1. Scope
This policy explains how Rowsh uses cookies, local storage, session storage, and similar technologies on its public website and SaaS application. It should be read with the Privacy Notice.
2. Essential storage and access
Rowsh uses essential technologies to authenticate sessions, refresh authorised access, protect requests, maintain signup and checkout state, route users to the correct workspace, remember privacy choices, and provide features requested by a user. These technologies are necessary for the requested service or its security and cannot be disabled through Rowsh without breaking the relevant feature. Browser settings can still block them.
rowsh_*_access: workspace scoped or platform scoped access state. It is a browser session cookie when "Keep me signed in" is off and may remain for up to 365 days when that option is on; the underlying access credential is short lived and refreshed.rowsh_*_refresh: HTTP only refresh session state. It is a browser session cookie when "Keep me signed in" is off and may rotate and remain for up to 365 days when that option is on.rowsh_*_mfa_device: an HTTP only identifier for a trusted multi factor authentication device, retained for up to 30 days.rowsh.signup.pendingCheckout: local browser state that reconnects an unfinished Stripe or JazzCash signup to its result. It expires after 24 hours and is cleared sooner when the transaction finishes or fails.rowsh_privacy_preferences_v1: a browser cache of whether optional diagnostics are allowed. For a signed in workspace user, Rowsh also stores the current version of that choice against the user's workspace account so it can be restored on another browser or after local data is cleared. The choice is requested again when the cookie or diagnostics functionality changes and the consent version is updated.
3. Functional preferences
Rowsh stores choices such as language, theme, navigation order, dismissed notices, recent workspace state, view modes, editor recovery data, call or notification preferences, and other interface settings. Theme cookies (rowsh_theme_mode and its tenant scope values) remain for up to 365 days. Session storage values normally end with the browser tab or session. Other local preferences remain until replaced, removed through the relevant feature, sign out cleanup, or browser data clearing. They provide the behaviour requested by the user and are not used for advertising.
4. Optional diagnostics
When a Sentry compatible diagnostics endpoint is configured, Rowsh can send limited browser error, stack, environment, and sampled performance information to identify faults and improve reliability. Default personal data collection is disabled in the SDK configuration, but diagnostic events may still contain technical identifiers or data present in an error. Rowsh starts these optional browser diagnostics only after the user selects "Allow diagnostics". Selecting "Essential only" keeps them off.
Rowsh does not currently use advertising cookies or cross site behavioural tracking. If that changes, this policy and the choices interface must be updated before the technology is activated.
5. Third party services
Stripe or JazzCash checkout, bot protection when enabled, calls, media, embedded content, and customer enabled integrations may use their own technologies within the relevant flow. A provider acting on its own website applies its own notice and controls. Rowsh does not treat a customer's decision to enable an integration as consent for unrelated tracking.
6. Your choices
Use the button below to allow or reject optional diagnostics. Rejecting them does not block access to Rowsh. A changed choice takes effect immediately for new diagnostic collection; browser controls may also be used to delete locally stored Rowsh data. When this control is used from a signed in workspace, the account backed choice is updated as well.
7. Retention and browser controls
The periods above are maximum browser storage periods, not a promise that every value remains for that long. Credentials can expire, rotate, or be revoked sooner, and sign out removes Rowsh authentication state from the browser. Browser settings can block or delete storage, but doing so may sign the user out, reset preferences, or prevent a requested feature from working.
8. Changes and contact
Rowsh will update this policy when its actual browser storage practices materially change. Questions or objections can be sent through the Contact page.