Effective date and last updated: 7 August 2026
Policy version: 2026-08-07
1. Who operates the central ELVPro website
The central ELVPro website and business-account interfaces are operated by:
- SYNCDEV S.R.L.
- Romanian Trade Register no.: J36/164/2014
- CUI / fiscal identification code: 33129339
- Registered office: Str. Fetițelor nr. 4, camera nr. 1, 820035 Tulcea, Tulcea, Romania
- Email: hello@elvpro.eu
This Policy should be read with the ELVPro Privacy Policy.
2. Scope
This Policy applies to cookies and similar technologies used by SYNCDEV on the central ELVPro presentation website and ELVPro business-account interfaces.
Each yard using ELVPro operates its own public storefront and is normally the controller for technologies used there. The yard must provide its own accurate privacy/cookie information. ELVPro supplies technical consent controls for optional storefront tags, but this central Policy does not replace the yard's notice.
3. What cookies and similar technologies are
A cookie is a small text file that a website stores on a browser or device and reads during a current or later visit. Similar technologies include local storage, session storage, pixels, tags, scripts and device/browser identifiers.
Romanian Law no. 506/2004 and Article 5(3) of Directive 2002/58/EC generally require prior informed consent before information is stored in or read from a user's device, unless the operation is strictly necessary to transmit a communication or provide a service expressly requested by the user.
Where a technology also processes personal data, the GDPR applies as well.
4. Our current approach
On the central ELVPro website:
- strictly necessary technologies may operate without consent;
- preference storage is used only to remember choices requested by you;
- our native audience measurement does not set an analytics cookie or use local storage;
- we do not use the native analytics identifier to follow a person across unrelated websites or across different days;
- an enabled browser "Do Not Track" signal prevents the native analytics beacon;
- an objection recorded through the "Privacy settings" control in the site footer also prevents it, both in the page and on our server; and
- optional analytics and advertising technologies, where enabled, are never loaded or read before you actively accept the matching category, and are described in section 7.
Where advertising or analytics providers are configured, no provider script is downloaded, executed or read from your device until you accept the corresponding category. Refusing is offered on equal terms with accepting, and refusal leaves the site fully usable.
5. First-party technologies currently used
a) ELVPro session cookie (for example, "elvpro-session")
- Provider: SYNCDEV / ELVPro
- Purpose: authentication, session continuity, security messages and core account functions. On the central website it also carries the campaign attribution described in section 8.
- Type: strictly necessary, first party, HTTP-only.
Typical duration: up to 120 minutes of inactivity by default, subject to the deployed session configuration; it may persist longer in the browser where a "remember me" function is requested.
b) XSRF-TOKEN or equivalent anti-forgery token
- Provider: SYNCDEV / ELVPro
- Purpose: protects forms and authenticated requests against cross-site request forgery.
- Type: strictly necessary, first party.
- Typical duration: session.
c) elvpro_cookie_consent
- Provider: SYNCDEV / ELVPro
- Purpose: remembers that the visitor has accepted or declined the offered optional categories so the banner is not repeated on every page, and records an objection to the native analytics beacon described in section 6.
- Storage: first-party cookie and a matching local-storage entry.
- Type: necessary to remember the requested privacy choice.
- Duration: 12 months in the current implementation, unless you clear it earlier.
- Third-party access: no.
d) elv_consent
- Provider: SYNCDEV / ELVPro
- Purpose: records which optional categories (analytics, marketing) you accepted or refused, together with the version of this Policy in force at the time. A decision taken against an older version of this Policy is treated as no decision, so the banner reappears and nothing optional loads until you choose again.
- Storage: local storage.
- Type: necessary to remember the requested privacy choice.
- Duration: until you change the choice, this Policy's version changes, or you clear site data.
- Third-party access: no.
e) mkt-theme / theme
- Provider: SYNCDEV / ELVPro
- Purpose: remembers the light, dark or automatic display preference selected by the user.
- Storage: local storage.
- Type: functional preference requested by the user.
- Duration: until the user changes the preference or clears site data.
- Third-party access: no.
f) mediaViewMode and comparable admin-interface preferences
- Provider: SYNCDEV / ELVPro
- Purpose: remembers an authenticated user's selected list/grid or interface display mode.
- Storage: local storage.
- Type: functional preference requested by the user.
- Duration: until the user changes the preference or clears site data.
- Third-party access: no.
6. Cookieless native analytics
The central website sends a first-party page-view request to ELVPro without setting an analytics cookie or local-storage identifier. The server uses the IP address and user-agent string transiently to:
- create a daily salted pseudonymous visitor hash and short session hash;
- derive approximate country/city;
- derive coarse device, browser and operating-system categories; and
- record the page path without its query string, referrer source and campaign parameters.
The raw IP address and full user-agent string are not written to the analytics record. This processing is still treated as pseudonymous personal-data processing, not as anonymous data. Its legal basis, retention and objection mechanism are described in the Privacy Policy.
Because this native system does not store information in or read tracking information from your device, it is not placed in an optional "analytics cookie" category. This does not remove the GDPR requirements that apply to the associated personal-data processing.
7. Optional analytics and advertising technologies on the central website
SYNCDEV advertises ELVPro on third-party platforms. To measure whether that advertising works, the central website can be configured to load the following providers:
- Google Tag Manager, Google Analytics 4 and Google Ads, provided by Google Ireland Limited;
- Meta Pixel, provided by Meta Platforms Ireland Limited; and
- where enabled, LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company) or TikTok Pixel (TikTok Information Technologies UK Limited).
