Cookie Policy
Version of 29 September 2026
1. What this policy covers
The ShieldWave service is run by Radosław Fedorczuk, trading as ENSOMEDIA Radosław Fedorczuk, ul. Chorwacka 33/42, 51-107 Wrocław, Poland, tax number (NIP) 8952195742, EU VAT number PL8952195742, business register number (REGON) 381626230, entered in the Polish Central Register and Information on Economic Activity (CEIDG). Below we call ourselves "ENSOMEDIA" or "we".
This policy describes what we store in your browser and read from it on the ShieldWave pages at shieldwave.io: the home page, the app, the blog, the free tools and the legal pages.
We describe three kinds of storage:
- cookies: small files that the browser sends back to the server with later requests;
- browser storage: localStorage (kept until you clear the site's data) and sessionStorage (gone when you close the tab); this storage is not sent to the server by itself;
- the app's own cache (a service worker), where the browser keeps copies of ShieldWave's files.
The WordPress plugin "Ensomedia Security powered by shieldwave.io" sets no cookies of its own. How we process personal data is described in the Privacy Policy.
2. Legal basis
Storing information on your device and reading it is governed by Article 399 of the Polish Electronic Communications Law of 12 July 2024. It requires your consent, unless the storage is necessary to transmit a communication or to provide a service you asked for. So necessary storage (section 3.1) and your settings (section 3.2) work without consent, while analytics (section 3.3) and marketing (section 3.4) work only after consent.
Where the storage involves personal data, the GDPR also applies. For necessary storage the legal basis is the contract or our legitimate interest in running and protecting the service (Article 6(1)(b) and (f) GDPR); for analytics and marketing it is your consent (Article 6(1)(a) GDPR).
3. What we store
The tables list everything our pages store in the browser. "Until cleared" means until you clear the site's data in your browser.
3.1 Necessary
| Name | Set by | What for | How long | Kind |
|---|---|---|---|---|
sw_ | ShieldWave | keeps you logged in; page scripts cannot read it (HttpOnly) | 24 hours | cookie |
_csrf | ShieldWave | protects forms against forged requests; set on the first visit | 24 hours | cookie |
__cf_ | Cloudflare | protects the service by telling people from automated traffic; Cloudflare sets it when it checks the traffic | up to 30 minutes | cookie |
cf_ | Cloudflare | remembers that the browser passed a Cloudflare security check | up to 1 year, as Cloudflare sets it | cookie |
shieldwave_ | ShieldWave | remembers your choice in the consent window, with version and date | until you change it (section 6) | localStorage |
wp_ | ShieldWave | the logged-in user name the app needs | until you log out | localStorage |
sw_ | ShieldWave | the plan and period you chose, so that sign-up leads on to payment | until the tab is closed | sessionStorage |
sw_ | ShieldWave | remembers that a purchase confirmation was already shown, so that it is not shown or counted twice (XXXX is the purchase identifier) | until the tab is closed | sessionStorage |
shieldwave- | ShieldWave | copies of the app's files (scripts, styles, images), so that it loads faster and works during a short loss of connection; no check results or account data | until the app is updated or the cache is cleared | app cache |
3.2 Settings
These entries are created when you change a setting or use a feature (such as report history), and serve only to remember it on your device.
| Name | Set by | What for | How long | Kind |
|---|---|---|---|---|
sw_ | ShieldWave | language of the site and app | until cleared | localStorage |
data-, swl- | ShieldWave | light or dark look of the site and app | until cleared | localStorage |
swl- | ShieldWave | whether the animation on the home page moves | until cleared | localStorage |
sw_, swr- | ShieldWave | look of the report | until cleared | localStorage |
sidebar_ | ShieldWave | which menu sections are expanded (XXXX is the section name) | until cleared | localStorage |
wp_, wp_ | ShieldWave | results per page and waiting time set in the app | until cleared | localStorage |
sw_ | ShieldWave | that the app's guided tour was completed | until cleared | localStorage |
sw_ | ShieldWave | list of recent reports (up to 100: domain, format, time, check identifier) | until cleared | localStorage |
shieldwave_ | ShieldWave | that the trial banner was closed | until the tab is closed | sessionStorage |
3.3 Analytics, only after consent
After you consent to analytics, we load Google Tag Manager and through it Google Analytics 4 (Google Ireland Limited). They help us see which pages and features are used.
| Name | Set by | What for | How long | Kind |
|---|---|---|---|---|
_ga | tells browsers apart to count visits and events | up to 2 years | cookie | |
_ga_ | keeps the session state in Google Analytics (XXXXXXXXXX is our property's identifier) | up to 2 years | cookie |
Google explains how it uses data from sites that use its services at policies.google.com/technologies/partner-sites.
3.4 Marketing, only after consent
We use no marketing tags today, and nothing of this group is stored. Consent to marketing has one effect: it lets Google link the data of Google Analytics with its advertising features; without that consent Google does not. When we add a marketing tag, we will name it here and in the consent window and ask for consent again.
4. Stripe's pages and outside content
Payments take place on Stripe's pages, to which we redirect you. Stripe sets its own cookies there under its own rules; we load no Stripe scripts on our pages. We serve fonts from our own server. We embed no maps, videos or social media buttons. Our e-mails contain no tracking pixels.
5. How to accept, refuse and change your choice
On your first visit you see a consent window with three buttons: "Accept all", "Reject all" and "Customize". In "Customize" you choose analytics and marketing separately and save with "Save preferences". Analytics and marketing stay off until you choose them, and we load Google Tag Manager only after you consent to analytics. Refusing does not limit your use of ShieldWave.
You can change your choice at any time with "Cookie settings" in the site footer or in the app menu, which opens the consent window again. After you withdraw consent we stop loading the analytics tools and delete the Google Analytics cookies they set.
You can also block cookies or clear the site's data in your browser. Without the necessary cookies you cannot log in to the app.
6. How long we remember your choice
We store your choice only in your browser (shieldwave_cookie_consent), with the version of the consent window and the date. It applies until you change it. We ask again after 12 months or when the list of tools changes. If you clear the site's data in your browser, we ask on your next visit.
7. Changes to this policy
We change this policy when what we store in the browser changes, and publish each version with its date and an entry in the change history. When we add a tool that needs consent, we ask for consent again. Questions:
- E-mail: support@shieldwave.io
8. Change history
- 29 September 2026: this version replaces the cookie policy of February 2026. It lists the cookies and browser storage the service really uses and names Article 399 of the Polish Electronic Communications Law as the legal basis.