The Rota Generator website currently uses storage needed for accounts, security and requested app features. We do not currently run Google Analytics, Meta Pixel or advertising trackers on Rota Generator pages.
1. What this policy covers
“Cookies” are small pieces of information stored by a browser. Similar rules can also apply to other browser-storage technologies such as local storage, session storage and some security identifiers. This policy describes the technologies Rota Generator intentionally uses or causes to be used as part of the service.
2. Technologies currently used
| Technology | Purpose | Typical duration |
|---|---|---|
rota-generator-session or equivalent session cookie | Keeps you securely signed in, maintains session state and supports security protections needed for forms and account access. | Session-based and subject to the configured inactivity lifetime. |
remember_web_* where used | Used only when you choose “Remember me” so your authenticated login can persist beyond the ordinary session. | Longer-lived authentication cookie until it expires, is cleared or the remembered login is invalidated. |
| Cloudflare Turnstile security technology | Helps protect login, registration, password-reset and contact forms from bots and automated abuse. It evaluates browser/security signals and may use security-related browser mechanisms needed to perform the challenge. | Short-lived or as needed for the security check; Cloudflare controls its own challenge mechanisms. |
sessionStorage: rgCopiedShift | Stores a shift you intentionally copy in the rota builder so it can be pasted elsewhere in the same browser session. | Normally cleared when the browser tab/session ends. |
The precise technical name of the Laravel session cookie can vary with application configuration. Its purpose remains account/session operation rather than advertising.
3. Why you do not currently see an “Accept all cookies” banner
At the date of this policy, Rota Generator does not intentionally place advertising or behavioural-tracking cookies on its own pages. The first-party session and requested functionality storage described above are used to provide account, security and rota functionality.
Rather than asking visitors to “accept” technology they cannot meaningfully decline while still using the requested secure service, we explain it here. If we introduce non-essential technology that requires consent, we will add an appropriate choice before that technology is used.
4. Stripe Checkout and Customer Portal
When a customer chooses a paid plan, Rota Generator redirects them to Stripe-hosted Checkout or billing pages. Those pages are provided by Stripe and may use Stripe cookies or similar technologies for payment security, fraud prevention, authentication and operation of Stripe's services.
These Stripe-hosted pages are separate from ordinary Rota Generator pages. More information about Stripe's use of cookies and personal data is available through Stripe's own privacy information.
5. Browser controls
Most browsers let you inspect, block or delete cookies and site data. Blocking the Rota Generator session cookie or security storage can prevent login, forms or protected product functionality from working correctly. Clearing session storage will simply remove temporary client-side items such as a copied shift.
If you believe Rota Generator is setting a non-essential technology that is not described here, contact [email protected] so we can investigate.
6. Future analytics or advertising
If we later add analytics, heatmaps, advertising pixels or similar technology, we will reassess the applicable rules before enabling it. This policy and any required consent or objection controls will be updated at that time.