Signal Sparrow

Legal

Cookie Policy

Effective date: 7 July 2026  |  Last updated: 7 July 2026

1. Scope of this policy

This Cookie Policy explains how Signal Sparrow LTD ("Signal Sparrow," "we," "us"), uses cookies, local storage, and similar technologies. It supplements our Privacy Policy and covers three distinct surfaces, because we play a different role — and a different cookie set applies — in each:

  • The marketing website (signalsparrow.com and its public pages) — where we are the controller.
  • The Signal Sparrow app (the authenticated dashboard your team logs into) — where we are the controller.
  • Our tracking SDK, embedded on a customer's own website — where the cookie is set on the customer's domain and the customer, not Signal Sparrow, is the controller responsible for visitor consent.

"Cookies" in this policy also covers functionally equivalent technologies, such as browser local storage, that we or our SDK use for the same purposes.

2. What a cookie is

A cookie is a small text file placed on your device by a website you visit. Cookies are widely used to make websites function, remember your preferences, keep you signed in, and measure how a site is used. Local storage serves a similar purpose but is not automatically sent with every request and typically persists until the browser or site clears it.

3. Cookies on signalsparrow.com (marketing website)

On the public marketing pages of signalsparrow.com, we use only cookies that are strictly necessary for the site to work. We do not set advertising or analytics cookies on the marketing website, and no cookie consent banner is shown because no non-essential cookie is placed before you interact with the site.

Cookie / storagePurposeTypeDuration
XSRF-TOKENCross-site request forgery protection for form submissions (e.g. signup, login).Strictly necessarySession
{app}-sessionLaravel's session cookie, used to maintain page state during signup and checkout flows.Strictly necessarySession (up to 2 hours idle)

Loading the marketing site also triggers two direct, third-party font requests — Inter from Google Fonts and General Sans from Fontshare. Both requests go straight from your browser to the font provider so that your browser can render the page correctly; neither provider is known to set a cookie for this kind of direct font-file request, but each will receive your IP address and browser headers as an unavoidable part of serving the file. See Section 7 for details.

4. Cookies in the Signal Sparrow app

Once you log in, the authenticated application at signalsparrow.com (or your configured subdomain) uses a small number of first-party cookies to keep you signed in and remember your preferences. We do not use advertising cookies inside the app, and we do not track your activity in the app across other websites.

Cookie / storagePurposeTypeDuration
{app}-sessionKeeps you authenticated between requests.Strictly necessarySession (up to 2 hours idle, refreshed while active)
XSRF-TOKENCross-site request forgery protection for authenticated actions.Strictly necessarySession
remember_web_*Optional "stay signed in" cookie, set only if you select that option at login.Strictly necessary (functional)Up to 5 years, or until you log out
sidebar_stateRemembers whether the app sidebar is expanded or collapsed.Preference1 year
__stripe_mid, __stripe_sidSet by Stripe's JavaScript library when you add or update a payment method on your Billing settings page, for fraud prevention on the payment form.Strictly necessary (third-party)__stripe_mid: 1 year; __stripe_sid: 30 minutes

Stripe cookies are set directly by Stripe.js, which we load only on the payment-method screen. Stripe acts as an independent controller for this fraud-prevention data; see Stripe's Cookies Policy.

5. Cookies set by our tracking SDK on customer websites

Signal Sparrow provides a first-party tracking SDK that our customers embed on their own websites to capture conversion events. When a visitor loads a page where a customer has installed the SDK, the SDK sets a cookie on that customer's domain — not on signalsparrow.com.

Cookie / storagePurposeTypeDuration
__rpv (default name; customer-configurable)Anonymous visitor identifier used to link a visitor session to a later conversion event, for attribution reporting.Analytics / measurementUp to 13 months, refreshed on each tracked interaction where persistence is allowed
Local storage fallback (same purpose as __rpv)Used when cookie storage is unavailable or restricted by the browser.Analytics / measurementUntil cleared by the visitor or the customer’s configured retention window

Who is responsible for consent. The website operator (our customer) is the data controller for this cookie and is solely responsible for displaying any cookie banner required by law and obtaining valid visitor consent before the SDK stores non-essential data. We provide the technical controls that let a customer configure how the SDK behaves before consent is given:

  • Anonymous-only mode (default): no cookie or personal data is stored before the visitor consents; data is enriched only after consent is granted.
  • Hold-until-consent mode: nothing is stored until the customer's own consent management platform signals that consent has been given.

If you are a visitor to one of our customers' websites and have questions about this cookie or want to exercise a data-subject right, please contact that website operator directly — they are the controller of your data. Further detail on our role as a processor is in Section 5 of our Privacy Policy and in our Data Processing Agreement.

6. Cookie categories we use

  • Strictly necessary — required for the site or app to function (authentication, security, load balancing). These cannot be switched off and do not require consent under EU/UK law.
  • Preference — remember a choice you made (such as sidebar state) to improve usability on return visits.
  • Analytics / measurement — used only by the tracking SDK on a customer's site, to attribute a conversion back to a marketing channel. Never used by Signal Sparrow to serve ads or build cross-site advertising profiles.

We do not use, and none of the cookies above are, advertising or targeting cookies. Signal Sparrow does not run ads, does not sell cookie data, and does not use cookies to build advertising profiles of individuals.

7. Third-party cookies and requests

ProviderWhereWhat it receives
Stripe, Inc.Billing settings page in the app (payment-method form only)Fraud-prevention identifiers via __stripe_mid / __stripe_sid; see Section 4.
Google FontsMarketing website (all pages)IP address and browser headers when your browser requests the Inter font file directly from Google.
Fontshare (Indian Type Foundry)Marketing website (all pages)IP address and browser headers when your browser requests the General Sans font file directly from Fontshare.

We do not embed third-party advertising pixels, social share widgets, or analytics scripts (such as Google Analytics or Meta Pixel) on signalsparrow.com.

8. Managing cookies

You can control or delete cookies through your browser settings. Because the cookies we set on signalsparrow.com and in the app are strictly necessary or preference cookies, blocking them may prevent you from logging in or using parts of the Service correctly.

  • Most browsers let you view, delete, and block cookies from their settings or privacy menu (for example, under "Privacy and security" in Chrome, Firefox, Safari, or Edge).
  • If you are a visitor to a customer's website that uses our SDK, look for that website's own cookie banner or preference center to manage the __rpv cookie described in Section 5.
  • Clearing cookies or local storage will reset the anonymous visitor identifier used for attribution, which may affect how a later conversion is credited.

We do not currently respond to browser Do Not Track signals or Global Privacy Control signals on signalsparrow.com, because we do not use tracking, advertising, or analytics cookies that such signals are designed to limit. See Section 11 of our Privacy Policy for our California-specific position.

9. Changes to this policy

We may update this Cookie Policy as our cookie usage changes — for example, if we add a new payment provider or change our font delivery setup. Material changes will be reflected by updating the "Last updated" date at the top of this page. We encourage you to review it periodically.

10. Contact us

Questions about this Cookie Policy, or about a cookie set by our tracking SDK on a website you operate, can be sent to: