RestfulSync logo
RestfulSync
Cookies

Cookie Policy

Review how RestfulSync uses cookies, tracking technologies, device identifiers, local storage, and related controls across web and mobile experiences.

Document type

Cookie Policy

Brand note

Formerly known as SafeZone

Format

Public-facing legal document

Section 1 — What Are Cookies and Why Does RestfulSync Use Them?

1.1 What Are Cookies?

Cookies are small text files placed on your device (computer, smartphone, or tablet) by a website or application when you visit or use it. Cookies allow the website or application to remember certain information about your session or preferences across visits. Cookies set by the website or application you are visiting are called "first-party cookies." Cookies set by other parties (such as third-party payment processors or SDK providers) are called "third-party cookies."

In addition to traditional cookies (which are stored in your browser), RestfulSync uses related technologies that function similarly to cookies in certain contexts:

Local Storage and Session Storage: Browser-based key-value stores that persist data beyond a single page load. RestfulSync uses local storage for certain UI preferences and session data on web properties.
Mobile SDK Identifiers: On mobile devices, traditional browser cookies are not used for in-app functionality. Instead, RestfulSync uses device identifiers, session tokens stored in secure app storage (not browser cookies), and third-party SDK data collection mechanisms. All of these are described in detail in Section 5 of this Policy.
Device Fingerprinting (Hashed): RestfulSync generates a hashed, pseudonymous device fingerprint from non-personal technical characteristics of your device (such as device model, operating system version, screen resolution, and timezone) for fraud detection and account security purposes. This fingerprint is not reversible to identify you personally and is anonymized after 12 months.
IP Address Collection: When you access RestfulSync, your IP address is collected automatically and is used for fraud detection, security, and — as a fallback — for the Compliance Decision Engine's jurisdiction detection when GPS is unavailable. IP address data in fraud logs is anonymized after 12 months.

1.2 Why Does RestfulSync Use Cookies and Tracking Technologies?

RestfulSync uses Cookies and Tracking Technologies for four specific, defined purposes:

Essential Platform Operation: To keep you authenticated, protect against CSRF and injection attacks, enforce the SOS 60-second exception window, apply recording compliance profiles, and perform other functions without which the platform cannot operate.
Functional Personalization: To remember your preferences (language, display mode, vault sort order), resume onboarding progress, and attribute referrals accurately.
Analytics and Performance: To collect aggregated, pseudonymous data on how users interact with the platform so RestfulSync can identify issues, improve features, and measure performance. Analytics data is not linked to your name or email address.
Security and Fraud Detection: To generate the hashed device fingerprint and session risk score used to detect multi-account abuse, billing circumvention, and unauthorized access attempts.
RestfulSync does NOT use cookies or tracking technologies for: advertising or marketing profiling; cross-site behavioral tracking; selling data to data brokers; or any purpose not listed above.

Section 5 — Mobile Application Tracking Technologies and SDKs

5.1 Mobile App Tracking — Different From Browser Cookies.

The RestfulSync mobile application (iOS and Android) does not use traditional browser cookies. Instead, the app uses mobile-specific technologies that serve equivalent functions to cookies in the mobile environment. These include: device identifiers stored in secure application storage (iOS Keychain or Android Keystore); session tokens managed by the app's authentication system; first-party and third-party mobile SDKs that collect defined data categories; and operating system-level identifiers where relevant (such as for push notification delivery).

All mobile tracking technologies used by RestfulSync are subject to the same privacy principles as browser cookies: they are used only for the four defined purposes (essential operation, functional personalization, analytics, and security/fraud detection); they do not include advertising or behavioral profiling technologies; and they are subject to the same user control mechanisms described in Section 7, adapted for the mobile context.

5.2 Mobile SDK and Tracking Technology Inventory.

The following table provides a complete inventory of all mobile SDKs and tracking technologies currently deployed in the RestfulSync mobile application:

SDK / Technology Platform Purpose Data Collected

Device Fingerprint (RestfulSync internal) iOS + Android Fraud detection; multi-account abuse prevention; account security Hashed device model, OS version, screen resolution, timezone — no PII; anonymized after 12 months

Analytics SDK (first-party) iOS + Android Aggregated feature usage and crash reporting Pseudonymous session ID, feature events, error logs — no personal content

Telematics / Location SDK (third-party) iOS + Android Live Map and Safe Trip GPS data transmission to trusted contacts Precise GPS coordinates during active, user-initiated sessions only — not stored beyond session

Stripe SDK iOS + Android Secure payment card input and processing Payment tokenization data — no card numbers stored on device; governed by Stripe privacy policy

Branch.io / Firebase Dynamic Links iOS + Android Deferred deep linking for referral attribution and campaign source detection Campaign source, referral code, install attribution — no personal data transmitted

Push Notification SDK (APNs / FCM) iOS + Android Delivery of SOS acknowledgment alerts, billing receipts, and account security notifications Device push token — no message content is stored in the token

