1. Statutory Authority & Operational Scope
This Enterprise Cookie & Telemetry Policy ("Policy") governs the operational principles, technical mechanisms, and lawful bases for deploying HTTP cookies, local storage objects, and telemetry agents within the Pegasus Logistics Operating System. This disclosure strictly complies with:
- Regulation (EU) 2016/679 (GDPR): Articles 6 (Lawfulness of processing), 7 (Conditions for consent), 12–14 (Transparency and data subject rights).
- Directive 2002/58/EC (ePrivacy Directive): Article 5(3) as amended by Directive 2009/136/EC regarding subscriber consent for terminal equipment access.
- California Consumer Privacy Act (CCPA / CPRA): Cal. Civ. Code § 1798.100 et seq. regarding notices at collection and opt-out of personal data sharing.
- United Kingdom Data Protection Act 2018 & PECR: Regulatory guidance on consent verification and non-essential cookie gating.
- Law of the Republic of Uzbekistan No. ZRU-547: Dated July 2, 2019 "On Personal Data" regulating the collection, systematization, and cross-border processing of digital identifiers.
2. Technical Definitions: Cookies & Storage Technologies
Cookies are standardized key-value text pairs generated by our web servers and stored locally by your browser client. In conjunction with traditional HTTP cookies, the Pegasus platform leverages adjacent client storage primitives:
- HTTP Cookies (First-Party & Third-Party): Small state containers transmitted with each network request via
CookieandSet-Cookieheaders, protected bySameSite=LaxandSecureflags. - Web Storage API (localStorage & sessionStorage): Sandboxed client-side key-value stores used to cache non-sensitive tactical UI state (such as dashboard table column widths and dark/light color tokens) without sending overhead bytes on every API trip.
- Session Tokens: Cryptographically signed JWT identifiers maintaining zero-trust authorization across distributed fleet microservices.
3. Cookie Classification & Lawful Grounds for Processing
Pegasus partitions all browser identifiers into four distinct, audited architectural tiers with discrete consent lifecycles:
Tier A: Strictly Necessary
Essential for cryptographic authentication, CSRF mutation gating, and distributed session routing.
Legal Basis: GDPR Art. 6(1)(f) (Legitimate Interest) / ePrivacy Art. 5(3) ExemptionTier B: Functional Preferences
Preserves freight corridor filters, map perspective, and density settings across sessions.
Legal Basis: GDPR Art. 6(1)(a) (Explicit Prior Consent)Tier C: Analytics & Telemetry
Self-hosted pseudonymized latency monitoring and crash diagnostics without profiling.
Legal Basis: GDPR Art. 6(1)(a) (Explicit Prior Consent)Tier D: Marketing & Partner Attribution
Attribution tracking for enterprise supply chain partner recruitment and wholesale inquiries.
Legal Basis: GDPR Art. 6(1)(a) Consent / CCPA Opt-Out Gated4. Exhaustive Technical Cookie Inventory
The table below provides an audited, line-item disclosure of each identifier deployed within the Pegasus production runtime:
| Identifier | Category | Provider / Host | Retention | Purpose Description |
|---|---|---|---|---|
| pegasus_session | necessary | Pegasus Systems | 30 days | Maintains authenticated supplier, warehouse, and dispatcher JWT sessions with cryptographic integrity. |
| pegasus_csrf | necessary | Pegasus Systems | Session | Protects mutation endpoints against Cross-Site Request Forgery (CSRF) attacks. |
| pegasus_consent | necessary | Pegasus Systems | 12 months | Stores your granular cookie consent choices and timestamp to comply with GDPR Art. 7 audit requirements. |
| pegasus-theme | necessary | Pegasus Systems | 12 months | Remembers tactical dark or operational light visual interface preference across page navigations. |
| pegasus_lang | necessary | Pegasus Systems | 12 months | Stores selected corridor interface language (English, Russian, Uzbek) to deliver statutory translations. |
| hasSeenSplash | necessary | Pegasus Systems | Session | Prevents redundant display of the initial tactical initialization splash screen during a single visit. |
| pegasus_ui_sidebar | functional | Pegasus Systems | 6 months | Remembers expanded or collapsed state of operations navigation rails and density panels. |
| pegasus_corridor_filter | functional | Pegasus Systems | 3 months | Persists active regional freight corridor filtering in tactical fleet and order monitoring views. |
| pegasus_map_view | functional | Pegasus Systems | 3 months | Stores preferred map zoom, tile layer, and geospatial perspective coordinates. |
| _pk_id | analytics | Pegasus Telemetry (Self-Hosted) | 13 months | Stores anonymized pseudonymized identifier to evaluate platform throughput, latency, and page speed. |
| _pk_ses | analytics | Pegasus Telemetry (Self-Hosted) | 30 minutes | Temporary telemetry heartbeat session token measuring real-time API latency without user profiling. |
| sentry_replay | analytics | Sentry Diagnostics | Session | Captures anonymized client-side crash telemetry and call stack traces to debug UI exceptions. |
| _li_fat_id | marketing | LinkedIn Corporation | 30 days | Measures effectiveness of enterprise wholesale supply chain partner communications and recruitment. |
| _gcl_au | marketing | Google LLC | 90 days | Attribution conversion tracker for verified enterprise supply chain procurement inquiries. |
5. Global Privacy Control (GPC) & Do Not Sell / Share Rights
Pegasus natively honors the Global Privacy Control (GPC) signal transmitted by compatible browsers (such as Brave, Firefox, or privacy extensions). When `navigator.globalPrivacyControl === true` or the `Sec-GPC: 1` header is detected, marketing and advertising cookies are programmatically locked in the disabled state in compliance with the California Consumer Privacy Act (CCPA/CPRA).
6. Modifying or Revoking Consent
Pursuant to GDPR Article 7(3), you have the unconditional right to modify or revoke your consent at any time without penalty or loss of fundamental platform service. You may exercise this right by:
- Clicking "Change Preferences" in the interactive control panel above or in the footer on any page.
- Clearing your browser cookies and site storage for pegasus.logistics, triggering a fresh consent prompt upon next visit.
7. Data Protection Officer (DPO) & Inquiries
For technical inquiries, consent audit verifications, or data subject access requests concerning browser telemetry, contact our Data Protection Office:

