Cookie Policy
Review how RestfulSync uses cookies, tracking technologies, device identifiers, local storage, and related controls across web and mobile experiences.
Document type
Cookie Policy
Brand note
Formerly known as SafeZone
Format
Public-facing legal document
Preamble — Purpose and Scope of This Cookie Policy
This Cookie Policy explains how RestfulSync, Inc. ("RestfulSync," "we," "us," or "our") uses cookies, mobile SDKs, device identifiers, local storage, and similar tracking technologies (collectively, "Cookies and Tracking Technologies") when you use the RestfulSync mobile application (formerly SafeZone), the LawYeti unified platform, and associated web properties (collectively, the "Services").
This Policy is intended to provide you with clear, complete, and transparent information about: what Cookies and Tracking Technologies RestfulSync uses; why we use them and the specific purpose of each; how long they persist; what data they collect; your rights and choices regarding each category; and how to exercise those choices across different devices, browsers, and platforms.
This Cookie Policy forms part of and should be read together with the RestfulSync Privacy Policy, the RestfulSync Terms of Use, and the RestfulSync Security Policy. Where this Policy addresses the same subject matter as the Privacy Policy, both Policies apply and are intended to be read consistently. In the event of a conflict, the Privacy Policy governs with respect to the rights and treatment of personal information.
No Advertising Cookies — Ever
RestfulSync products are ad-free environments. RestfulSync does not use advertising cookies, third-party tracking pixels, behavioral profiling cookies, or any cookie or technology designed to build a profile of your interests for advertising purposes — either for its own advertising or for the benefit of any third-party advertiser or ad network. This commitment is unconditional and is not subject to change based on user consent choices.
RestfulSync does not display ads and does not allow advertisers to pay to reach users through the RestfulSync platform.
Section 1 — What Are Cookies and Why Does RestfulSync Use Them?
1.1 What Are Cookies?
Cookies are small text files placed on your device (computer, smartphone, or tablet) by a website or application when you visit or use it. Cookies allow the website or application to remember certain information about your session or preferences across visits. Cookies set by the website or application you are visiting are called "first-party cookies." Cookies set by other parties (such as third-party payment processors or SDK providers) are called "third-party cookies."
In addition to traditional cookies (which are stored in your browser), RestfulSync uses related technologies that function similarly to cookies in certain contexts:
1.2 Why Does RestfulSync Use Cookies and Tracking Technologies?
RestfulSync uses Cookies and Tracking Technologies for four specific, defined purposes:
Section 2 — Cookie Categories
2.1 Category 1: Essential / Strictly Necessary Cookies.
Essential cookies are cookies that are strictly necessary for the RestfulSync platform to function. Without these cookies, the Services cannot operate — they power authentication, security, compliance enforcement, and safety-critical features. Essential cookies cannot be disabled without disabling the Services themselves.
Because these cookies are necessary for platform security and safety feature operation, they are not subject to user opt-out. RestfulSync's consent management system does not offer an opt-out for essential cookies, and disabling cookies entirely in your browser or device settings will prevent you from logging into or using RestfulSync.
2.2 Category 2: Functional Cookies.
Functional cookies enhance the platform by remembering your preferences and providing a more personalized experience. While the platform can operate without functional cookies, your experience will be degraded — preferences will reset, onboarding will restart, and referral attribution may be lost. RestfulSync uses functional cookies for: subscription tier caching to avoid repeated database queries; user interface preferences (dark/light mode, language, notification settings); jurisdiction caching for CDE performance optimization; Evidence Vault display preferences; onboarding progress tracking; and referral code storage for new user registration attribution.
You may opt out of functional cookies through the RestfulSync Cookie Preferences Center (available in Account Settings → Privacy → Cookie Preferences) or through your browser or device settings. Opting out of functional cookies will not prevent you from using the platform but will disable preference persistence and referral attribution functionality.
2.3 Category 3: Analytics and Performance Cookies.
Analytics cookies collect pseudonymous data about how you and other users interact with the RestfulSync platform. This data is used exclusively for platform improvement — to identify which features are most used, detect usability issues, measure page and feature load performance, and generate crash reports that help developers resolve stability issues. Analytics data collected by RestfulSync is: aggregated before analysis (individual user data is not reviewed); pseudonymous (linked to a session or device identifier, not to your name or email); not shared with advertising networks or data brokers; and not used for any purpose other than platform improvement.
