This notice explains the cookies and similar technologies (local storage, pixels) used on rockface.biz and our application at app.rockface.biz. It is provided in addition to our Privacy Notice and is written to satisfy UK PECR and the EU ePrivacy Directive.
1. Categories of cookies we use
| Category | Purpose | Consent required? | Retention |
|---|---|---|---|
| Strictly necessary | Auth session, CSRF protection, load balancing, region routing | No — exempt under PECR | Session — 30 days |
| Functional | Remembering UI preferences (theme, sidebar state, table density) | No — first-party, no tracking | 12 months |
| Analytics (first-party, aggregated) | Anonymous page-view counts, error monitoring on our marketing site | Yes (consent banner) | 13 months |
| Marketing / advertising | We do not set advertising cookies. We do not run retargeting pixels. | N/A | N/A |
2. Specific cookies we set
| Name | Purpose | Type | Expires |
|---|---|---|---|
| tf_session | Authenticated session | Strictly necessary | 30 days (httpOnly, Secure, SameSite=Lax) |
| tf_csrf | CSRF protection | Strictly necessary | Session |
| tf_region | Routes you to your data-residency region | Strictly necessary | 12 months |
| tf_prefs | UI preferences (theme, sidebar) | Functional | 12 months |
| tf_consent | Stores your cookie-consent choices | Strictly necessary | 12 months |
| tf_analytics_id | Anonymous, rotating analytics ID (only set with consent) | Analytics | 13 months |
3. How to control cookies
- Use the cookie banner on first visit, or revisit /legal/cookies and click 'Cookie preferences' below to change your choices at any time.
- All major browsers let you block or delete cookies — note that blocking strictly-necessary cookies will break sign-in.
- We honour Global Privacy Control (GPC) and Do Not Track signals as a withdrawal of consent for analytics cookies.
4. Third parties
We do not embed third-party advertising tags. Our marketing analytics is a self-hosted, first-party setup. For a complete list of sub-processors that may process personal data, see /legal/subprocessors.
5. Changes
We will update this notice if we add or remove cookies. Material changes are surfaced via the cookie banner on your next visit.
Contact us
Data Protection Officer · Rockface Limited Email: rockface@rockface.biz Postal: Suite RA01, 195-197 Wood Street, London, E17 3NU, United Kingdom For UK/EEA residents, you also have the right to lodge a complaint with the UK ICO (ico.org.uk) or your local supervisory authority.
This page is a plain-English summary. If anything here conflicts with your signed agreement (MSA, DPA, or order form), the signed agreement controls.