Cookie Policy
In this document
Introduction
SorviAI uses very few cookies, and all of them are needed to make the product work. We set no advertising, analytics or tracking cookies, and we let no third party track you across other websites through our product.
Most of what we store in your browser is not a cookie at all. It is local storage, which we use to keep you signed in and to remember small preferences such as your dark mode setting and whether you prefer a list or a grid. That information stays on your device and is never sent to an advertising network.
Because everything we set is strictly necessary or a preference you chose yourself, we do not show a consent banner. The section on managing cookies and storage explains how to clear or block this storage if you want to.
About this policy
This policy explains how SorviAI uses cookies and similar technologies on our platform and on our public website. It sits alongside our Privacy Policy, which explains what we do with personal information more generally. Where this policy uses terms such as controller and processor, they carry the meaning given in the Privacy Policy.
It covers the SorviAI platform and every application within it, together with our public website. The section on storefronts run by our customers explains the one important thing it does not cover.
What cookies and similar technologies are
A cookie is a small text file that a website asks your browser to store and sends back on later visits. Cookies are how a website recognises that two requests came from the same person, which is what keeps you signed in as you move between pages.
Similar technologies do the same job in a different way. The two we use are:
- Local storage. A larger, longer-lived store in your browser. Unlike a cookie, it is not automatically attached to every request we make, so it never travels to a third party by accident. We use it for most of what SorviAI needs to remember.
- Session storage. The same idea, but cleared as soon as you close the tab. We use it for short-lived steps such as completing a sign-in redirect.
Throughout this policy we use “storage” to mean all three, and we say specifically which one applies in the tables below.
The categories, and which ones we use
The industry generally recognises four categories. SorviAI uses the first two only.
| Category | What it is for | Do we use it |
|---|---|---|
| Strictly necessary | Signing you in, keeping your session alive, routing you to the right workspace, protecting against request forgery | Yes. The product cannot work without these |
| Preferences | Remembering choices you made yourself, such as dark mode or a list-versus-grid view | Yes. Set only after you make the choice |
| Analytics | Measuring how many people visit and which features they use | No |
| Advertising and tracking | Building a profile of you to target adverts, on our site or elsewhere | No, and we have no plans to |
Cookies we set
These are true cookies, sent with requests to our servers. This is the complete list.
| Name | Purpose | Category | Expires |
|---|---|---|---|
sessionid | Keeps you signed in to our administrative interfaces. Contains a random identifier only, never your details. | Necessary | One hour, and in any case when you close your browser |
csrftoken | Protects against cross-site request forgery, which is an attack where another site tries to make your browser perform an action in SorviAI without your knowledge. | Necessary | One year |
sf_cart_token | Set only on storefront sites. Identifies your basket so its contents survive a page reload or a return visit. Contains a random token, not your details. | Necessary | 30 days |
blog_feedback / help_feedback | Set only if you answer “Was this helpful?” on a blog article or a help guide, so we do not ask you the same question twice. Records which articles this browser has answered and nothing about you: no account, no name, no address. | Necessary | One year |
All of these are first-party cookies, meaning they are set by the SorviAI domain you are visiting and are not readable by any other website.
Our public marketing website sets no cookies except the feedback cookie above, and only after you choose to answer.
Browser storage we use
This is where most of SorviAI’s browser storage lives. It stays on your device and is read by the application running in your browser. We describe it here, even though it is not technically a cookie, because you have a right to know what is being kept.