RestfulSync's analytics are first-party analytics operated by RestfulSync. RestfulSync does not embed third-party analytics SDKs (such as Google Analytics, Mixpanel, or similar services) in its platform that would allow those third parties to build profiles of RestfulSync users. Performance and crash metrics are processed by RestfulSync's own internal analytics infrastructure.
You may opt out of analytics cookies at any time through the Cookie Preferences Center in Account Settings. Opting out of analytics will not affect your ability to use any platform feature. RestfulSync will honor opt-out preferences immediately.
2.4 Category 4: Security and Fraud Detection Identifiers.
Security and fraud detection identifiers are not traditional cookies in the marketing sense — they are security mechanisms that function through device-level identification and session risk scoring. RestfulSync uses these technologies exclusively to: detect and prevent multi-account creation in violation of the Terms of Use's one-account policy; detect and prevent billing circumvention and referral fraud; protect against brute force authentication attacks through rate limiting; and identify anomalous session behavior that may indicate account compromise.
Security identifiers cannot be disabled by users because doing so would undermine the platform's ability to protect against fraud and abuse. However, consistent with the Privacy Policy, the raw device fingerprint and IP address data used in fraud logs are programmatically anonymized or hashed after 12 months, limiting the long-term storage of individually identifiable technical data.
Why Security Cookies Cannot Be Opted Out
You may notice that RestfulSync's Cookie Preferences Center does not offer an opt-out for security and fraud detection identifiers. This is intentional. Allowing users to disable fraud detection would enable bad actors to circumvent the one-account policy, create multiple free accounts to obtain referral bonuses, and abuse the SOS system. The minimal privacy impact of a hashed device fingerprint (which cannot be reversed to identify you personally and is anonymized after 12 months) is proportionate to the security benefit it provides to all platform users. We do not believe this represents a disproportionate privacy intrusion.
2.5 Category 5: Payment Processor Cookies (Stripe).
RestfulSync uses Stripe as its payment processor. When you access payment-related features (subscription management, Booster Pack purchases, the On-Demand Access Pass, or video consultation billing), Stripe may set cookies on your device as part of its own fraud prevention, payment session management, and merchant identification functionality. These cookies are set by Stripe and governed by Stripe's own privacy policy and terms of service, not by RestfulSync's Cookie Policy.
RestfulSync has no visibility into or control over the specific technical implementation of Stripe's cookies beyond what Stripe publicly documents. Stripe's cookies are necessary for payment processing and cannot be disabled without disabling the ability to make purchases on the platform. Users who wish to review Stripe's cookie practices should consult Stripe's Privacy Policy and Cookie Policy at stripe.com/privacy.
Section 3 — Complete Cookie and Tracking Technology Inventory
3.1 Master Cookie Inventory.
The following table provides a comprehensive inventory of all cookies and tracking technologies currently deployed by RestfulSync across its web platform and mobile applications. This inventory is reviewed and updated with each Policy revision. Where a cookie is set by a third party (such as Stripe), the third party's name is noted and the third party's privacy policy governs that cookie's data practices.
Cookie / Identifier Name Category Duration Purpose Can Opt Out?
