Cookie Policy
Effective: August 11, 2026
This policy lists every cookie RosterSafe sets, what each one does, and how long it lasts. It covers both the public website at rostersafe.com and the application at app.rostersafe.com.
The short version
The application at app.rostersafe.com sets two cookies, and both are strictly necessary to keep you signed in. No analytics runs there, and no screen holding provider or credential data is ever recorded.
This marketing site also runs Microsoft Clarity, which replays how visitors move through the public pages so we can see which parts of them fail to explain the product. It sets three non-essential cookies, named in section 4. We block the request Clarity would otherwise make to Microsoft's advertising identity graph, so none of this is linked to advertising anywhere.
There is no consent banner. If you are in the UK, the EEA or Switzerland, Clarity's consent mode applies by default: it waits for a consent signal before setting any cookie, and we do not send one. Visitors from those regions are therefore measured without cookies, and nothing links one visit to the next.
1. What cookies are
A cookie is a small text file a site stores in your browser. It is sent back on subsequent requests, which is how a site recognizes you between page loads. Some cookies are set by the site you are visiting (first party) and some by other services embedded in it (third party).
2. Cookies we set
Both are strictly necessary. Both are httpOnly, meaning JavaScript cannot read them, and both are sent only over HTTPS.
| Name | Purpose | Lifetime | Type |
|---|---|---|---|
accessToken | Keeps you signed in between requests. It carries a session reference and nothing else, so your permissions are looked up fresh on every request rather than trusted from the cookie. | 5 minutes | First party, strictly necessary |
refreshToken | Gets you a new access token without making you sign in again. It is opaque, and only a hash of it is stored on our side, so the stored value cannot be replayed if our database were ever exposed. | 7 days, or 30 days if you chose to stay signed in | First party, strictly necessary |
Deleting these signs you out. You can do so from your browser settings, or by signing out, which also revokes the session on our side rather than merely dropping the cookie.
3. Cookies set by others
| Set by | Where | Purpose |
|---|---|---|
| Paddle | Checkout, and the public site where Paddle's script loads | Processing payments and recovering failed ones. Paddle is our Merchant of Record and sets its own cookies under its own policy. |
| Cloudflare | Both sites | Security and bot mitigation at the network edge. |
| Only if you use Sign in with Google | Authenticating you with your Google account. |
We do not control these and cannot switch them off individually. See Paddle's privacy policy, Cloudflare's, and Google's.
4. Analytics
We run Microsoft Clarity, on this marketing site only. It records page views, clicks, scrolling and mouse movement, and replays them as session recordings and heatmaps. We use it to find out which parts of these pages fail to explain the product. It is not loaded on app.rostersafe.com, so nothing you do inside the application, on any screen holding provider or credential data, is recorded.
Clarity sets three cookies. Two are first party, stored under rostersafe.com, and one is set by Microsoft on .clarity.ms.
| Name | Purpose | Type |
|---|---|---|
_clck | Holds a Clarity user id for this site, so repeat visits are counted as one person rather than several. | First party, non-essential |
_clsk | Joins several page views into a single session recording. | First party, non-essential |
CLID | Records the first time Clarity saw this browser on any site using Clarity. | Third party (.clarity.ms), non-essential |
We do not run advertising or marketing trackers. Clarity normally also pings c.bing.com to sync the visitor into Microsoft's cross-site advertising identity graph. We block that request in our Content Security Policy, which is why the Microsoft advertising cookies you may have seen listed elsewhere are not set here. Form inputs are masked by default, so what you type is not captured. Behavioural data sent to Clarity is handled under the Microsoft Privacy Statement.
If you are in the UK, the EEA or Switzerland, Microsoft applies consent mode by default: Clarity waits for a consent signal before setting any of these, and we do not send one. Clarity still measures the visit, but it cannot store an identifier in your browser. To opt out of recordings anywhere else, email [email protected].
5. Controlling cookies
Every major browser lets you view, block, and delete cookies in its settings. Blocking the two strictly necessary cookies above will prevent you from signing in, because there would be no way to carry your session between requests. Blocking third-party cookies does not stop you using RosterSafe, though it may interfere with checkout.
To stop Clarity specifically, block cookies for rostersafe.com and clarity.ms in your browser, or use a tracker-blocking extension. Clarity does not set cookies when the browser refuses them.
We do not respond to Do Not Track signals. The setting has no agreed meaning a site can act on reliably, and claiming to honour it would imply a guarantee we cannot verify. Blocking the cookies above is the control that actually works.
6. Changes
If we add or remove a cookie, this page changes at the same time. The effective date above tells you when it was last accurate.
7. Contact
Questions to [email protected]. See also the Privacy Policy, our security practices, and the Terms of Service.