Necessary storage
These keep you signed in and get you to the right place. Without them the product cannot function.
| Key | Purpose | Cleared |
|---|---|---|
access_token, auth, auth_tokens, auth_user | Holds your signed-in session and basic profile so you are not asked to sign in on every page. Access tokens expire after 60 minutes and are renewed automatically while you are active. | When you sign out, or when you clear site data |
portal_auth | The same, for customers and suppliers signing in to a Portal rather than the main platform. | When you sign out |
lastTenant | Remembers which workspace you last used, so we can send you to the right one instead of asking every time. | When you clear site data |
hmrc_oauth_pending, outlook_oauth_result, ups_oauth_result, stripe_oauth_result | Temporary markers used while you are being handed back from an external service such as HMRC, Microsoft, UPS or Stripe after authorising a connection. | Immediately after the connection completes |
Preference storage
These remember choices you made in the interface. Nothing here is written until you make the choice, none of it leaves your device, and losing all of it costs you nothing but your layout settings. We describe it by category rather than as a fixed list of keys, because a key is added each time a screen gains a preference, and a list of names would be out of date the week after we published it.
| What it remembers | Keys look like | Cleared |
|---|---|---|
| Your light or dark theme choice | theme | When you clear site data |
| Whether you last chose a table or a card view on a list screen, for invoices, quotes, customers, items, shipments and so on | sorvi-<screen>-view-mode, nest-view-mode | When you clear site data |
| Which columns you chose to show or hide on a list screen | column-visibility-<screen> | When you clear site data |
| The applications you pinned in the launcher, and the ones you opened most recently | sorvi-favorite-apps, and per-application launcher keys | When you clear site data |
| That you ticked “do not show this again” on a confirmation dialog, so we stop showing it | dontShowRecordPaymentConfirmation, dontShowCreditNoteConfirmation | When you clear site data |
| Layout state in TeamEmail and Nest, such as which sidebar sections you left open and how densely you prefer messages listed | teamemail_*, outlook_email_density | When you clear site data |
| Which settings tab you had open, and the screen to return you to when you leave settings | settings-tab-*, *-return-path, lastNonSettingsPage | When you clear site data |
| Work in progress on a screen you have not finished, such as a held POS sale or a repair ticket draft, so that a reload does not lose it | pos_*, sorvi_repair_tickets | When the work is completed or discarded, or when you clear site data |
One identifier that deserves a specific mention
If your organisation uses our HMRC tax filing feature, we generate a random device identifier and store it as hmrc_device_id. HMRC requires software submitting VAT returns to send information identifying the device the submission came from, as part of their fraud prevention rules. The identifier is random, is not used for any other purpose, and is not shared with anyone except HMRC as part of a submission you initiate.
Third parties
We do not allow third parties to set cookies or place trackers in SorviAI. Two suppliers are worth naming because they receive some technical information without using cookies to do so.
- Sentry collects error reports when something in the product goes wrong. A report contains technical details of the failure, which may include the page you were on and the account making the request. Sentry does not set cookies in your browser and is not used to track you. We explicitly block error reports originating from browser extensions and unrelated third-party scripts so that they are never sent.
- Microsoft handles sign-in when your organisation connects a Microsoft 365 mailbox. That sign-in happens on Microsoft’s own pages, under Microsoft’s cookie policy, before you are returned to SorviAI.
- YouTube supplies the videos in our help guides, through its youtube-nocookie.com player. Nothing loads from Google when you open a guide: the page shows only a preview image served by us, and the player is fetched only after you choose to press play. That press is the consent, which is why no banner precedes it.
Beyond that, our public website embeds no third-party advertising, social media or analytics scripts, and no other third-party video, chat or webinar embeds. If we ever add one, we will list it here and add a consent banner before it loads.
What we do not do
Stated plainly, so there is no ambiguity.
- We do not use cookies or storage to serve you adverts, in SorviAI or anywhere else.
- We do not sell or share browser storage data with data brokers or advertising networks.
- We do not track you across other websites, and we do not embed anything that would let a third party do so.
- We do not use fingerprinting to identify your device beyond the single HMRC identifier described under browser storage we use, which exists because a tax authority requires it.
- We do not read the contents of your workspace through browser storage. Your business records live on our servers, not in your browser.
Storefronts run by our customers
Businesses can use SorviAI to publish their own online store on their own web address. If you are shopping on one of those sites, the business running it decides what cookies that site uses, and its own cookie policy applies rather than this one.
