Legal
Cookie Policy (New Zealand)
Cookies, local storage, session storage, and similar technologies used by DREKAR CRM.
Effective: August 27, 2026
Last updated: August 27, 2026
- v2.0 · July 13, 2026Expanded categories, purposes, retention, and browser controls.
- v1.0 · June 1, 2026Initial Cookie Policy.
This Cookie Policy explains how SparrowHawk CRM LLC uses cookies, local storage, session storage, and similar technologies on the SparrowHawk CRM website, platform, and customer portals for organisations under the New Zealand profile. It forms part of the Privacy Policy.
SparrowHawk CRM does not use advertising cookies and does not sell or share information from cookies for advertising purposes.
1. What Are Cookies
Cookies are small text files that websites place on a device to store information between requests. "Local storage" and "session storage" are related browser mechanisms that store larger amounts of data on the device without sending it with every request. SparrowHawk CRM uses these technologies interchangeably where appropriate, and the term "cookies" in this policy refers to all of them.
2. Categories We Use
SparrowHawk CRM uses the following categories of cookies:
- Strictly necessary cookies — required to sign in, keep users signed in, protect against cross-site request forgery, and route requests to the correct backend region.
- Functional cookies — remember user preferences such as theme (light or dark), preferred language, and dismissed banners.
- Security cookies — enforce rate limits, detect abusive automation, and protect against session fixation.
- Analytics cookies — measure aggregate platform usage, feature adoption, and performance issues so we can prioritize improvements. Analytics data is not used to target individuals with advertising.
3. Purposes
Cookies are used to:
- keep users signed in across pages and between tabs
- remember which organization the user is currently working inside
- hold short-lived state during onboarding and multi-step flows
- protect authenticated actions from cross-site request forgery
- remember accessibility and display preferences
- detect and slow down abusive automated traffic
- measure aggregate platform reliability and performance
4. Third-Party Cookies
Some subprocessors described on the Subprocessor List may set cookies as part of their service — for example, Stripe on payment pages, Cloudflare for edge protection, and Google when a user chooses Google sign-in. Those cookies are governed by each provider's own cookie and privacy policies.
5. Retention
Session cookies expire when the browser is closed or when the user signs out. Persistent cookies expire at the time set by SparrowHawk CRM or by the third-party provider that set them, which is typically no longer than reasonably necessary for the purpose described.
6. Your Controls
Most browsers let the user view, block, or delete cookies through browser settings. Some browsers offer a "do not track" or "global privacy control" signal; where SparrowHawk CRM is required by applicable law to honor a specific signal, we will do so.
Customer administrators may also configure their organization's use of platform-level features, which can further reduce the categories of cookies set for their end users.
7. Impact of Disabling Cookies
Strictly necessary cookies cannot be disabled without breaking the platform: sign-in, organization scoping, and CSRF protection all depend on them. Disabling functional or analytics cookies is safe but may reduce personalization and slow the pace of platform improvements.
8. Changes to This Policy
When we materially change this Cookie Policy, we will bump the version and effective date shown at the top of this page and record the change in the change log.
New Zealand: Cookies and the Privacy Act 2020
New Zealand does not have a standalone cookie-consent statute. Where a cookie or similar technology collects personal information, it is handled under the Privacy Act 2020 and the Privacy Policy, including the collection, use, security, and disclosure principles described there.
The technologies we use are limited to those needed to operate the service and, where offered, optional analytics and preference storage. Categories in use are: strictly necessary/essential; authentication, session, and security (including trusted-device and two-factor state); preference storage such as interface and device settings; and product analytics where enabled.
You can manage or clear cookies and site storage through your browser settings, and use any consent or preference controls offered in the platform. Blocking essential or authentication storage will prevent sign-in and core features from working.
