SSO LEGAL

Cookie Policy

This Cookie Policy explains how SSO websites and digital services may use cookies, local storage, analytics tools, and similar technologies.

Effective: July 27, 2026Last updated: July 27, 2026

Preference notice

Blocking strictly necessary technologies may prevent login, security, forms, preferences, or core page functions from working. Nonessential technologies are subject to available consent and preference controls where required.

1. Overview

Cookies are small data files stored by a browser. Similar technologies include local storage, session storage, pixels, tags, software development kits, and server logs. They can recognize a browser or device, retain settings, support security, and provide information about use.

This Policy supplements the SSO Privacy Policy. Specific SSO products or embedded third-party services may provide additional notices.

2. Technologies covered

  • First-party cookies set by an SSO-controlled domain.
  • Third-party cookies or tags set by an integrated service provider.
  • Local and session storage used to preserve settings, authentication state, or application data.
  • Pixels, tags, and event signals used to measure page delivery or interactions.
  • Server, application, security, and API logs generated when a request reaches SSO systems.

3. Cookie categories

CategoryPurposeTypical status
Strictly necessaryPage delivery, routing, authentication, account security, fraud prevention, load balancing, consent records, and core functionality.Required for the requested service; generally cannot be disabled through a site preference tool.
FunctionalRemember language, accessibility, interface, organization, display, or workflow preferences.May be optional depending on the function and jurisdiction.
Analytics and performanceUnderstand traffic, errors, feature use, page performance, and service reliability using aggregated or pseudonymous measurements where feasible.Used with consent where required.
Communications and attributionMeasure whether a communication, campaign, referral, or business outreach resulted in a visit or requested action.Used with consent or another lawful basis where permitted.
Advertising or cross-site measurementSupport advertising, audience measurement, or cross-context activity if such features are implemented.Not used without required notice and choice mechanisms.

4. Purposes

  • Maintain sessions and route requests.
  • Authenticate users and enforce role-based access.
  • Detect abuse, fraud, unusual activity, and security incidents.
  • Remember consent and interface preferences.
  • Diagnose errors and improve availability, speed, and compatibility.
  • Understand which pages and features are useful.
  • Measure business communications and referrals where permitted.

5. Third-party technologies

Pages may include services supplied by hosting, security, analytics, media, form, payment, communications, or other vendors. Those providers may receive technical information necessary to deliver their services and may set their own technologies when integrated.

Third-party technologies are also governed by the provider's privacy documentation. SSO seeks to configure integrations consistently with applicable consent and contractual requirements, but does not control independent third-party websites reached through links.

6. Session and persistent storage

Session technologies generally expire when the browser or session ends. Persistent technologies remain for a defined period or until deleted. Duration depends on purpose, security needs, provider configuration, consent status, and technical requirements.

Security, audit, and server logs may be retained separately from browser cookies according to SSO's retention practices and legal obligations.

7. Your choices

  • Use an available cookie or privacy preference control on the relevant site.
  • Change browser settings to block, delete, or limit cookies and site storage.
  • Use device or browser controls that limit tracking or reset advertising identifiers.
  • Disable optional analytics or communications preferences where an account setting is available.
  • Avoid using account features if you do not wish to allow technologies required for authentication and security.

Browser controls vary. Deleting cookies may also delete saved preferences and require you to make choices again.

8. Browser privacy signals

Some browsers transmit signals such as Do Not Track or Global Privacy Control. Legal recognition and technical standards vary by jurisdiction and service.

Where applicable law requires SSO to treat a recognized signal as an opt-out request, SSO will do so for the browser or device from which the signal is received, subject to verification and technical feasibility. A signal may not apply to authenticated account-level processing unless the law requires it.

9. Updates to this Policy

SSO may update this Policy as technologies, providers, services, and legal requirements change. The current version is identified by the updated date at the top of the page.

10. Contact

Questions about cookies or site-level privacy controls may be submitted through the contact portal. Identify the domain, page, browser, and technology involved when possible.