The basket cookie described under the cookies we set is the one piece of storage that comes from our platform on those sites, and it exists purely to keep the basket working. Anything beyond that, including any analytics or advertising the store owner chooses to add, is their decision and their responsibility to disclose.
Managing cookies and storage
You are in control of what your browser keeps. There are three levels.
- Clear your preferences without signing out. Most of the preference storage listed under browser storage we use can be reset simply by changing the setting again in the interface, for example switching the theme back or choosing a different view.
- Clear everything for SorviAI. Every modern browser lets you delete cookies and site data for a single website. Doing this signs you out and resets your preferences to their defaults. Nothing in your workspace is affected, because your business records are stored on our servers.
- Block storage entirely. You can configure your browser to refuse cookies and site storage. Be aware that this will prevent you from signing in to SorviAI at all, because there would be nowhere to keep your session.
The relevant settings live under Privacy in Chrome, Edge and Brave, under Privacy and Security in Firefox, and under Settings then Privacy in Safari. Your browser’s own help pages give current step-by-step instructions, and they stay accurate for longer than any instructions we could write here:
Do Not Track and Global Privacy Control
Some browsers and extensions can send a Do Not Track or Global Privacy Control signal asking sites not to track you, or not to sell or share your information. Several United States state privacy laws recognise Global Privacy Control as a valid opt-out signal, and require businesses that sell or share personal information to honour it.
We do not need to act on these signals in any special way, because we do not track you, and we do not sell or share your information for advertising. There is no behaviour for the signal to switch off. We treat a signal as an instruction we already comply with by default, everywhere, for everyone.
If we ever introduce analytics or any form of advertising, we will honour these signals and say so here.
Where you are, and which law applies
SorviAI is used by businesses in the United Kingdom, the European Economic Area, India and the United States, and the rules on browser storage are written differently in each. The practical answer is the same everywhere, because it follows from what we do rather than from where you are: we set nothing that requires your consent, because we run no analytics and no advertising.
What changes by region is the legal reasoning behind that, and who you can complain to if you disagree with it.
| Where you are | What applies | What it means here | Who you can complain to |
|---|---|---|---|
| United Kingdom | The Privacy and Electronic Communications Regulations 2003, and UK GDPR | Consent is needed for storage that is not strictly necessary for a service you asked for. Everything in the first of the categories above is exempt, and the second is set only on your instruction. | Information Commissioner’s Office, ico.org.uk |
| European Economic Area | The ePrivacy Directive as implemented in your country, and the GDPR | The same exemption, in the provision the UK rules were derived from. Storage strictly necessary to provide a service you explicitly requested does not require consent. | The data protection authority in your own country |
| India | The Digital Personal Data Protection Act 2023 and the rules made under it | There is no cookie-specific rule. Storage needed to deliver the account you signed up for is covered by the notice and consent given when your workspace was created, and we ask for nothing beyond it. | Data Protection Board of India |
| United States | No federal cookie law. State privacy laws, including California’s, regulate the sale and sharing of personal information for targeted advertising | We do not sell or share your personal information, and we do not use it for targeted advertising, so there is nothing for you to opt out of. We honour Global Privacy Control regardless, as the section on Do Not Track and Global Privacy Control explains. | California residents: the California Privacy Protection Agency or the state Attorney General. Elsewhere: your state Attorney General |
Nothing in this section limits rights you have under your own local law. If a law that applies to you gives you more than this policy describes, that law wins.
Changes to this policy
We update this policy whenever the storage we use changes. The effective date and version at the top tell you which version you are reading.
If we ever add storage that is not strictly necessary or a preference you chose, we will ask for your consent before setting it, and we will update this policy first. Routine corrections take effect when published. Previous versions remain available at [ARCHIVE URL].
How to contact us
If you have a question about anything in this policy, or you think we have set something we have not disclosed, please tell us. We would rather hear about it than not. One address reaches us wherever you are, and we answer in English.
Data protection contact
Regional contacts
Some of the regional laws set out above require a named contact inside the region. Where one is required of us, it is listed here.
