Cookie & Storage Technologies Policy
Last updated: August 21, 2026
1. Introduction
This Cookie and Storage Technologies Policy explains how StaffSync Portal ("StaffSync", "we", "us", or "our") uses cookies, local browser storage, and related web technologies when you visit our website, log into our client workspace dashboards, or access our employee self-service portals.
We are committed to transparent information practices in accordance with the Privacy and Electronic Communications Regulations (PECR), the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and relevant provisions of the Data (Use and Access) Act 2025.
2. What Are Cookies and Storage Technologies?
HTTP Cookies: Cookies are small data text files placed on your device (computer, tablet, or smartphone) by your browser when you visit a website. Cookies allow web applications to identify your browser session, maintain secure authentication, and remember preference settings across page loads.
Local Storage (localStorage): HTML5 local storage is a browser technology that allows web applications to store key-value data locally within your browser with no automatic transmission to the server on every request. StaffSync uses local storage strictly for client-side interface state (such as your chosen visual theme and notice acknowledgment state).
3. Our Privacy-First Approach
StaffSync operates a privacy-conscious, business-focused platform. We do not deploy cross-site advertising trackers, third-party behavioral profiling cookies, or invasive marketing beacons.
We classify storage technologies into four distinct categories:
- Strictly Necessary: Essential for platform security, user authentication, and basic service operation. Under UK PECR regulation 26, strictly necessary storage is exempt from the requirement for consent because the service requested by the user cannot be provided without it.
- Functionality & Preferences: Used to remember user-requested interface settings (such as light/dark visual theme or acknowledging informational notices).
- Analytics & Performance: Used to understand aggregated site usage and improve performance where consent has been granted.
- Marketing: Used for campaign attribution where explicit consent has been granted.
4. Comprehensive Storage Inventory
The following table lists every cookie and browser storage item verified in the current StaffSync product:
| Identifier / Name | Type & Origin | Category | Lifespan | Technical Purpose & Security |
|---|---|---|---|---|
| session | HTTP Cookie (1st party) | Strictly Necessary | 24 Hours (from login/renewal) | Holds a cryptographically signed JWT (HS256) maintaining authenticated login state for Master Admin, Client Admin, Manager, Viewer, and Employee users. Configured with HttpOnly, SameSite=Lax, and Secure flags in production. |
| staffsync_cookie_consent | HTTP Cookie (1st party) | Preferences / Functionality | 365 Days | Stores a JSON string recording your cookie consent preferences (necessary, preferences, analytics, marketing, and timestamp) so the banner does not repeatedly prompt on subsequent visits. |
| staffsync_location_notice_acknowledged_v1 | localStorage (1st party) | Functionality / Preference | Persistent in browser | Records whether an Employee Portal user has read and acknowledged the timeclock location-verification information notice, preventing unnecessary repetitive modal popups. |
| app-theme | localStorage (1st party) | Functionality / Preference | Persistent until reset | Stores user-selected visual theme choice (light or dark mode) when explicitly toggled. Removed when reverting to system default. |
5. Current Status of Optional Scripts & Analytics
Our application includes a consent-gating registry (OptionalScriptsGate) and provides preference controls for Analytics and Marketing categories.
Current Factual Position: StaffSync does not currently load third-party analytics scripts (such as Google Analytics, PostHog, or Mixpanel) or marketing tracking pixels through this optional-script registry. If optional performance or measurement tools are introduced in the future, they will strictly require prior opt-in consent and will be gated by our cookie consent manager before any script executes or cookie is set.
6. How to Control and Manage Cookies
You have multiple options to control and manage how cookies and storage technologies are used on your device:
A. StaffSync Cookie Preference Centre
You can review, modify, or withdraw your cookie preferences at any time by clicking the link below or selecting "Cookie Settings" in our website footer:
B. Browser-Level Controls
Most modern web browsers permit you to manage cookie settings through their preferences or options menus. You can configure your browser to block all cookies, reject third-party cookies, or alert you when a cookie is placed.
To find out more about managing cookies in popular browsers, visit:
7. Effect of Disabling Cookies
Strictly necessary cookies (such as our session cookie) are essential for logging into the portal and securing your account. If you configure your browser to reject all cookies, you will be unable to sign in to the Client Admin Portal or Employee Portal, and workspace management features will not function.
Disabling optional preferences or local storage will not prevent you from using the core platform, but your visual theme preferences or notice acknowledgments will reset on each page reload.
8. Changes to this Policy
We may periodically update this Cookie and Storage Technologies Policy to reflect technological changes, product updates, or legal requirements. Any modifications will be posted directly to this page with an updated "Last updated" date.
9. Contact Us
If you have any questions about our use of cookies or storage technologies, please contact our data protection contact at support@staffsyncportal.com or view our full Privacy Policy.