This page explains what cookies (and similar browser-storage tech) StaffNet uses, why, and how long they stick around. It complements our Privacy Policy.
Short version.
We only use cookies that are necessary to run the app - authentication, security, saved UI preferences. We do not use tracking or advertising cookies. Your consent choice is remembered in your own browser only.
1. What is a cookie?
A cookie is a small text file that a website stores in your browser so it can remember you between page loads. Some are essential (like the one that keeps you signed in). Others are optional (analytics, advertising) - we don't use those.
2. Cookies StaffNet uses
Strictly necessary
These make the app work. You can't turn them off without breaking sign-in.
-
staffnet_session- Laravel session cookie. Keeps you signed in on the tenant subdomain. First-party, HTTP-only, secure. Expires when you sign out or after the session timeout (default 2 hours idle). -
XSRF-TOKEN- CSRF protection. Ensures form submissions come from the real site and not a malicious page. First-party. Session-scoped. -
theme- remembers whether you chose light or dark mode. First-party. Persists across visits. -
sidebar-compact- remembers if you collapsed the sidebar. First-party. Persists across visits. -
st_ticket_*/st_chat_*- anonymous session tokens for public support tickets and live chat, so you can close the browser and come back to the same conversation. First-party. 30 days.
Preferences (localStorage)
Not technically cookies but browser-local. Same treatment applies - stays on your device only, no server round-trip.
-
staffnet_cookie_consent- your consent choice on this banner. - Dashboard widget layout, filter presets, UI hints seen - the app remembers your personal UI state locally.
Analytics / advertising
None. We do not use Google Analytics, Facebook Pixel, or any third-party tracker on the public marketing pages or inside the app.
If we ever add opt-in analytics in the future, we will surface a clear toggle here and default it to off.
3. Third-party cookies
A few integrations may drop their own cookies when you use them:
- Paystack - during checkout, Paystack sets cookies inside its own payment page. Governed by Paystack's privacy policy.
-
Google Fonts - our public pages load fonts from
fonts.googleapis.com. Google may log the request. No cookies are set.
4. Managing cookies
You can:
- Delete cookies through your browser's settings. Deleting session cookies will sign you out.
- Block cookies for a specific site. Blocking StaffNet's session cookie means you cannot sign in.
- Use "private" / "incognito" browsing to avoid persistent cookies entirely.
We do not need your consent for the strictly-necessary cookies listed above - they are exempt under NDPR and standard cookie-law practice. If we ever add optional cookies we will ask before setting them.
5. Do-Not-Track
We honour the browser Do-Not-Track signal by default, though since we don't run tracking cookies it's effectively a no-op.
6. Changes
We update this page when the cookie list changes. The "Last updated" date at the top reflects the last edit.
7. Contact
Questions about cookies? Email hello@fregatelab.com or use the contact form.