IMPORTANT: This Policy describes cookies and similar technologies used on shieldportglobal.com. It should be read with the ShieldPort Privacy Policy and Terms of Service.
1. Scope
This Cookie Policy applies to the website and online features operated by ShieldPort IT & Management Marketplace LLC ("ShieldPort," "we," "our," or "us") at shieldportglobal.com and related ShieldPort-controlled pages (collectively, the "Platform"). It explains what cookies and similar technologies are, which technologies were identified on the Platform at the effective date, why they are used, and how users can manage available choices.
This Policy does not govern cookies or technologies placed by an independent website after a user follows an affiliate, travel, product, social-media, payment, or other third-party link. The destination provider's cookie and privacy notices govern those technologies.
2. What Cookies and Similar Technologies Are
A cookie is a small data file stored on or read from a browser or device. Cookies may be temporary session cookies, which generally expire when the browser session ends, or persistent cookies, which remain until their stated expiry or deletion. First-party cookies are associated with the domain being visited; third-party cookies are associated with another domain.
Similar technologies include local storage, session storage, pixels, tags, scripts, software-development kits, referral parameters, and device or browser signals. Some technologies store or access information on a device, while others—such as certain performance beacons or URL referral parameters—may operate without placing a cookie.
3. Current Technology Register
ShieldPort last reviewed the technologies deployed on the Platform on September 6, 2026. The technologies described below were identified in the current implementation or are reasonably necessary for the stated Platform functions. Logged-in, payment, verification, administrative, or future features may use additional strictly necessary technologies. ShieldPort will update this register when its implementation materially changes.
3.1 ShieldPort Platform and Session Technologies
- Provider: ShieldPort IT & Management Marketplace LLC.
- Purpose: Operate the website, maintain requested sessions, process forms, support sign-in and account security, prevent request forgery, remember language or consent choices where implemented, and provide user-requested marketplace functions.
- Category: Strictly necessary or functional, depending on the particular technology and user request.
- Data: A random session or security identifier, consent or language choice, and technical request information. ShieldPort does not intentionally place full payment-card data or passwords in cookies.
The Platform currently sets the following first-party cookies:
- shieldport-session — the session cookie. It holds a random session identifier only; the session record itself is stored on ShieldPort's servers. It carries the signed-in session, the cross-site request forgery token, and the language selected through the site's language switcher. Set
HttpOnlyandSameSite=Lax, so it cannot be read by scripts and is not sent on cross-site requests. It expires 120 minutes after the last request, or when the browser data is cleared. - XSRF-TOKEN — the companion cross-site request forgery token, readable by the Platform's own scripts so that forms and background requests can be submitted securely. It carries no account or behavioural data and expires on the same 120-minute schedule.
Both are strictly necessary: the Platform cannot maintain a sign-in or accept a form submission without them, and neither is used for analytics, advertising, or profiling. Account, sign-in, payment, and authenticated flows may set further strictly necessary session technologies that are not visible to ordinary client-side inspection.
3.2 Google Analytics 4 (Consent Mode v2)
- Provider: Google LLC.
- Technology: The Google tag (
gtag.js), loaded from www.googletagmanager.com, configured with a Google Analytics 4 measurement identifier. The tag is only loaded when ShieldPort has configured a measurement identifier for the environment being visited. - Purpose: Measure page views and aggregate site usage so ShieldPort can understand and improve how the Platform is used.
- Category: Performance and analytics — optional, and not used to deliver advertising.
- Consent behaviour: The tag is loaded with Google Consent Mode v2 and
analytics_storageset to denied by default. Until a visitor accepts through the cookie banner, Google's cookieless consent-mode signals are used and no_gaor_ga_<measurement id>cookie is written. Accepting updates the consent state to granted for that browser; declining leaves it denied. - Storage duration on the device: None unless the visitor accepts. After acceptance, Google's analytics cookies (
_ga,_ga_<measurement id>) are written under Google's own documented durations, up to two years, and may be cleared at any time through the browser.
Cloudflare may separately use strictly necessary security, load-balancing, or challenge cookies if ShieldPort enables the relevant Cloudflare feature or if a security challenge is presented. Examples may include __cf_bm, cf_clearance, or __cflb. These cookies should not be assumed to be active on every visit; their presence and duration depend on the enabled Cloudflare service and security event.
3.3 Affiliate and Referral Links
- Providers: Independent affiliate networks, travel platforms, retailers, and other destination providers selected by ShieldPort from time to time.
- Technology: URL referral parameters, campaign identifiers, redirect domains, and cookies or similar technologies that the independent destination may place after the user follows the link.
