Cookie Policy
PointRoost sets one cookie. It keeps you signed in, and there is no advertising or third-party tracking cookie on this site.
Effective 16 September 2026
1. The cookie
| Name | What it does | Type | Lasts |
|---|---|---|---|
__session | Keeps you signed in between page loads, and lets the server know which pages are yours. | Strictly necessary | Until it expires or you sign out |
It is httpOnly, so page scripts cannot read it, and it is only set once you sign in. Browsing without an account sets no cookie at all.
2. Why there is no cookie banner
Consent is required for cookies that are not strictly necessary — analytics, advertising, tracking. PointRoost currently sets none of those, so there is nothing to ask you about, and a banner that appeared anyway would be theatre.
If that changes, a consent prompt will appear before any such cookie is set, and this page will be updated first.
3. Analytics
PointRoost is built to record product analytics — which features are used, how often — through Firebase Analytics. It is currently switched off in production and sends nothing.
When it is switched on it will collect usage events only. What those events may contain is limited by a fixed schema: no identity document contents, no exact prices, no Disney confirmation numbers. The detail is in the Privacy Policy.
4. Local storage
Some preferences — your theme choice, for example — are kept in your browser’s local storage rather than a cookie. That data never leaves your device and is not sent to any server. Clearing your browser data removes it.
5. Other companies’ cookies
Signing in with Apple or Google, and paying through Stripe, happens on their pages. Those companies set their own cookies under their own policies, which PointRoost does not control and cannot read.
6. Controlling cookies
Your browser can block or delete cookies. Blocking __session means sign-in will not persist — you would be signed out on every page load — but browsing and search keep working.