Legal

Cookie Policy

Last updated: 2026-08-13 · Effective from the same date
Plain English summary

By default we set only the strictly-necessary cookies that keep you signed in. One exception, and it's opt-in: if you click 'Accept all' on the cookie banner, the marketing site (scarifone.com public pages only — never the dashboard) loads the Meta Pixel so we can measure our own ads. Decline, and it never loads. The tables below list every cookie, what it does, and how long it lives.

1. What cookies are

Cookies are small text files a website stores on your device. They’re used for everything from keeping you logged in to tracking you across the web for advertising. We use them mostly for the first reason — and for the second only on our own marketing site, only with your explicit consent, as described below.

2. Categories we use

We classify cookies as required by UK e-privacy law (PECR) and ICO guidance:

  • Strictly necessary — required for the service to work (e.g. session token). No consent needed; you can’t opt out without breaking the service. We use these.
  • Functional — improve experience but not strictly required (e.g. remembered theme preference). We use one (theme).
  • Analytics — measure usage patterns. Our page analytics (Plausible, when enabled) is cookieless; product analytics (PostHog, when enabled) stores a first-party identifier in your browser. Neither tracks you across other sites.
  • Advertising / trackingconsent-gated, marketing site only. If (and only if) you click “Accept all” on the cookie banner, the public marketing pages load the Meta (Facebook) Pixel. The authenticated dashboard never loads it.

3. The cookies we set ourselves

NamePurposeTypeLifetime
scarif_sessionHMAC-signed session token. Identifies you while signed in. HttpOnly + Secure + SameSite=Lax.Strictly necessary30 days (rolling)
scarif_csrfCSRF protection token for form submissions.Strictly necessarySession
scarif_themeStores your light/dark theme override (if you change from default).Functional1 year

Your cookie-banner choice itself is stored in localStorage (key scarif-cookie-consent) — browser storage rather than a cookie, readable only by our site.

4. The Meta Pixel (consent-gated, marketing site only)

We advertise Scarif One on Meta platforms (Facebook / Instagram), and we measure whether those ads work using Meta’s standard Pixel. Being precise about it:

  • Where: only on the public marketing pages of scarifone.com (homepage, pricing, signup funnel). Never on tenant dashboards or any authenticated page.
  • When: only after you choose “Accept all” on the cookie banner. If you choose “Essential only” (or make no choice), the pixel script is not loaded and no Meta cookies are set.
  • What it collects: page views and funnel events (viewing pricing, starting a checkout, signing up, contacting us), your IP address and browser user-agent, and Meta’s own identifiers. We also send some of the same events server-side to Meta’s Conversions API with hashed identifiers (e.g. a SHA-256 hash of your email at checkout) so duplicate events can be matched and discarded.
  • Why: ad measurement and retargeting audiences for our own marketing. We do not sell this data, and it has nothing to do with any Meta integration a tenant connects for their own store — that is separate, tenant-controlled, and governed by the tenant’s own policies.
NamePurposeTypeLifetime
_fbpSet by Meta's pixel script to distinguish browsers for ad measurement. Only set after 'Accept all'.Advertising (third party — Meta)~90 days
_fbcSet by Meta when you arrive from a Meta ad click (stores the click id). Only set after 'Accept all'.Advertising (third party — Meta)~90 days

Meta’s own handling of this data is described in Meta’s privacy policy. To withdraw consent, clear this site’s browser storage (which resets the banner) and choose “Essential only”, and delete the _fbp/_fbc cookies in your browser settings.

5. Analytics

When enabled on an install, we use Plausible Analytics for page analytics — first-party, cookieless, no cross-site tracking — and PostHog for product analytics, configured privacy-first: no autocapture, profiles only for identified users, EU hosting preferred. PostHog stores a first-party identifier in your browser storage to keep sessions coherent; it does not follow you around the web. Self-host (Sovereign) installs ship with no analytics at all unless the operator configures them.

6. How to control cookies

Most browsers let you block or delete cookies via settings. Blocking strictly-necessary cookies will break sign-in. Blocking functional cookies just resets your preferences each visit. The Meta Pixel is controlled by the consent banner — it simply never loads unless you accepted all cookies.

If you want us to delete all your cookies server-side (e.g. log out everywhere), use the “Sign out of all devices” button in /security in the dashboard.

7. Updates

If we add a new cookie or change purpose, we update this page and the “last updated” date. Material changes (new categories, new third-party processors that set cookies) trigger a fresh consent prompt.

8. Contact

Questions: [email protected].

Questions about this document? Email [email protected] for privacy / DPA questions, [email protected] for everything else. Tom replies within a few hours during UK office hours.