Last updated: July 2026
Applies to: www.my-roost.com.au and related web pages, and the Roost mobile app where equivalent technologies are used.
Cookies are small text files placed on your device by a website or app. Similar technologies include local storage, session storage, pixels, tags, SDKs, device identifiers, push notification tokens, and crash reporting agents. In the Roost app, we use some of these equivalent technologies for login, analytics, crash reporting, push notifications, and feature delivery — the principles and controls described in this policy apply to both the website and the app.
For how personal information collected through these technologies is handled, used, disclosed, and protected — including overseas processing — please refer to our Privacy Policy.
We group the technologies we use into five categories. The table in Section 3 maps each provider to one of these categories.
We do not currently use marketing or advertising cookies. If we introduce any in future — for example, to measure campaign performance — we will update this policy, display a clear consent request before enabling them, and not use them until consent has been given.
The table below lists the specific providers whose technologies are currently in use across the website and app. This list may change as the product evolves; we will update this table when providers are added or removed.
| Provider | Technology type | Category | Purpose | Approx. retention | Privacy information |
|---|---|---|---|---|---|
| Roost (first-party) | Session cookie, local storage | Strictly necessary | Login session management, authentication tokens, security controls, CSRF protection | Session / up to 30 days | This policy and our Privacy Policy |
| PostHog | JavaScript SDK, cookie, local storage | Analytics | Product analytics — feature usage, flow performance, activation funnel tracking, session events. Events may be tied to a pseudonymous user identifier for logged-in users. | Up to 12 months | posthog.com/privacy |
| Sentry | JavaScript / mobile SDK | Diagnostics | Crash reporting, error tracking, and performance monitoring for the website and app. May capture a device identifier, session ID, and limited context around the error event. | Up to 90 days | sentry.io/privacy |
| Crisp | JavaScript widget, cookie | Communications | In-app support chat and support ticket management. May set a visitor identifier to maintain chat continuity across sessions. | Up to 12 months | crisp.chat/en/privacy |
| OneSignal | Mobile SDK, push notification token | Communications | Push notification delivery for the Roost app — inspection reminders, signing requests, inbox messages, and service alerts. Operates on a device token, not a persistent cookie. | Until notification permission revoked | onesignal.com/privacy_policy |
| Stripe | JavaScript SDK, cookie | Strictly necessary | Payment processing and fraud prevention on checkout pages. Stripe may set cookies for security, session continuity, and fraud detection during the payment flow. | Session / up to 12 months | stripe.com/privacy |
| Google Cloud | Server-side infrastructure | Strictly necessary | Hosting, storage, database, and content delivery infrastructure. Google Cloud does not set client-side cookies on our behalf; any data handling is server-side and described in the Privacy Policy. | Varies — see Privacy Policy | cloud.google.com/privacy |
Provider changes. The provider list above reflects our current setup and will be updated when providers are added or removed. Third-party providers may process information under their own terms and privacy policies, which we encourage you to review. For a complete picture of how personal information is handled — including cross-border data flows — see our Privacy Policy.
Because Roost is primarily a mobile app, most user interaction happens outside a browser. In the app, we use SDK-based equivalents of cookies rather than traditional browser cookies. These may include:
When you visit the Roost website, a cookie preference banner allows you to accept, reject, or manage non-essential cookies before they are set. Strictly necessary cookies — including session management, security controls, and payment fraud prevention — are set without consent because they are essential to operate the site.
You can change your cookie preferences at any time using the cookie settings link in the website footer. Withdrawing consent for non-essential cookies will stop those technologies from running but may mean some features work differently or less completely.
Where you are logged in to Roost on the website, certain analytics events may be associated with your account to help us understand how features are used. This is described in the Privacy Policy.
You can control, block, or delete cookies through your browser settings. Most browsers allow you to see which cookies are set, block third-party cookies, or delete all cookies when you close the browser. Blocking strictly necessary cookies may prevent login or other key functions from working. Common browser settings pages:
Session cookies expire when you close your browser. Persistent cookies remain on your device for a set period or until you delete them. Approximate retention periods for each provider are shown in the table in Section 3. Push notification tokens persist until you revoke notification permission on your device. Server-side logs and identifiers are subject to the retention periods described in our Privacy Policy.
We may update this Cookie Policy to reflect changes to our product, provider stack, or applicable law. When we add new providers or change how non-essential cookies are used, we will update the provider table in Section 3 and revise the "Last updated" date. The latest version will be posted on this page. If we introduce marketing or advertising cookies for the first time, we will request fresh consent before enabling them.
If you have questions about cookies, tracking, or your privacy preferences, contact us at support@my-roost.com. For broader privacy questions, see our Privacy Policy.