1. What cookies are
A cookie is a small text file a site saves in your browser and reads on later visits. This site uses session and consent cookies and, with performance consent, a first-party visitor identifier. Any later use of similar technologies must be added to this inventory before activation.
Similar technologies can include browser local storage, pixels or embedded identifiers. The first-party public and account interface does not currently use localStorage or sessionStorage for tracking. Session data is held on the server; the cookie contains the identifier needed to retrieve it, not your complete profile.
2. The legal basis
In Romania, storing and reading cookies on your terminal equipment is governed by art. 4(5) of Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector. The rule is prior consent, given after clear and complete information. The exception covers cookies strictly necessary to transmit a communication or to provide a service you have expressly requested.
On top of that comes Regulation (EU) 2016/679 (GDPR), which sets the basis for processing the personal data read from cookies: consent, under art. 6(1)(a), for the non-essential categories, and legitimate interest, under art. 6(1)(f), for those strictly necessary to run the site. Citing the GDPR alone is not sufficient in Romania — the two texts apply together, and the table below cites both for every category.
Consent is given by a clear affirmative action: you tick the categories you want or press the accept button. Continuing to browse, scrolling the page or closing the banner does not amount to consent, and no box is pre-ticked. Until you choose, only strictly necessary cookies are set. Refusing is as easy as accepting.
The strictly necessary storage exception is interpreted narrowly: the function must not reasonably be capable of being provided without that storage. For associated personal data, the GDPR basis may be performance of the requested service, a legal duty or legitimate interest according to the specific function; the “necessary” label does not create a basis by itself.
3. Consent categories and current inventory
The preferences panel has four categories. Strictly necessary storage is active; performance storage is optional; functional and marketing integrations are reserved but not currently declared as active.
| Category | What they do | Examples | Legal basis | Duration |
|---|---|---|---|---|
| Strictly necessary | Keep the sign-in session, protect forms against CSRF attacks and remember your cookie choices. | Application session, anti-CSRF token and evo_consent preference record. | Art. 4(5) of Law no. 506/2004 — the exception for a service you expressly requested, no consent needed; art. 6 GDPR — contract, legal duty or legitimate interest according to the specific function. | From the browsing session up to 12 months. |
| Performance and statistics | Associate consented visits with a random first-party identifier so traffic and page use can be measured. | evo_vid and first-party visitor/page-view records. No third-party analytics tool is currently declared. | Art. 4(5) of Law no. 506/2004 — prior consent; art. 6(1)(a) GDPR. | evo_vid: up to 2 years on a sliding basis; detailed first-party visitor data: up to 14 months. |
| Functional | Reserved for optional convenience features that may remember a choice after this policy and the inventory are updated. | No functional integration is currently declared; the consent record can store your choice without activating one. | Art. 4(5) of Law no. 506/2004 — prior consent; art. 6(1)(a) GDPR. | No functional identifier is currently set. |
| Marketing | Reserved for a future advertising integration, which may run only after this policy names it and you consent. | No advertising or marketing-cookie integration is currently declared. | Art. 4(5) of Law no. 506/2004 — prior consent; art. 6(1)(a) GDPR. | No marketing identifier is currently set. |
4. Consent and withdrawing it
You can change your choices at any time from the cookie banner or from your browser settings. Withdrawing consent is as easy as giving it and does not affect the lawfulness of processing carried out beforehand.
The evo_consent cookie records the policy version, timestamp and category choices in the browser for up to 12 months. The platform does not currently create a separate server-side profile of the person merely from this choice. A changed policy version or a new purpose requires a new choice.
- The panel opens automatically only on the homepage on a desktop screen while there is no valid choice; this interface detail does not change the consent rule.
- The “Cookie settings” button reopens the panel on public pages and in the account area, so a choice can be changed without finding the initial banner.
- All optional categories remain off until affirmative action, and accept and refuse are presented at the same level.
- Closing the panel without choosing does not mean acceptance and does not create evo_consent.
- When performance consent is withdrawn, evo_vid expires on the next response and the journey is no longer continued; later activation may require a page reload to begin measurement.
5. Third-party cookies
The station map requests tiles from OpenStreetMap infrastructure when the map opens, so that provider receives ordinary web-request data even though no map cookie is declared here. Payment components are loaded only on the relevant charging or card page and are governed by the payment provider's policy. No embedded-video or advertising integration is currently declared.
6. Browser settings
You can block or delete cookies directly in your browser, usually from its privacy settings. Blocking strictly necessary cookies can stop sign-in and protected forms from working; there is currently no shopping basket on this site.
7. Questions
For anything unclear about cookies or the data read through them, write to us through the contact form. How we handle personal data generally is described in the Data protection.
8. Current technical inventory
Configurable names and supplier behaviour must be checked again before launch and after every integration. The table describes storage observable in the current implementation; it does not promise that a third party will never change its technology.
| Name or component | Provider | What they do | Category | Duration |
|---|---|---|---|---|
| Application session cookie (name configured for the network) | Network operator | Authentication, session continuity and protection of requested flows and forms. | Strictly necessary | Configured inactivity period; the current default is 120 minutes. Server-side data cleanup may have its own cycle. |
| evo_consent | Network operator | Records the version, time and selected categories so the choice is not requested on every page. | Strictly necessary to remember the preference | Up to 12 months, or until deleted or the policy version changes. |
| evo_vid | Network operator | Links consented visits through a random first-party identifier for our own statistics. | Performance, only with consent | Up to 2 years, renewed on use; it expires after refusal or withdrawal on the next response. |
| Stripe Payment Element and its technical storage | Stripe | Secure payment processing, authentication and fraud prevention on the payment page. | To be validated before launch: strictly necessary only for the requested payment function; any extra purpose needs separate classification. | Set by Stripe according to component and service; identifiers and duration must be reconfirmed in the live integration. |
9. What happens without performance consent
Without consent, the middleware does not set evo_vid or make a detailed record linking pages viewed by the same browser. Account, safety, map and charging functions must not depend on accepting statistics.
The platform may increment an anonymous daily total for service health, without a visitor identifier or reconstructing a person’s journey. Strictly technical and security logs are separate processing described in the privacy policy.
10. Map, payment and external services
A request to an external service can transmit the IP address and ordinary headers even where that service sets no cookie declared by us. We activate a component only in the context of the function that needs it.
- OpenStreetMap: the browser requests map tiles when you open the station map. We found no first-party map cookie in the code, but the provider receives the ordinary web request.
- Stripe: Payment Element loads in the payment flow and receives card data directly. Its current storage must be checked in the live integration and Stripe notice.
- Email and server-to-server processes: confirmations may use external providers, but those server calls do not by themselves install a cookie in your browser.
- No advertising or video integration that sets marketing identifiers is currently declared.
11. Changes to the inventory
Before enabling a new SDK, pixel, iframe or storage mechanism, the operator must document its name, supplier, purpose, recipients, duration and category, then verify that it is blocked before consent unless strictly necessary.
A new purpose or material reclassification requires an updated policy and panel and, where necessary, a new choice. Tests must cover acceptance, refusal, withdrawal, expiry and RO/EN behaviour.