CDE Jurisdiction Module iOS + Android On-device recording compliance profile determination based on GPS or IP fallback GPS coordinates (if active) or IP address — used for compliance determination only, not stored as a tracking record

5.3 Platform-Specific Privacy Controls.

Apple iOS: The iOS App Tracking Transparency (ATT) framework requires apps to request permission before tracking users across apps and websites owned by other companies. RestfulSync does not engage in cross-app tracking and therefore does not request ATT permission from iOS users. Our analytics and device fingerprinting are first-party, in-app only, and do not use the advertising IDFA (Identifier for Advertisers). iOS users may control app permissions (location, notifications, camera, microphone) through Settings → Privacy on their device.
Android: Android users can control app permissions (location, camera, microphone, notifications) through Settings → Apps → RestfulSync → Permissions. Android users can reset the Google Advertising ID through Settings → Privacy → Ads, though this does not affect RestfulSync's first-party analytics identifier, which is independent of the Advertising ID.

5.4 Push Notification Tokens.

When you enable push notifications for RestfulSync, your device generates a unique push notification token (Apple Push Notification service token on iOS; Firebase Cloud Messaging token on Android). This token is stored on RestfulSync's servers and is used solely to deliver push notifications to your device — including SOS acknowledgment alerts, billing receipts, and critical account security notifications. Push notification tokens are not used for advertising, analytics, or any tracking purpose. Revoking notification permissions on your device automatically invalidates the token for notification delivery, though the token record may remain in RestfulSync's systems until the next time the app attempts to send a notification and receives a delivery failure.

5.5 Deferred Deep Links and Campaign Attribution.

RestfulSync uses Branch.io or Firebase Dynamic Links for deferred deep linking — a technology that allows the platform to detect the campaign or referral source that led to an app install, and to automatically apply the relevant referral code when a new user first opens the app. Data collected during this process includes: the campaign source (e.g., which referral link was clicked); the referral code; the installation timestamp; and the install attribution source (e.g., App Store vs. direct link). This data is used exclusively for referral program administration and to attribute Booster Pack unlocks and Access Pass waivers to the correct referring user. It is not used for advertising or sold to third parties. Branch.io and Firebase Dynamic Links operate under their own privacy policies, and RestfulSync's use of these services is governed by Data Processing Agreements that restrict their use of RestfulSync data.

Section 8 — Third-Party Cookies and No Advertising Commitment

8.1 Third-Party Cookie Inventory.

RestfulSync currently uses the following third-party cookies: Stripe's __stripe_mid and __stripe_sid cookies (payment processing and fraud prevention, as described in Section 2.5 of this Policy). These are the only third-party cookies that RestfulSync permits to be set on users' devices through its web platform or mobile application. RestfulSync does not embed any third-party advertising networks, social media tracking pixels, behavioral analytics platforms, or any other third-party cookie-setting services.

8.2 No Advertising Cookies — Detailed Commitment.

RestfulSync makes the following unconditional commitments regarding advertising cookies and tracking:

RestfulSync does not display advertising of any kind on its platform. No advertiser pays to reach users through RestfulSync.

RestfulSync does not use advertising cookies, tracking pixels, retargeting scripts, or any technology designed to build a behavioral profile of users for advertising purposes.

RestfulSync does not embed Facebook Pixel, Google Ads, Google Analytics 4 (GA4), LinkedIn Insight Tag, TikTok Pixel, Twitter/X Pixel, or any other third-party advertising platform technology.

RestfulSync does not share user data with advertising networks, data management platforms (DMPs), demand-side platforms (DSPs), or data brokers for advertising purposes.

This commitment is not subject to change based on user consent choices — it is a platform policy commitment, not a consent-based default. RestfulSync's revenue model does not and will not depend on advertising.

8.3 What to Do If You See an Unexpected Cookie.

If you identify a cookie on the RestfulSync domain that is not listed in the inventory in Section 3 and that appears to be set by a third party not identified in this Policy, please report it to privacy@restfulsync.com with the cookie name, the domain it was set by, and how you discovered it. RestfulSync takes any unexpected third-party cookie seriously and will investigate promptly. Unexpected third-party cookies most commonly result from: a browser extension or security tool injecting scripts into RestfulSync pages (not RestfulSync's cookie); a misconfiguration in a third-party dependency that unexpectedly sets a cookie (will be investigated and remediated); or a compromised or modified version of the application (contact security@restfulsync.com if you suspect this).

Third-Party Cookie Reporting

If you identify any cookie on a RestfulSync property that is not listed in this Cookie Policy and that appears to be set by an advertising or analytics third party, please report it to:

privacy@restfulsync.com — Subject: 'Unexpected Cookie Report'

We will investigate within 5 business days and update this Policy if a new technology has been inadvertently deployed.