SETROASFLOW — COOKIE & TRACKING POLICY
Version: Draft — 25 August 2026
1. SCOPE
This Policy describes cookies and browser storage used by SetRoasFlow's tracking technology when deployed on a Merchant's website.
2. _SRF COOKIE
The _srf cookie is a signed first-party cookie used to preserve a session identifier and relevant advertising/click identifiers. It is Secure, HttpOnly and SameSite=Lax and has an approximate lifetime of 13 months, subject to browser limitations.
3. AUDIENCE COOKIE
_srf_aud_<token> stores short segment identifiers used for on-site personalization. It is signed, readable by JavaScript and has a 30-day lifetime. A server-side KV copy has a 30-day TTL.
4. ATTRIBUTION LOCAL STORAGE
The client snippet may store first- and last-touch campaign information in localStorage under _srf_ft and _srf_lt. These values contain campaign/source information, including UTM/referrer/landing information, rather than direct personal identifiers.
The current implementation writes this attribution storage without a consent gate.
[LEGAL REVIEW REQUIRED: determine whether and when this localStorage use requires consent under applicable ePrivacy rules and how it should be disclosed.]
5. CONSENT
The current implementation gates the _srf and audience cookies using geo-aware consent handling. GPC prevents the audience cookie from being written and prevents advertising-cookie revival for applicable US traffic.
6. THIRD-PARTY ADVERTISING IDENTIFIERS
The system may collect and forward identifiers such as fbp/fbc, gclid/gbraid/wbraid, ttclid/ttp, sc_click_id, epik and rdt_cid where the applicable consent/privacy signal permits.
7. EU EDGE TRANSIT
Where an EU user has not provided the required affirmative consent, the browser request may technically reach the SetRoasFlow first-party Cloudflare edge before the consent state is enforced and the applicable personal data is discarded or anonymized.
[LEGAL REVIEW REQUIRED: assess the legal characterization and disclosure of this ephemeral edge transit.]
8. MERCHANT RESPONSIBILITY
The Merchant is responsible for its own CMP configuration, cookie banner, privacy notice and lawful basis.