restfulsync_refresh_session Essential Up to 30 days by default (server-configured) Secure HttpOnly refresh-session credential used only to obtain a new short-lived access token; it is rotated by the server and is never readable through browser JavaScript No — required for authenticated web-session continuity
restfulsync_access_session Essential Short-lived; expires according to the signed access token Secure HttpOnly access-session cookie used to authorize authenticated web API requests. The credential is not exposed to browser JavaScript and follows the server-managed authentication session lifecycle. No — required while signed in
No separate RestfulSync CSRF cookie is currently used Essential security control N/A Credentialed refresh requests are restricted to trusted application origins and use a Secure HttpOnly refresh cookie. State-changing application APIs continue to require authenticated authorization. N/A
__rs_device_id Essential 12 months Device identifier used for account security and fraud detection No — security-critical; anonymized after 12 months
__rs_2fa_verified Essential 24 hours Records that MFA was successfully completed for the current session No — security-critical
__rs_consent_record Essential 12 months Stores your cookie consent preferences so you are not prompted on every visit No — required to honor your consent choices
__rs_compliance_profile Essential Session Stores the recording compliance profile (A–D) determined by the Compliance Decision Engine for the current session No — legally required for recording compliance enforcement
SOS session state Essential application state (not represented here as a dedicated web cookie) Active SOS session only Safety-session state is maintained by the applicable app/backend workflow; the current web client does not rely on a dedicated __rs_sos_session_id cookie. No — safety-critical while active
__rs_tier_cache Functional 24 hours Caches your subscription tier to avoid repeated database queries and ensure correct feature access Yes — but may cause feature display inconsistencies
__rs_ui_prefs Functional 12 months Stores your UI preferences (dark/light mode, language, notification settings) Yes — without this, preferences reset each visit
__rs_last_jurisdiction Functional 7 days Caches the last-detected jurisdiction for CDE performance optimization to reduce repeated GPS lookups Yes — CDE will re-detect jurisdiction from scratch each session
__rs_vault_sort_prefs Functional 12 months Stores your preferred sort order and filter settings for the Evidence Vault view Yes
__rs_onboarding_state Functional 30 days Tracks progress through the onboarding flow to resume where you left off across sessions Yes — but onboarding will restart from the beginning
__rs_referral_code Functional 30 days Stores referral code from a referral link click so it can be attributed after account creation Yes — referral credit cannot be applied after opt-out
__rs_analytics_id Analytics 12 months Pseudonymous identifier for aggregated usage analytics — tracks feature adoption and error rates without identifying you personally Yes — via analytics opt-out in account settings
__rs_crash_report_id Analytics 30 days Links crash reports to a session for debugging; contains no personal content, only technical error metadata Yes — but crash reports help improve stability
__rs_fp_hash Security / Fraud 12 months (then anonymized) Hashed device fingerprint used to detect multi-account creation and billing circumvention; cannot be reversed to identify you; anonymized after 12 months per Privacy Policy No — security-critical; anonymized after 12 months
__rs_rate_limit_token Security / Fraud Per-request; very short TTL Rate limiting token to enforce API request throttling and prevent brute force attacks No — security-critical
__rs_risk_score Security / Fraud Session Real-time computed risk score for the current session used to flag anomalous behavior for review; no personal data stored in the cookie itself No — security-critical
__stripe_mid Payment (Stripe) 12 months Stripe's fraud prevention and merchant identifier cookie; set by Stripe SDK. Governed by Stripe's privacy policy. No — required for payment processing
__stripe_sid Payment (Stripe) 30 minutes Short-lived Stripe session cookie for payment flow continuity. Governed by Stripe's privacy policy. No — required for payment processing
3.2 Cookie Inventory Updates.
RestfulSync's platform evolves over time, and the cookie inventory above may be updated as new features are added, old features are deprecated, or vendors change. Any material changes to the cookie inventory — including the addition of new cookies in the Functional or Analytics categories — will be reflected in an updated version of this Cookie Policy published with a revised effective date. Users will be notified of material changes consistent with the notification procedures described in Section 9 of this Policy.
RestfulSync does not add cookies to the Essential or Security/Fraud categories without a clear security or compliance justification, and such additions are subject to internal security team review before deployment. RestfulSync will never add advertising cookies or third-party behavioral tracking cookies to any category without obtaining explicit, prior user consent — and currently has no plans to ever do so.
Section 4 — Cookie Lifetime and Storage
4.1 Session Cookies.
Session cookies are temporary cookies that exist only for the duration of your browser session or active in-app session. They are automatically deleted when you close your browser, log out, or close the application. Session cookies are used for: CSRF protection tokens; SOS session tracking (expires automatically at end of SOS event); compliance profile caching for the current session; rate limiting tokens; and short-lived session analytics data. Session cookies cannot persist your preferences across device restarts or separate visits.
