SETROASFLOW: COOKIE & TRACKING POLICY
Version: Draft, 26 August 2026
1. SCOPE
This Policy describes cookies and browser storage used by SetRoasFlow's tracking technology when deployed on a Merchant's website.
2. _SRF COOKIE
The _srf cookie is a signed first-party cookie used to preserve a session identifier and relevant advertising/click identifiers. It is Secure, HttpOnly and SameSite=Lax and has an approximate lifetime of 13 months, subject to browser limitations.
3. AUDIENCE COOKIE
_srf_aud_<token> stores short segment identifiers used for on-site personalization. It is signed, readable by JavaScript and has a 30-day lifetime. A server-side KV copy has a 30-day TTL.
4. ATTRIBUTION LOCAL STORAGE
The client snippet may store first- and last-touch campaign information in localStorage under _srf_ft and _srf_lt. These values contain campaign/source information, including UTM/referrer/landing information, rather than direct personal identifiers.
The current implementation writes this attribution storage without a consent gate.
We treat this storage as requiring consent where ePrivacy rules apply to it, and we are aligning the implementation accordingly. This point is being finalized with counsel; write to [email protected] for the current position.
5. CONSENT
The current implementation gates the _srf and audience cookies using geo-aware consent handling. GPC prevents the audience cookie from being written and prevents advertising-cookie revival for applicable US traffic.
6. THIRD-PARTY ADVERTISING IDENTIFIERS
The system may collect and forward identifiers such as fbp/fbc, gclid/gbraid/wbraid, ttclid/ttp, sc_click_id, epik and rdt_cid where the applicable consent/privacy signal permits.
7. EU EDGE TRANSIT
Where an EU user has not provided the required affirmative consent, the browser request may technically reach the SetRoasFlow first-party Cloudflare edge before the consent state is enforced and the applicable personal data is discarded or anonymized.
We disclose this transit rather than omit it: the request reaches the edge, the consent state is evaluated there, and personal data that may not be processed is discarded or anonymized at that point. This point is being finalized with counsel; write to [email protected] for the current position.
8. MERCHANT RESPONSIBILITY
The Merchant is responsible for its own CMP configuration, cookie banner, privacy notice and lawful basis.