Legal document
Cookie Policy
SaveAtCost currently uses essential authentication cookies and limited preference storage. It does not run advertising or product-analytics cookies.
Last updated:
1. Overview
Cookies are small values a website stores or reads through a browser. Similar technologies include session storage and extension storage. This Policy describes the technologies used by the implemented SaveAtCost website and browser extension.
2. Technologies in use
| Category and technology | Purpose | Typical duration |
|---|---|---|
| Essential — access_token / __Host-access_token | HTTP-only cookie authenticating a signed-in browser session. | Up to 15 minutes; refreshed when an eligible session continues. |
| Essential — refresh_token / __Host-refresh_token | HTTP-only rotating session cookie used to obtain a new short-lived access token. | Configured for 14 days by default and capped at 30 days. |
| Preference — receipts_mobileFiltersOpen | Session-storage value remembering whether receipt filters were open in the current browser session. | Until the browser tab/session storage is cleared. |
| Essential security — Cloudflare Turnstile | Bot and abuse checks on sign-in, sign-up, and account-recovery flows. | Controlled by Cloudflare and limited to the authentication interaction. |
| Payment security — Stripe | Stripe may set necessary fraud-prevention, checkout, and portal technologies on Stripe-hosted pages. | Controlled by Stripe under its own policy. |
| Extension storage | Stores SaveAtCost connection tokens, pending device authorization, and short-lived cached receipt-import data inside the extension. | Until expiry, sign-out, cache cleanup, extension removal, or browser-data clearing. |
3. Technologies not currently used
The implemented site does not load advertising cookies, affiliate cookies, social-media pixels, or another nonessential product-analytics script. Google Fonts is requested to display the interface typeface, but SaveAtCost does not use that request for site analytics.
4. Why there is no consent banner
Because the implemented website uses only essential account/security technologies plus a limited interface preference, it does not display an intrusive cookie-consent banner. Essential cookies cannot be disabled through a preference center because the signed-in Service would not function securely without them. If nonessential tracking is introduced, it must remain blocked until the required consent is obtained and a preference control is provided.
5. Your controls
You can block or delete cookies and storage through browser settings and can clear extension storage by signing out, clearing extension data, or removing the extension. Blocking authentication cookies prevents signed-in dashboard use. Closing a tab or clearing session storage resets the receipt-filter display preference.
6. Changes and contact
We will update this Policy before materially changing tracking practices and will add consent controls when required. Questions may be sent to support@saveatcost.co.
Questions about this document?
Email support@saveatcost.co. Do not include a password, full payment-card number, or retailer-session token.