4.2 Persistent Cookies.
Persistent cookies remain on your device for a defined period after your session ends, even after you close the application or browser. Persistent cookies allow the platform to recognize you on return visits, maintain your preferences, and support security continuity. RestfulSync's persistent cookies have the following maximum durations:
4.3 Secure and HttpOnly Flags. The RestfulSync web access-session and refresh-session credentials are set as Secure, HttpOnly cookies, which prevents browser JavaScript from reading either authentication credential and limits transmission to encrypted connections in production. Security and preference values that are not authentication cookies may use browser storage instead of cookies and do not inherit the HttpOnly property.
4.4 SameSite Attribute.
RestfulSync sets the SameSite attribute on all cookies to either Strict or Lax where technically feasible. SameSite=Strict prevents cookies from being sent with cross-site requests entirely, providing strong CSRF protection. SameSite=Lax permits cookies to be sent with top-level cross-site navigations (such as clicking a link from another site to RestfulSync) but not with cross-site subrequests (such as embedded images or iframes). RestfulSync does not set any cookies with SameSite=None without also requiring Secure, consistent with modern browser requirements.
4.5 Local Storage and IndexedDB.
In addition to cookies, the RestfulSync web application uses browser local storage and session storage for limited client-side application state, including sanitized account-display state, selected UI state, device-security identifiers, and narrowly scoped temporary workflow state. RestfulSync access and refresh credentials are not stored in localStorage or sessionStorage; the web client uses Secure HttpOnly cookies for those authentication credentials. The current RestfulSync web client does not persist Evidence Wizard drafts in IndexedDB, and this Policy does not represent that such a web control is currently implemented. Any future offline or IndexedDB-based feature will be added to this inventory when it is actually deployed. Browser storage can be cleared through browser settings; doing so may reset local preferences and require a new sign-in.
Section 5 — Mobile Application Tracking Technologies and SDKs
5.1 Mobile App Tracking — Different From Browser Cookies.
The RestfulSync mobile application (iOS and Android) does not use traditional browser cookies. Instead, the app uses mobile-specific technologies that serve equivalent functions to cookies in the mobile environment. These include: device identifiers stored in secure application storage (iOS Keychain or Android Keystore); session tokens managed by the app's authentication system; first-party and third-party mobile SDKs that collect defined data categories; and operating system-level identifiers where relevant (such as for push notification delivery).
5.2 Mobile SDK and Tracking Technology Inventory.
The following table provides a complete inventory of all mobile SDKs and tracking technologies currently deployed in the RestfulSync mobile application:
SDK / Technology Platform Purpose Data Collected
Device Fingerprint (RestfulSync internal) iOS + Android Fraud detection; multi-account abuse prevention; account security Hashed device model, OS version, screen resolution, timezone — no PII; anonymized after 12 months
Analytics SDK (first-party) iOS + Android Aggregated feature usage and crash reporting Pseudonymous session ID, feature events, error logs — no personal content
Telematics / Location SDK (third-party) iOS + Android Live Map and Safe Trip GPS data transmission to trusted contacts Precise GPS coordinates during active, user-initiated sessions only — not stored beyond session
Stripe SDK iOS + Android Secure payment card input and processing Payment tokenization data — no card numbers stored on device; governed by Stripe privacy policy
Branch.io / Firebase Dynamic Links iOS + Android Deferred deep linking for referral attribution and campaign source detection Campaign source, referral code, install attribution — no personal data transmitted
Push Notification SDK (APNs / FCM) iOS + Android Delivery of SOS acknowledgment alerts, billing receipts, and account security notifications Device push token — no message content is stored in the token
CDE Jurisdiction Module iOS + Android On-device recording compliance profile determination based on GPS or IP fallback GPS coordinates (if active) or IP address — used for compliance determination only, not stored as a tracking record
5.3 Platform-Specific Privacy Controls.
5.4 Push Notification Tokens.
When you enable push notifications for RestfulSync, your device generates a unique push notification token (Apple Push Notification service token on iOS; Firebase Cloud Messaging token on Android). This token is stored on RestfulSync's servers and is used solely to deliver push notifications to your device — including SOS acknowledgment alerts, billing receipts, and critical account security notifications. Push notification tokens are not used for advertising, analytics, or any tracking purpose. Revoking notification permissions on your device automatically invalidates the token for notification delivery, though the token record may remain in RestfulSync's systems until the next time the app attempts to send a notification and receives a delivery failure.
