approved live staging credentials before release and is not guessed here.

Language preference

Key or name
SUNRUN_LOCALE
Storage type
First-party cookie
Allowed values
ru, en, zh
Purpose
Remember the selected language and redirect the site root to ru, en, or zh.
Lifetime
Maximum age: one year. A new valid locale-prefixed request refreshes the preference.

Theme preference

Key or name
sunrun-theme
Storage type
Browser localStorage, not a cookie
Allowed values
light, dark, system
Purpose
Retain the chosen light, dark, or system appearance. System mode follows the browser or operating-system color preference.
Lifetime
Persists in the browser until the user or browser clears site storage.

Consent preference

Key or name
SUNRUN_CONSENT
Storage type
First-party cookie
Allowed values
v1.a0.m0, v1.a1.m0, v1.a0.m1, v1.a1.m1
Purpose
Store the current versioned choices for analytics and external media. The compact value contains no timestamp, identifier, or personal information.
Lifetime
Maximum age: 15552000 seconds (approximately 180 days). This technical proposal requires legal approval and is refreshed only by an intentional consent action.

The locale-cookie maximum age is configured as 31536000 seconds.

Locale-preference behavior

A valid locale-prefixed request stores only ru, en, or zh in the first-party SUNRUN_LOCALE cookie. It uses Path=/, SameSite=Lax, a one-year maximum age, and the Secure attribute in production. The root path uses this valid preference first, then the browser language, and otherwise Russian. Invalid values are ignored.

Theme-preference behavior

The website stores light, dark, or system under the localStorage key sunrun-theme. System mode follows the browser or operating-system preference. Unsupported stored values are removed before the interface initializes.

Current preference purpose

Language, theme, consent preference, core security, and protection for an intentionally used form are essential or user-requested functionality. Essential storage cannot be disabled in the consent dialog. Analytics and external media default to off; the banner offers equally direct Accept all and Reject optional actions plus detailed settings.

Third-party technology status

Yandex Metrika and Yandex Maps are independently release-disabled by default. When correctly configured, Metrika loads only after analytics consent and records page views only, while Maps requires external-media consent and a separate Load map action. Google Analytics, advertising pixels, Webvisor, session replay, click maps, form analytics, advertising features, embedded video, and social-media widgets are not enabled. Provider-created cookie names are not listed until verified in approved live staging QA.

Browser controls

Cookies and site storage can generally be removed or blocked through browser settings. The available controls and labels depend on the browser. No browser-version-specific instructions are required to use the website.

Effect of disabling storage

Rejecting optional categories leaves public content, direct contact options, language, theme, and forms available. Withdrawing analytics consent saves the denial and performs a controlled same-page reload to stop future page-view dispatch because the current official API provides no verified teardown; it does not delete previously transmitted data. Withdrawing external-media consent destroys an active map. Browser controls may also remove site data, but provider-controlled storage behavior requires live verification.

Future integrations and updates

The consent value is strictly versioned as v1.a0.m0 through v1.a1.m1. Malformed, oversized, unknown, or unsupported values deny optional categories and reopen the banner. A category, purpose, provider, duration, or material behavior change requires policy review and normally a consent-version change; production enablement still requires the legal and provider reviews described in the Privacy Policy.

Contact

Questions about the current browser-storage implementation can be sent to the company’s centralized email address.

info@sunrun.by

Essential

Language, theme, consent preference, core security, and requested form protection.

Always enabled

Privacy policyCookies policy