Cookie Policy

Last updated: 1 July 2026  ·  Effective: 1 July 2026

1. What Are Cookies?

Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work correctly, to remember your preferences, and to provide security. Rafiki uses cookies to keep you securely signed in to your account.

2. Cookies We Use

Rafiki uses only essential, functional cookies. We do not use advertising, tracking, or analytics cookies from third parties.

Cookie NameTypePurposeExpiry
rafiki_auth_tokenEssentialStores your authentication token to keep you signed in. Readable by client-side JavaScript for API calls.Session (or 7 days with "remember me")
rafiki_auth_token_midEssentialHttpOnly mirror of the auth token for server-side route protection. Not accessible to JavaScript.Session (or 7 days)
rafiki_refresh_tokenEssentialHttpOnly long-lived token used to renew your session without requiring re-login. Never exposed to JavaScript.30 days
rafiki_userEssentialStores basic user profile information (name, role) to display in the dashboard without an extra API call.Session (or 7 days)

3. Why We Don't Use Third-Party Tracking Cookies

We do not embed Google Analytics, Facebook Pixel, advertising networks, or other third-party trackers on the Rafiki platform. Your business data and usage patterns are not shared with advertising platforms. The only third-party domains loaded by the platform are:

  • fonts.googleapis.com — Google Fonts (for Inter font). No cookies are set by this request.
  • fonts.gstatic.com — Font file delivery by Google.

4. How to Control Cookies

Because all cookies we use are strictly necessary for the Service to function, disabling them will prevent you from signing in or using the platform.

You can manage cookies through your browser settings:

  • Chrome: Settings → Privacy and Security → Cookies and other site data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data
  • Safari: Preferences → Privacy → Manage Website Data
  • Edge: Settings → Cookies and site permissions

To sign out and clear your Rafiki session cookies, use the "Sign Out" option in the platform dashboard.

5. Offline Progressive Web App (PWA)

Rafiki supports offline use through a browser Service Worker and local cache. When you install the Rafiki PWA, the browser stores certain assets and data locally for offline POS operation. This local storage is separate from cookies and is managed by your browser's storage API. You can clear this data through your browser's site settings.

6. Changes to This Policy

We will update this Cookie Policy if we change the cookies we use. Updates will be notified in the platform and by email at least 14 days in advance for material changes.

7. Contact

For questions about this Cookie Policy, email [email protected].