5.5 Deferred Deep Links and Campaign Attribution.
RestfulSync uses Branch.io or Firebase Dynamic Links for deferred deep linking — a technology that allows the platform to detect the campaign or referral source that led to an app install, and to automatically apply the relevant referral code when a new user first opens the app. Data collected during this process includes: the campaign source (e.g., which referral link was clicked); the referral code; the installation timestamp; and the install attribution source (e.g., App Store vs. direct link). This data is used exclusively for referral program administration and to attribute Booster Pack unlocks and Access Pass waivers to the correct referring user. It is not used for advertising or sold to third parties. Branch.io and Firebase Dynamic Links operate under their own privacy policies, and RestfulSync's use of these services is governed by Data Processing Agreements that restrict their use of RestfulSync data.
Section 6 — RestfulSync-Specific Cookie Interactions With Safety Features
6.1 Compliance Decision Engine (CDE) and Jurisdiction Cookies.
The Compliance Decision Engine is RestfulSync's system for automatically enforcing state recording consent laws by detecting the user's geographic jurisdiction and applying the appropriate recording compliance profile (Profiles A through D, as defined in the Terms of Use, Article XI). The CDE's operation necessarily involves the collection and temporary storage of location-related data.
CDE Cookies Cannot Be Opted Out
The recording compliance profile and jurisdiction cache cookies are classified as Essential cookies because they are legally required for RestfulSync to enforce state recording consent laws. Disabling these cookies would prevent the CDE from applying compliance profiles, potentially resulting in recordings being made in jurisdictions where all-party consent is required without proper notice — exposing you to legal liability. These cookies contain no personally identifiable information (only a compliance profile designation) and expire at session end. They are not subject to user opt-out.
6.2 SOS Session State and the 60-Second Exception Window.
SOS and Panic workflows use the session state required by the applicable RestfulSync safety workflow to evaluate the 60-second cancellation exception and the resulting evidence-retention treatment. The current RestfulSync web client does not rely on, set, or claim a dedicated __rs_sos_session_id browser cookie for that purpose. This Cookie Policy therefore distinguishes SOS application/session state from the actual browser-cookie inventory rather than describing a cookie that is not implemented.
6.3 Evidence Vault Session State.
The Evidence Vault web interface uses session-scoped local storage to maintain your vault browsing state (current sort order, active filters, selected evidence item) within a single session. This data is stored in browser local storage, not in a cookie, and is cleared when you close the browser tab or log out. It is not transmitted to RestfulSync's servers and is not used for analytics or any purpose other than maintaining a consistent Evidence Vault browsing experience within a session.
6.4 Fraud Detection and SOS Abuse Prevention.
RestfulSync's security and fraud detection systems monitor SOS activations for abuse patterns (repeated false alarms in violation of the Terms of Use). The __rs_risk_score and __rs_fp_hash cookies contribute to this monitoring by providing the security system with device continuity information. If a device is associated with repeated SOS abuse, fraud, or Terms of Use violations, the hashed device fingerprint enables RestfulSync to enforce account restrictions even if the user creates a new account. This use of device fingerprinting for abuse prevention is a proportionate security measure necessary to protect the integrity of the emergency support service integration and to prevent false alarms.
Section 7 — Your Cookie Choices and Opt-Out Mechanisms
7.1 RestfulSync Cookie Preferences Center.
RestfulSync provides a Cookie Preferences Center accessible from Account Settings → Privacy → Cookie Preferences. The Cookie Preferences Center allows you to: review all cookies currently set by RestfulSync on your device; opt out of Functional cookies (preference caching, UI personalization); opt out of Analytics cookies (pseudonymous usage and performance data); and view the current status of Essential and Security cookies (which cannot be opted out). Changes made in the Cookie Preferences Center take effect immediately and are stored in your account settings so they persist across devices when you are logged in.
In addition to the Cookie Preferences Center, you may control cookies through your browser or operating system settings, as described in Section 7.2. Note that browser-level cookie controls apply to the web platform only — they do not affect mobile app-level tracking technologies, which must be controlled through the Cookie Preferences Center or operating system permissions.
