StarboardLog Cookie and Browser Storage Notice
Version 1.0 · Effective Date: 26 September 2026
Download PDFThis Notice describes the browser storage currently used for authenticated sessions, sign-in choice, Workspace and administrative UI state, notice acknowledgement and an optional application-install prompt. The Privacy Policy explains related personal-data processing.
1 Operator and scope
This Notice applies to the StarboardLog site and web application provided by Sándor Levente Szabó e.v., 9400 Sopron, Semmelweis utca 10., Hungary; individual entrepreneur registration number 61070435; Hungarian tax number 91404451-1-28; EU VAT number HU91404451. Contact: starboardlog@gmail.com. The Privacy Policy addresses related personal-data processing.
2 Storage technologies
Cookies, local storage and session storage can retain information on a user's device. Session storage typically ends when a tab or session closes; local storage usually persists until erased, replaced or reset. The need for consent depends on purpose and technical use rather than the label. Strictly necessary storage can support a service explicitly requested by a user; non-essential analytics or advertising storage may need prior consent.
3 Current browser storage inventory
The following functional browser values are used in the current production application. Some keys retain historical technical names that are not user-facing product branding. The application audit found no application-set cookies reachable in current production flows; this does not rule out cookies independently set by infrastructure or providers.
Authentication session: the localStorage key pattern sb-<project>-auth-token keeps an authenticated User signed in and restores the session. The exact provider-generated key may vary with project configuration. It remains until sign-out, expiry or invalidation, application removal or browser clearing; blocking it may prevent protected Workspace functions.
Session-only sign-in choice: rfl:session-only in localStorage and rfl:session-alive in sessionStorage support the User’s choice not to remain signed in after the browser/session closes. The local value persists until cleared or replaced by the application or browser; the session value ends with the tab/session or earlier clearing.
Active Workspace: winglog.active_workspace in sessionStorage remembers the selected Workspace for the current tab/session. It ends with that tab/session or changes when another Workspace is selected.
Master Admin impersonation: winglog.master_admin.impersonation in sessionStorage is temporary state for authorized administrative Workspace access, not ordinary Customer tracking. It ends with the tab/session or earlier clearing.
New Workspace welcome: fleetops:newSchoolWelcome in sessionStorage temporarily supports the welcome message after registration. It is removed after use or when the tab/session ends.
Notice acknowledgement: starboardlog-cookie-consent in localStorage remembers that the informational browser-storage notice was dismissed. It remains until cleared or reset and is not advertising or behavioral-tracking consent.
Application-install prompt: rfl:pwa-install-dismissed in localStorage remembers dismissal of the optional PWA install prompt so it is not immediately shown again. It remains until cleared or reset.
A booking-linked Guest Access link is time-limited and revocable. The guest token is read from the link URL and sent only with the relevant first-party requests during the page view. Guest Access requires no sign-in and creates, reads or stores no Guest-Access-specific cookie, local-storage value or session-storage value. It does not provide ordinary Workspace membership or Google Drive access. Authenticated-User session storage and notice-acknowledgement storage are separate from Guest Access.
4 Consent and notice
The described authentication and requested functional storage is necessary for the service the user requests or to remember an acknowledged informational notice. The notice can use Close or Understood; it does not ask for advertising consent. The Service does not currently use Google Analytics, Meta Pixel, PostHog, Plausible, advertising cookies or newsletter tracking. If non-essential technology is added, it will be separately assessed and any legally required consent obtained before use.
5 User controls
Users can sign out and clear or block site data in browser settings. This may sign a User out, reset the selected Workspace or sign-in preference, end temporary administrative state, or show the notice or application-install prompt again. Clearing browser storage does not delete an Account, Workspace record or independently controlled Google Drive file. Account or Workspace deletion follows a separate verified process.
6 Updates and contact
Before adding non-essential tracking, we will assess purpose, legal basis, provider, retention and required consent, and update this Notice and the Privacy Policy. Material changes may be announced in the Service or by email. Questions: starboardlog@gmail.com.

