Cookie Policy

Last changed: 25 September 2026

What Are Cookies?

Cookies are small text files stored on your device when you visit a website. They help the website remember your preferences and keep you signed in.

How We Use Cookies

Sajama Campus uses essential authentication cookies. We also remember your optional analytics choice in local storage. Analytics are off until you opt in. We do not use advertising cookies or cross-site tracking identifiers.

CookiePurposeDurationType
sb-*-auth-tokenSupabase session authentication. Keeps you signed in securely.SessionEssential
sb-*-refresh-tokenSupabase session refresh. Automatically renews your session without requiring re-login.SessionEssential

Cookie Security

  • Authentication: Session handling is provided by Supabase. Server-side identity checks validate the user; cookie contents alone are not trusted for authorization.
  • Secure: In production, cookies are only sent over HTTPS connections.
  • SameSite=Lax: Cookies are not sent with cross-origin requests, preventing most cross-site request forgery (CSRF) attacks.

Optional First-Party Analytics

With your permission, we count page views on a small allowlist of public and adult staff pages. Counts are grouped by day, page category, browser family, device category and approximate country where our trusted hosting proxy supplies it. Staff-page counts can be grouped by school. They are page views, not unique people.

We do not collect GPS, student or parent portal analytics, persistent visitor IDs, URL parameters, or raw IP addresses or user-agent strings in these counters. An IP-derived daily rate-limit key is used only to limit abuse. Browser Do Not Track and Global Privacy Control signals disable optional analytics.

The preference key sajama.analytics.v1 stores only “granted” or “denied” in your browser until you change it or clear local storage. Counters are retained for up to 90 days under our scheduled cleanup policy. Withdrawing consent stops new analytics; aggregate counts do not identify you for individual deletion.

Third-Party Cookies

We use Paystack for payment processing. When you make a payment, Paystack may set its own cookies on their checkout page. We do not control these cookies. Please refer to Paystack's Privacy Policy for details.

Managing Cookies

Most browsers allow you to block or delete cookies. However, blocking essential cookies will prevent you from signing in and using the platform. To manage cookies, check your browser's settings under "Privacy" or "Cookies."

Contact

Questions about our use of cookies? Email privacy@sajamacampus.com.