Google Tag Manager and Google Analytics 4 fall under the analytics category. Google Ads, Meta Pixel, LinkedIn Insight Tag and TikTok Pixel fall under the marketing category.
None of these is downloaded, executed or permitted to read from your device before you accept the matching category. ELVPro uses Google's Basic Consent Mode: before a choice is made, all consent signals are set to denied and no Google tag library is loaded, so no pre-consent tracking ping of any kind is sent. Providers without an equivalent mechanism are simply not injected into the page until consent is given.
These providers set their own cookies and identifiers once loaded, may combine what they observe with data they hold about you from other websites and their own services, and act as independent or joint controllers for that processing. Their own notices govern it. Their processing may involve transfers outside the European Economic Area, carried out under the European Commission's adequacy decision for the EU-US Data Privacy Framework or, where that does not apply, standard contractual clauses.
Currently enabled on the central website. At the date of this Policy, the only optional technologies actually enabled are Google Tag Manager and Google Analytics 4, both in the analytics category. Google Tag Manager sets no cookies of its own; it is the container that loads Google Analytics 4. Once you accept the analytics category, Google Analytics 4 sets two first-party cookies, "_ga" and "_ga_5G6330MS9S", each lasting two years, used to distinguish visitors and sessions. Google Signals is disabled, so no cross-device tracking or demographic profiling is performed and no advertising-personalisation cookie is set. Event data is retained by Google for 14 months. No marketing-category technology is currently enabled on the central website.
Refusing these categories, or making no choice at all, prevents them from loading. It does not limit your use of the website.
8. Campaign attribution and conversion measurement
When you arrive at the central website from an advertisement, the link may carry campaign parameters (for example "utm_source", "utm_campaign") and an advertising click identifier issued by the platform (for example "gclid", "gbraid", "wbraid" from Google, or "fbclid" from Meta).
We record these in the server-side session carried by the strictly necessary session cookie described in section 5(a). We do not place a separate advertising or attribution cookie on your device for this purpose, and we do not read one. If you go on to create an ELVPro account, the recorded values are stored with that account so that the subscription can be related back to the campaign that produced it.
Reporting a conversion to the advertising platform. Where you have accepted the marketing category, we may report the fact that an account was created — and, later, that it became a paid subscription — to the advertising platform that referred you, using Google Ads conversion import and the Meta Conversions API. This is done from our servers rather than from your browser. What is sent is the click identifier above, the time and type of the event, and, where the platform supports it, an irreversibly hashed form of the account email address used solely for matching. We do not send the plain email address, the account contents, or anything about the vehicles or parts in the account.
If you have not accepted the marketing category, no conversion is reported to any advertising platform.
Click identifiers are erased 120 days after they are recorded, which is past the point at which the advertising platforms will accept a conversion for them. Campaign names such as "utm_campaign" identify a campaign rather than a person and are kept for our own acquisition reporting.
9. Technologies on yard storefronts
Depending on features enabled by a particular yard, its storefront may use:
- elvpro_cart_token: a first-party guest-cart/reservation identifier, normally for 30 days;
- chat_visitor_token: a first-party HTTP-only live-chat continuity/security identifier, normally for 7 days;
- elvChatConversation: local storage used to reconnect to an active chat, until the conversation is removed or site data is cleared;
- elvChatProactiveDismissed: session storage remembering that a proactive chat prompt was dismissed, until the browser session ends;
- elv_consent: local storage containing the visitor's analytics/marketing choices and policy version; and
- optional Google Analytics 4, Google Tag Manager, Google Ads, Meta Pixel, TikTok Pixel or LinkedIn Insight technologies configured by the yard.
The yard must list the exact enabled providers, cookie names, purposes, durations, recipients and transfer information in its own notice.
Optional Google Analytics 4, Google Tag Manager, Google Ads, Meta Pixel, TikTok Pixel or LinkedIn Insight technologies are not downloaded or executed before the visitor grants the corresponding analytics or marketing category. ELVPro uses Google's Basic Consent Mode approach. It does not use server-side tagging and does not send pre-consent tracking pings.
10. How to manage choices
On a yard storefront with optional tags, use "Cookie settings" in the footer to accept, reject or change analytics and marketing choices. Rejecting must be as easy as accepting. Withdrawing consent does not affect processing that was lawful before withdrawal.
On the central site, use the "Privacy settings" link in the footer to review, narrow or withdraw an optional choice at any time. The same controls are offered on equal terms: refusing every optional category is a single action, exactly like accepting all of them. Withdrawing consent stops future loading of the relevant technologies and stops any further conversion reporting described in section 8; it does not affect processing that was lawful before withdrawal.
You may also reset the stored decision by deleting "elvpro_cookie_consent" and the "elv_consent" local-storage entry in your browser.
You may also delete or block cookies through browser settings. Blocking strictly necessary cookies can prevent login, checkout, cart, security or other requested functions from working.
Browser controls do not always stop server-side security logs or the cookieless first-party analytics described above. For that analytics, use the "Privacy settings" control in the site footer, enable "Do Not Track", or object as described in the Privacy Policy. An objection recorded through the footer control stops future collection immediately and stays in effect until you withdraw it there.
11. Consent records
Where optional consent is requested, on the central website and on yard storefronts alike, ELVPro keeps a minimised proof record containing the choice, categories, policy version, time, coarse country and a daily pseudonymous visitor hash. This is accountability evidence, not permission to use rejected categories. It is retained for the limited period stated in the Privacy Policy.
12. Changes and contact
We update this Policy and its effective date when technologies or providers change.
Questions:
- SYNCDEV S.R.L.
- General questions: hello@elvpro.eu
- Privacy questions: dpa@elvpro.eu