7.2 Browser and Operating System Cookie Controls.
All major web browsers and mobile operating systems provide mechanisms for users to view, control, block, and delete cookies. The following table provides guidance on cookie management paths for common browsers and platforms:
Browser / Platform Cookie Management Path Notes
Google Chrome (Desktop) Settings → Privacy and Security → Cookies and other site data Supports per-site cookie deletion and blocking
Mozilla Firefox Settings → Privacy & Security → Cookies and Site Data Supports enhanced tracking protection levels
Apple Safari (Desktop) Safari → Settings → Privacy → Manage Website Data Intelligent Tracking Prevention (ITP) enabled by default
Microsoft Edge Settings → Cookies and site permissions → Cookies and site data Supports strict, balanced, and basic tracking prevention
Apple Safari (iOS) Settings (device) → Safari → Privacy & Security → Block All Cookies Affects all Safari browsing on the device
Google Chrome (Android) Chrome app → Settings → Privacy and Security → Clear Browsing Data Per-site cookie controls available in Site Settings
iOS — App Tracking Transparency Settings (device) → Privacy → Tracking Controls cross-app tracking; does not affect in-app analytics
Android — Ad ID Reset Settings → Privacy → Ads Resets Google Advertising ID; does not affect in-app analytics
7.3 Effects of Disabling or Deleting Cookies.
Different categories of cookies have different consequences when disabled or deleted. You should be aware of these effects before making changes:
7.4 Do Not Track (DNT) Signals.
Some browsers support a "Do Not Track" (DNT) signal that, when enabled, sends a request to websites and applications not to track your browsing activity. There is currently no universally accepted standard for how websites and applications should interpret or respond to DNT signals. RestfulSync's approach to DNT is as follows: RestfulSync does not engage in cross-site tracking of any kind — we do not track your activity on other websites. Our analytics and fraud detection technologies are first-party and session-scoped. As a result, DNT signals do not materially change what RestfulSync collects from you, as we are not doing the type of cross-site tracking that DNT was designed to prevent. We do not, however, ignore DNT signals in bad faith — if DNT is enabled in your browser, we interpret it as a signal that you prefer minimal data collection and will apply analytics opt-out automatically.
7.5 Global Privacy Control (GPC).
The Global Privacy Control (GPC) is a browser-level signal that communicates a user's preference to opt out of the sale or sharing of personal data for targeted advertising under applicable privacy laws (including CCPA/CPRA). Because RestfulSync does not sell personal data and does not share it for advertising purposes, GPC signals do not require any change in RestfulSync's data practices. However, RestfulSync will honor GPC signals as equivalent to an analytics opt-out preference, consistent with our commitment to respecting user privacy signals even where not strictly legally required.
Section 8 — Third-Party Cookies and No Advertising Commitment
8.1 Third-Party Cookie Inventory.
8.2 No Advertising Cookies — Detailed Commitment.
RestfulSync makes the following unconditional commitments regarding advertising cookies and tracking:
RestfulSync does not display advertising of any kind on its platform. No advertiser pays to reach users through RestfulSync.
RestfulSync does not use advertising cookies, tracking pixels, retargeting scripts, or any technology designed to build a behavioral profile of users for advertising purposes.
RestfulSync does not embed Facebook Pixel, Google Ads, Google Analytics 4 (GA4), LinkedIn Insight Tag, TikTok Pixel, Twitter/X Pixel, or any other third-party advertising platform technology.
RestfulSync does not share user data with advertising networks, data management platforms (DMPs), demand-side platforms (DSPs), or data brokers for advertising purposes.
This commitment is not subject to change based on user consent choices — it is a platform policy commitment, not a consent-based default. RestfulSync's revenue model does not and will not depend on advertising.
8.3 What to Do If You See an Unexpected Cookie.
If you identify a cookie on the RestfulSync domain that is not listed in the inventory in Section 3 and that appears to be set by a third party not identified in this Policy, please report it to privacy@restfulsync.com with the cookie name, the domain it was set by, and how you discovered it. RestfulSync takes any unexpected third-party cookie seriously and will investigate promptly. Unexpected third-party cookies most commonly result from: a browser extension or security tool injecting scripts into RestfulSync pages (not RestfulSync's cookie); a misconfiguration in a third-party dependency that unexpectedly sets a cookie (will be investigated and remediated); or a compromised or modified version of the application (contact security@restfulsync.com if you suspect this).
