Cookie Policy
Last updated: 2026-05-10
This Cookie Policy explains how SoloRiff ("SoloRiff", "we", "our") uses cookies and similar storage technologies on our marketing site, dashboard ("Studio") and Customer-embedded widgets. It supplements our Privacy Policy and the Data Processing Addendum.
1. What is a cookie?
A cookie is a small text file placed on your device by a website. We also use closely related technologies — local storage, session storage, IndexedDB and pixel tags — collectively referred to as "cookies" in this policy. Cookies can be set by the website you are visiting ("first-party") or by another domain it loads ("third-party").
2. Categories
We classify cookies in four categories aligned with the EU GDPR / e-Privacy Directive and the UK PECR framework, and disclosed under the CCPA/CPRA where applicable:
- Strictly necessary — required for the Service to function (authentication, CSRF, fraud prevention). No consent required under the e-Privacy Directive Art. 5(3) exemption.
- Functional — remember preferences such as theme or sidebar state. Set with consent or legitimate interest depending on jurisdiction.
- Analytics — help us understand how Customers use Studio. Set only with consent.
- Marketing / advertising — we do not use these on the marketing site or Studio.
3. Cookies we use on the SoloRiff marketing site & Studio
| Name | Category | Purpose | Duration | Provider |
|---|---|---|---|---|
laravel_session | Strictly necessary | Maintains the authenticated Studio session. | Session | SoloRiff (first-party) |
XSRF-TOKEN | Strictly necessary | CSRF protection on form submissions. | 2 hours | SoloRiff (first-party) |
soloriff.token (localStorage) | Strictly necessary | Bearer token for API requests from Studio. | Until logout | SoloRiff (first-party) |
soloriff.theme (localStorage) | Functional | Light / dark theme preference. | Persistent until cleared | SoloRiff (first-party) |
soloriff.cookies-consent (localStorage) | Functional | Records your cookie-banner choice. | 12 months | SoloRiff (first-party) |
4. Cookies set by Customer-embedded widgets
When SoloRiff is embedded on a Customer's website, the widget may set the following cookies on that Customer's domain in order to operate. The Customer is the controller for these cookies and is responsible for surfacing them in their own cookie notice.
| Name | Category | Purpose | Duration |
|---|---|---|---|
soloriff_visitor_id | Functional / strictly necessary depending on configuration | Anonymous visitor identifier so a returning visitor can resume an in-progress conversation. | Up to 12 months |
soloriff_session | Strictly necessary | Short-lived session token for the active conversation. | Session |
5. Third-party cookies
Our marketing site does not embed third-party advertising or social-network cookies. The only third-party request occurs at checkout and inside billing pages, when our payment processor is loaded. We do not use Google Analytics, Meta Pixel, LinkedIn Insight Tag or similar ad-tech tags on the marketing site.
6. Managing your choices
EU / UK
Where your jurisdiction requires consent for non-essential cookies (EU Member States under the e-Privacy Directive, UK PECR and equivalent), we present a cookie banner on first visit. You can withdraw consent at any time by clearing the soloriff.cookies-consent entry in your browser, or by following the "Manage cookies" link in the footer.
California / other US states
California Consumer Privacy Act (CCPA) as amended by the CPRA, and equivalent laws in Colorado, Connecticut, Virginia, Utah, Texas, Oregon and Montana, give residents the right to opt out of "sale" or "sharing" of personal information. SoloRiff does not sell or share personal information for cross-context behavioural advertising. We respect Global Privacy Control (GPC) signals where applicable.
All visitors
You can clear or block cookies through your browser settings. Blocking strictly-necessary cookies will prevent Studio from working. End Users on Customer sites should follow that Customer's cookie-banner controls.
7. "Do Not Track" and Global Privacy Control
Many browsers offer a "Do Not Track" header. There is no industry-wide standard for how to respond to it. SoloRiff does not engage in tracking that would be affected by DNT in the first place. Where the Global Privacy Control (GPC) signal is sent and applicable under California law, we treat it as an opt-out request for sale/sharing.
8. Changes
We will update this Policy when we add or remove a cookie. Material changes will be communicated by in-product notice. The "Last updated" date at the top of the page reflects the current effective date.
9. Contact
Questions: [email protected] with the subject prefix [cookies].
Have a question about this document? Email [email protected].
See also: Terms of Service, Privacy Policy, Data Processing Addendum.