Privacy

Cookie & Technology Policy

Last revised August 13, 2026

This policy describes the cookies, local or session storage, security technology, and browser telemetry currently used by Syferway. Some technologies are cookieless, so “technology” is more accurate than “cookies” alone.

This is a measured technical notice and legal draft. Provider retention and contractual details that cannot be verified from the application are identified rather than guessed.

1. Your choices

Necessary technology is used for security, sign-in, requested functionality, and service delivery. Optional Analytics is off until you positively allow it. Rejecting Analytics does not block Syferway.

2. Necessary and functional technology

Name / providerMechanism and purposeDuration and activation

Supabase authentication session

Syferway / Supabase

Secure first-party cookies

Sign-in, session refresh, OAuth/PKCE, and authenticated requests.

Controlled by the authenticated session and Supabase Auth configuration; removed or expired through sign-out/session lifecycle.

When you sign in or start an authentication flow.

syf_staff_access

Syferway

Signed, HttpOnly first-party cookie

Authorizes valid Staff Access for the private launch surface.

14 days by default; production configuration is constrained to 1 hour–30 days.

After a valid Staff Access code.

syf_staff_rl

Syferway

Signed, HttpOnly first-party cookie

Rate-limits repeated Staff Access attempts.

Up to 15 minutes.

After a failed Staff Access attempt.

syf_recovery, syf_recovery_pkce, syf_recovery_pending

Syferway / Supabase

Encrypted, HttpOnly first-party cookies

Keeps a password-recovery and PKCE flow bound to the browser without exposing recovery tokens to client JavaScript.

Up to 15 minutes and scoped to recovery/callback routes.

When you request or complete account recovery.

syf_onb_done

Syferway

Signed, HttpOnly first-party cookie

Caches the completed onboarding state to avoid an unnecessary database check on each request.

Up to 24 hours.

After authenticated onboarding is completed.

Turnstile challenge technology

Cloudflare

Third-party challenge script, network request, and security state as required by Cloudflare

Detects automated abuse on protected public forms. It is security technology, not optional product analytics.

Controlled by Cloudflare’s challenge lifecycle and security documentation.

On a form protected by Turnstile.

Syferway also uses first-party local/session storage and small preference cookies for choices you request, including theme/workspace layout, sidebar state, notification read state, draft recovery, AI library state, Backtesting panel layout, and short-lived navigation/recovery state. These records are functional, are not advertising identifiers, and remain until the preference is changed, the browser/session is cleared, or an applicable built-in expiry is reached.

The first-party local-storage record syferway.consent stores only the policy version, Analytics true/false, Reviews widget true/false, and decision timestamp. It contains no email, account ID, or random tracking identifier.

3. Optional Analytics

If you allow Analytics, Syferway loads Vercel Web Analytics and Vercel Speed Insights in the browser. They send cookieless page-use and performance information to Vercel. They do not load merely because the consent banner is displayed, and no advertising or marketing category is used.

  • Provider: Vercel.
  • Purpose: aggregate product usage and web-performance measurement.
  • Mechanism: browser script and HTTPS telemetry beacon; Vercel documents these services as cookieless.
  • Activation: only after a valid positive Analytics decision.
  • Retention: governed by the configured Vercel account and Vercel’s current service/privacy terms; Syferway must verify the production account setting and contract.

Cloudflare client-side Web Analytics/RUM is disabled and is not an approved Analytics vendor in this consent model. Cloudflare proxy, DNS, WAF, Turnstile, and server-side security/traffic operations are separate necessary infrastructure.

3a. Optional Reviews widget (Trustpilot)

If you allow the Reviews widget, the home page loads Trustpilot's TrustBox to show Syferway's live Trustpilot rating. Trustpilot draws it inside its own frame. Without this permission no request is made to Trustpilot; you see a plain link to our Trustpilot page instead.

  • Provider: Trustpilot A/S.
  • Purpose: displaying Syferway's public Trustpilot rating and review count.
  • Mechanism: script from widget.trustpilot.com and a Trustpilot frame; no cookie is set on syferway.com, but Trustpilot's frame uses its own analytics under Trustpilot's terms.
  • Activation: only after a valid positive Reviews widget decision, and only when the rating comes into view.
  • Withdrawal: switching it off saves the choice and reloads the page so the script is removed.

4. Rejecting or withdrawing Analytics

Use Privacy choices in the public footer or Settings → Privacy. If you switch Analytics off after it was on, Syferway saves the rejection and reloads the page so initialized browser analytics listeners are removed. Authentication, Staff Access, security cookies, and workspace preferences are not cleared.

If browser storage is unavailable or the saved record is malformed or from an unknown policy version, Syferway fails closed: optional Analytics remains off and asks for a valid choice again.

5. More information

For personal-data purposes, rights, processors, and contact details, read the Privacy Policy. Browser or operating-system controls can also clear local data, but blocking necessary cookies may prevent sign-in or recovery.