Cookie & Storage Technologies Policy

Last updated: August 21, 2026

1. Introduction

This Cookie and Storage Technologies Policy explains how StaffSync Portal ("StaffSync", "we", "us", or "our") uses cookies, local browser storage, and related web technologies when you visit our website, log into our client workspace dashboards, or access our employee self-service portals.

We are committed to transparent information practices in accordance with the Privacy and Electronic Communications Regulations (PECR), the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and relevant provisions of the Data (Use and Access) Act 2025.

2. What Are Cookies and Storage Technologies?

HTTP Cookies: Cookies are small data text files placed on your device (computer, tablet, or smartphone) by your browser when you visit a website. Cookies allow web applications to identify your browser session, maintain secure authentication, and remember preference settings across page loads.

Local Storage (localStorage): HTML5 local storage is a browser technology that allows web applications to store key-value data locally within your browser with no automatic transmission to the server on every request. StaffSync uses local storage strictly for client-side interface state (such as your chosen visual theme and notice acknowledgment state).

3. Our Privacy-First Approach

StaffSync operates a privacy-conscious, business-focused platform. We do not deploy cross-site advertising trackers, third-party behavioral profiling cookies, or invasive marketing beacons.

We classify storage technologies into four distinct categories:

  • Strictly Necessary: Essential for platform security, user authentication, and basic service operation. Under UK PECR regulation 26, strictly necessary storage is exempt from the requirement for consent because the service requested by the user cannot be provided without it.
  • Functionality & Preferences: Used to remember user-requested interface settings (such as light/dark visual theme or acknowledging informational notices).
  • Analytics & Performance: Used to understand aggregated site usage and improve performance where consent has been granted.
  • Marketing: Used for campaign attribution where explicit consent has been granted.

4. Comprehensive Storage Inventory

The following table lists every cookie and browser storage item verified in the current StaffSync product:

Identifier / NameType & OriginCategoryLifespanTechnical Purpose & Security
sessionHTTP Cookie (1st party)Strictly Necessary24 Hours (from login/renewal)Holds a cryptographically signed JWT (HS256) maintaining authenticated login state for Master Admin, Client Admin, Manager, Viewer, and Employee users. Configured with HttpOnly, SameSite=Lax, and Secure flags in production.
staffsync_cookie_consentHTTP Cookie (1st party)Preferences / Functionality365 DaysStores a JSON string recording your cookie consent preferences (necessary, preferences, analytics, marketing, and timestamp) so the banner does not repeatedly prompt on subsequent visits.
staffsync_location_notice_acknowledged_v1localStorage (1st party)Functionality / PreferencePersistent in browserRecords whether an Employee Portal user has read and acknowledged the timeclock location-verification information notice, preventing unnecessary repetitive modal popups.
app-themelocalStorage (1st party)Functionality / PreferencePersistent until resetStores user-selected visual theme choice (light or dark mode) when explicitly toggled. Removed when reverting to system default.

5. Current Status of Optional Scripts & Analytics

Our application includes a consent-gating registry (OptionalScriptsGate) and provides preference controls for Analytics and Marketing categories.

Current Factual Position: StaffSync does not currently load third-party analytics scripts (such as Google Analytics, PostHog, or Mixpanel) or marketing tracking pixels through this optional-script registry. If optional performance or measurement tools are introduced in the future, they will strictly require prior opt-in consent and will be gated by our cookie consent manager before any script executes or cookie is set.

6. How to Control and Manage Cookies

You have multiple options to control and manage how cookies and storage technologies are used on your device:

A. StaffSync Cookie Preference Centre

You can review, modify, or withdraw your cookie preferences at any time by clicking the link below or selecting "Cookie Settings" in our website footer:

Cookie Preferences

B. Browser-Level Controls

Most modern web browsers permit you to manage cookie settings through their preferences or options menus. You can configure your browser to block all cookies, reject third-party cookies, or alert you when a cookie is placed.

To find out more about managing cookies in popular browsers, visit:

7. Effect of Disabling Cookies

Strictly necessary cookies (such as our session cookie) are essential for logging into the portal and securing your account. If you configure your browser to reject all cookies, you will be unable to sign in to the Client Admin Portal or Employee Portal, and workspace management features will not function.

Disabling optional preferences or local storage will not prevent you from using the core platform, but your visual theme preferences or notice acknowledgments will reset on each page reload.

8. Changes to this Policy

We may periodically update this Cookie and Storage Technologies Policy to reflect technological changes, product updates, or legal requirements. Any modifications will be posted directly to this page with an updated "Last updated" date.

9. Contact Us

If you have any questions about our use of cookies or storage technologies, please contact our data protection contact at support@staffsyncportal.com or view our full Privacy Policy.