Cookies and local storage
This working policy describes essential first-party preferences and the conservative explicit opt-in controls for optional analytics and external maps. It documents technical behavior and is not a final legal conclusion.
- Policy status
- Working notice — legal review required before production freeze
- Last updated
- July 24, 2026
Cookies and local storage
A cookie is a small value sent between a website and a browser and may be returned with later requests. localStorage is a separate browser-side store accessed by website code. The current theme preference uses localStorage and must not be described as a cookie.
Current storage inventory
The application intentionally stores the language preference, theme preference, and versioned SUNRUN_CONSENT consent choice listed below. Provider-created storage must be inventoried with approved live staging credentials before release and is not guessed here.
Language preference
- Key or name
- SUNRUN_LOCALE
- Storage type
- First-party cookie
- Allowed values
- ru, en, zh
- Purpose
- Remember the selected language and redirect the site root to ru, en, or zh.
- Lifetime
- Maximum age: one year. A new valid locale-prefixed request refreshes the preference.
Theme preference
- Key or name
- sunrun-theme
- Storage type
- Browser localStorage, not a cookie
- Allowed values
- light, dark, system
- Purpose
- Retain the chosen light, dark, or system appearance. System mode follows the browser or operating-system color preference.
- Lifetime
- Persists in the browser until the user or browser clears site storage.
Consent preference
- Key or name
- SUNRUN_CONSENT
- Storage type
- First-party cookie
- Allowed values
- v1.a0.m0, v1.a1.m0, v1.a0.m1, v1.a1.m1
- Purpose
- Store the current versioned choices for analytics and external media. The compact value contains no timestamp, identifier, or personal information.
- Lifetime
- Maximum age: 15552000 seconds (approximately 180 days). This technical proposal requires legal approval and is refreshed only by an intentional consent action.
The locale-cookie maximum age is configured as 31536000 seconds.
Locale-preference behavior
A valid locale-prefixed request stores only ru, en, or zh in the first-party SUNRUN_LOCALE cookie. It uses Path=/, SameSite=Lax, a one-year maximum age, and the Secure attribute in production. The root path uses this valid preference first, then the browser language, and otherwise Russian. Invalid values are ignored.
Theme-preference behavior
The website stores light, dark, or system under the localStorage key sunrun-theme. System mode follows the browser or operating-system preference. Unsupported stored values are removed before the interface initializes.
Current preference purpose
Language, theme, consent preference, core security, and protection for an intentionally used form are essential or user-requested functionality. Essential storage cannot be disabled in the consent dialog. Analytics and external media default to off; the banner offers equally direct Accept all and Reject optional actions plus detailed settings.
Third-party technology status
Yandex Metrika and Yandex Maps are independently release-disabled by default. When correctly configured, Metrika loads only after analytics consent and records page views only, while Maps requires external-media consent and a separate Load map action. Google Analytics, advertising pixels, Webvisor, session replay, click maps, form analytics, advertising features, embedded video, and social-media widgets are not enabled. Provider-created cookie names are not listed until verified in approved live staging QA.
Browser controls
Cookies and site storage can generally be removed or blocked through browser settings. The available controls and labels depend on the browser. No browser-version-specific instructions are required to use the website.
Effect of disabling storage
Rejecting optional categories leaves public content, direct contact options, language, theme, and forms available. Withdrawing analytics consent saves the denial and performs a controlled same-page reload to stop future page-view dispatch because the current official API provides no verified teardown; it does not delete previously transmitted data. Withdrawing external-media consent destroys an active map. Browser controls may also remove site data, but provider-controlled storage behavior requires live verification.
Future integrations and updates
The consent value is strictly versioned as v1.a0.m0 through v1.a1.m1. Malformed, oversized, unknown, or unsupported values deny optional categories and reopen the banner. A category, purpose, provider, duration, or material behavior change requires policy review and normally a consent-version change; production enablement still requires the legal and provider reviews described in the Privacy Policy.
Contact
Questions about the current browser-storage implementation can be sent to the company’s centralized email address.
info@sunrun.by