- Purpose: Attribute a qualifying click, registration, booking, or purchase to ShieldPort and calculate an affiliate commission.
- Category: Affiliate attribution or advertising, depending on the destination provider's implementation and applicable law.
- Duration: Determined by the independent destination provider or affiliate network. ShieldPort does not state a universal affiliate-cookie duration because it can vary by program, campaign, jurisdiction, browser, and user choice.
ShieldPort's current travel and concierge features are affiliate, referral, informational, or redirect features only. A user completes any booking, payment, cancellation, refund request, or support interaction directly with the destination provider. ShieldPort may receive a referral identifier and commission status but does not receive the user's full travel booking record merely because the user follows a link.
3.4 Consent and Preference Record
The Platform displays a cookie notice with acceptance and decline choices. The choice is stored in the browser's local storage under the key shieldport_cookie_consent, with the value granted or denied. It is used only to remember the visitor's selection, to stop the banner from reappearing, and to determine whether optional technologies may run. It is a first-party record that stays in the browser and is not transmitted to ShieldPort's servers. Because local storage has no expiry, the record persists until the visitor clears their browser's site data, at which point the banner is shown again and analytics returns to the denied default. Such a record is treated as strictly necessary for the privacy choice requested by the user.
4. Cookie Categories
- Strictly necessary. Required to provide a feature requested by the user or to transmit communications, secure the Platform, authenticate an account, process a form, balance traffic, prevent fraud, or remember a privacy choice. These technologies are not used for unrelated advertising.
- Functional. Remember non-essential settings such as language, display choices, or convenience preferences. Consent is requested where applicable law requires it.
- Analytics and performance. Measure visits, performance, errors, and feature use. ShieldPort uses privacy-preserving or aggregated tools where reasonably available and obtains consent where required.
- Affiliate and advertising. Measure referrals, commissions, campaigns, or advertising effectiveness. These technologies may be considered sale, sharing, or targeted-advertising processing under some U.S. state laws and may require consent or an opt-out depending on the jurisdiction and implementation.
5. Consent and Lawful Use
ShieldPort may use strictly necessary technologies without consent where permitted because they are essential to provide a service requested by the user or protect the Platform. Where applicable law requires consent, ShieldPort will not activate functional, analytics, advertising, or affiliate technologies on the ShieldPort domain until the user gives a clear affirmative choice.
Continuing to browse is not treated as consent where affirmative consent is legally required. Rejecting optional technologies will not prevent access to ordinary public content, although blocking necessary technologies may affect sign-in, security, forms, payments, preferences, or other requested features.
6. Managing Choices
Where categories of optional technologies are deployed, the Platform should provide clear options to Accept All, Reject Non-Essential, and Manage Preferences. Users must be able to change or withdraw a prior choice as easily as they gave it, through a persistent cookie-settings link or comparable control.
Users may also delete or block cookies through browser settings. Browser controls vary, and deleting a preference cookie may cause the banner to appear again. Blocking all cookies may impair secure or account-based features.
Where applicable law recognizes a browser-based opt-out signal, such as Global Privacy Control, ShieldPort will process that signal for sale, sharing, or targeted-advertising activity associated with the relevant browser or device. A signal does not necessarily apply to another browser, device, or account.
7. Third-Party Destinations
When a user follows an affiliate or other external link, the browser leaves ShieldPort or contacts a third-party redirect domain. The independent provider may collect an IP address, device or browser data, referral parameters, account information, booking or purchase details, and payment information under its own terms. ShieldPort does not control the provider's cookies, durations, consent interface, or subsequent use of information.
Users should review the destination provider's cookie and privacy notices before submitting personal information. ShieldPort does not represent that rejecting optional cookies on ShieldPort automatically rejects cookies on an independent destination.
8. International Processing
Cookie and technical data may be processed in the United States and other countries where ShieldPort or its service providers operate. Where required, ShieldPort will use an approved transfer mechanism and appropriate safeguards as described in the ShieldPort Privacy Policy.
9. Children
The Platform is intended for adults and is not directed to children. Users must be at least 18 years old to create an account or enter an Order. ShieldPort does not knowingly use cookies to sell, share, or target advertising to children in a manner prohibited by law.
10. Changes to This Policy
ShieldPort may update this Policy when technologies, providers, purposes, durations, legal requirements, or Platform features change. The revised Policy will state its effective date. ShieldPort will request fresh consent where required for a materially different optional purpose.
11. Contact Information
For cookie questions, privacy choices, or rights requests, contact:
A Delaware limited liability company
Registered Office: 16192 Coastal Highway
Lewes, Delaware 19958, United States
Privacy and legal email: [email protected]
General support: [email protected]
Website: https://shieldportglobal.com