The section on where you are, and which law applies lists the regulator you can complain to in each region if you are not satisfied with our answer. We would rather you came to us first, but nothing here requires you to.
Key terms
The words in this policy that carry a specific meaning, in plain language.
Cookie
A small text file that a website asks your browser to store, and which your browser sends back on later visits to the same site. It is how a website recognises that two separate requests came from the same person. A cookie can hold only a small amount of text, and ours hold a random identifier rather than anything about you.
Local storage
A larger, longer-lived store built into your browser. Unlike a cookie it is not attached automatically to every request, so it cannot travel to a third party by accident. It stays on your device until you clear it, and only the site that wrote it can read it.
Session storage
The same idea as local storage, except the browser empties it the moment you close the tab. We use it only for short-lived steps such as completing a sign-in redirect.
First-party cookie
A cookie set by the website you are actually visiting, rather than by an advertiser or another company embedded in the page. Every cookie we set is first-party. A third-party cookie is the kind used to follow you between unrelated websites, and we set none.
Strictly necessary
Storage without which a service you actively asked for cannot work. Keeping you signed in is the clearest example: remove it and every page load looks like a brand new visitor. UK law exempts this category from the requirement to ask for consent, which is why signing in does not produce a banner.
Preference storage
A record of a choice you made yourself in the interface, such as dark mode or a card-versus-table view. It is written only as a direct result of that choice, never on first load, and it exists so the product behaves the way you left it.
Fingerprinting
Identifying a device by combining signals it gives off, such as screen size, installed fonts and time zone, rather than by storing anything on it. It is used to recognise people who have cleared their cookies. We do not do it. The one device identifier we hold is the HMRC one described under browser storage we use, which is a random value we generate and store openly, not a fingerprint we derive from you.
Controller and processor
Two roles defined by data protection law. The controller decides why and how personal information is used. The processor only handles it on the controller’s instructions. SorviAI is the controller for your account with us, and the processor for the business records our customers keep in their own workspaces. Our Privacy Policy explains which applies to you.
Consent banner
The dialogue many sites show asking you to accept cookies. It is required only when a site sets storage that is not strictly necessary, typically analytics or advertising. We set neither, so there is nothing to ask you about. If that ever changes, the banner arrives before the storage does, not after.
Global Privacy Control
A signal your browser or a browser extension can send automatically to every site you visit, saying that you do not want your personal information sold or shared. Several United States state privacy laws treat it as a legally valid opt-out, which a business that sells or shares data has to honour.
It is the successor to Do Not Track, which sites were free to ignore. We do not sell or share your information in the first place, so the signal asks us for something we already do.
PECR and the ePrivacy Directive
The rules that specifically govern storing things on your device in the United Kingdom and the European Economic Area. The UK’s version is the Privacy and Electronic Communications Regulations 2003; the EU’s is the ePrivacy Directive, implemented separately by each country. Both require consent before a site stores anything on your device, unless the storage is strictly necessary to provide a service you explicitly asked for.
They sit alongside the UK GDPR and the GDPR rather than replacing them, and they are the reason cookie banners exist in Europe and not elsewhere.
India's DPDP Act
The Digital Personal Data Protection Act 2023, India’s general data protection law, together with the rules made under it. Unlike the European rules it contains no cookie-specific provision, so browser storage is treated like any other processing of personal data: it needs notice and a lawful basis, which for a workspace you signed up for is the consent given at that point.
Complaints go to the Data Protection Board of India.
Sale and sharing (United States)
Terms with a specific and broad meaning under California’s privacy law and several other state laws. “Sale” covers disclosing personal information for money or other value, not only a cash transaction. “Sharing” covers passing it to another business for cross-context behavioural advertising, which is advertising based on your activity across unrelated sites.
Both are broad enough to catch things a normal reader would not call selling data, which is why we state plainly that we do neither. It is also why we carry no “Do Not Sell or Share My Personal Information” link: there is nothing for it to switch off.