This is a starting draft. Have it reviewed before you rely on it.
What we set
FaithOps sets only what it needs to work:
- a session cookie, so you stay signed in between pages
- a CSRF token, which stops another site submitting forms as you
- a locale preference, where you have chosen a language
These are strictly necessary, so they are set without asking. There is no advertising or cross-site tracking, and we run no third-party analytics that follows you between sites.
Turning them off
Your browser can refuse them. Signing in will then not work, because staying signed in is what the session cookie is for.
Embedded services
A congregation may embed a video player or a support widget on its own pages, and those providers may set their own cookies. Where they do, it is the congregation's choice and its own notice applies.