Sakenora logo
Legal

Cookie Policy

Last updated 28 July 2026

1. What this policy covers

The cookies used by the Sakenora platform at https://sakenora.com, including the management application and the resident portal.

We keep this short because we use very few cookies.

2. What we do NOT use

Being clear about this matters more than the list of what we do use:

  • No advertising cookies. None. We do not advertise on the platform.
  • No third-party tracking or behavioural profiling cookies.
  • No social media pixels or share-button trackers.
  • No cross-site tracking of any kind.
  • We do not use cookies to build profiles of you or to sell data to anyone.

If a future version introduces analytics or any non-essential cookie, we will update this policy and, where the law requires it, ask for your consent before setting it.

3. The cookies we use

All are strictly necessary — the platform cannot work without them. Strictly necessary cookies do not require prior consent, because you cannot use a login-based service without them.

Cookie Type What it does How long it lasts
sakenora-session Session, strictly necessary Holds a random session identifier so the platform knows who you are between pages. The identifier is meaningless on its own — your session data is stored on our server, not in the cookie. The cookie is encrypted and signed. Expires after 120 minutes of inactivity, or when you close your browser depending on your settings. Deleted on logout.
XSRF-TOKEN Security, strictly necessary Protects against cross-site request forgery — an attack where another site tries to make your browser act in Sakenora without your knowledge. Checked on every form submission. Same lifetime as the session cookie.
remember_web_* Persistent authentication, only if you choose it Set only if you tick "Remember me" at login. Keeps you signed in after your session expires. Contains a long random token, not your password. Up to 30 days, unless you log out. Logging out deletes it immediately.

The remember_web_* name includes a hash generated by the application framework, so it appears with a string of characters after remember_web_.

4. Security settings on our cookies

  • HttpOnly — the session and remember-me cookies cannot be read by JavaScript, limiting the damage a cross-site scripting attack could do.
  • Secure — only sent over HTTPS, so they cannot be read in transit.
  • SameSite — restricts cookies being sent on requests from other sites, reducing cross-site attack risk.
  • Encrypted — the session cookie's contents are encrypted and signed by the application.

5. The mobile app

The mobile app does not use cookies.

When you log in, the app receives an access token stored in the app's own storage on your device. That token keeps you signed in and is sent with each request to prove who you are.

Logging out deletes the token from your device. If you lose your device, tell your landlord or contact support@sakenora.com so the session can be ended.

6. Managing cookies

You can control cookies through your browser settings — every major browser lets you view, delete and block them.

Please note: if you block or delete our cookies, you will not be able to log in or stay logged in. They are not optional extras; they are how the login works.

To end your session properly use the Log out button. That is more reliable than deleting cookies manually, because it also invalidates the session on our server.

7. Local storage

The web application may use your browser's local storage for small interface preferences, such as whether a menu is collapsed. This is not tracking, it does not leave your device, and it contains no personal data.

8. Changes to this policy

We will update this policy if the cookies we use change. The date at the top will change.

9. Contact

Questions: support@sakenora.com or support@sakenora.com.