Third-Party Cookie Reporting
If you identify any cookie on a RestfulSync property that is not listed in this Cookie Policy and that appears to be set by an advertising or analytics third party, please report it to:
privacy@restfulsync.com — Subject: 'Unexpected Cookie Report'
We will investigate within 5 business days and update this Policy if a new technology has been inadvertently deployed.
Section 9 — Changes to This Cookie Policy
9.1 Policy Update Process.
9.2 Material Changes.
9.3 Non-Material Changes.
Non-material changes — including corrections of typographical errors, clarifications that do not change the substantive meaning of any provision, and updates to the cookie inventory table to reflect minor technical changes (such as a cookie being renamed without changing its function) — may be made without advance notice. The "Last Updated" date will be updated and a summary of changes will be included in the header of the revised Policy.
9.4 Your Choices After a Material Update.
If you do not accept a material change to this Cookie Policy, you may: update your cookie preferences through the Cookie Preferences Center to opt out of any newly added non-essential cookie; or, if the change is fundamental to how the platform operates and you cannot accept it, contact support@restfulsync.com to discuss account closure. RestfulSync will never add advertising cookies or behavioral profiling technologies to any category without obtaining explicit affirmative user consent through a new consent flow — a policy change notice alone will not constitute consent for advertising cookies.
Section 10 — Children and Cookie Consent
10.1 Cookie Consent for Minor Users.
Consistent with RestfulSync's COPPA compliance obligations (described in the Privacy Policy, Section 12), cookie consent for users under 13 is obtained as part of the verified parental consent (VPC) process. The parent or guardian who completes the VPC process consents on behalf of the minor to the Essential, Functional, Security, and (where applicable) Analytics cookies necessary to operate the minor's account. Cookie preferences for minor accounts are managed by the parent or guardian through the parent dashboard.
10.2 Teen Users (Ages 13–17).
Teen users between 13 and 17 may manage their own cookie preferences within the Cookie Preferences Center for Functional and Analytics categories, subject to the constraints of their Teen Mode account. Essential and Security cookies cannot be opted out regardless of the user's age. Parents or guardians with VPC authority may also adjust cookie preferences for teen accounts through the parent dashboard and may override any preferences set by the teen user.
10.3 Age Verification and Cookie Consent.
RestfulSync's age verification process (which establishes whether a user is under 13, 13–17, or 18+) relies on self-reported date of birth during account creation, supplemented by behavioral analysis for fraud detection. RestfulSync does not use cookies to determine user age. Age determination occurs through the account data verification process, and the result is reflected in the user's account record, which governs which features and consent flows apply.
Section 11 — Cookie Policy Enforcement and Contact
11.1 Relationship to Other Policies.
This Cookie Policy is part of RestfulSync's integrated legal framework. It operates alongside and is consistent with the RestfulSync Privacy Policy (which governs the collection and use of personal information broadly), the RestfulSync Security Policy (which governs the technical controls that protect data collected through cookies and other means), and the RestfulSync Terms of Use (which governs your use of the platform and your consent to all incorporated policies). In the event of any inconsistency between this Cookie Policy and the Privacy Policy regarding personal data rights, the Privacy Policy governs.
11.2 Enforcement.
RestfulSync's cookie practices are subject to enforcement under: the Federal Trade Commission Act (Section 5) unfair or deceptive practices standards; the California Consumer Privacy Act (CCPA/CPRA), which requires disclosure of cookie-based data collection; applicable state consumer protection laws; and any other applicable privacy or electronic communications laws. RestfulSync is committed to maintaining cookie practices that are accurate, transparent, and fully consistent with the disclosures in this Policy. Any discrepancy discovered between actual cookie practices and the descriptions in this Policy will be treated as a priority issue and corrected promptly.
11.3 Contact Information.
If you have questions about this Cookie Policy, wish to report an unexpected cookie, or want to exercise your cookie consent rights, please contact:
We take all cookie-related inquiries seriously and will respond within the timeframes required by applicable law (generally within 30 to 45 days for privacy rights requests).
RestfulSync is formerly known as SafeZone. RestfulSync and LawYeti are products of LawYeti, Inc. and its affiliates.
