

Legal
A cookie is a small text file a site asks your browser to keep. It lets the site recognise the same browser on a later request, which is how you stay signed in from one page to the next.
Two other stores work the same way in law, and we use both: local storage, which survives until it is cleared, and session storage, which is emptied when you close the tab. Where this policy says cookies, it means all three unless it says otherwise.
A cookie is first party when it belongs to staffcoder.com, and third party when it belongs to another company whose code runs on the page. Some third-party code sets first-party cookies; Google Analytics is the example on this site, and it is named in full below.
Staffcoder is operated by SHASTACK INDIA TECHNOLOGIES (OPC) PRIVATE LIMITED. We decide what cookies this site sets and why, which makes us the controller for them.
Questions about this policy go to support@staffcoder.com.
The cookies we need to run the site are set as soon as you use it, because without them the site cannot do what you asked. Everything optional is off until you say otherwise. We ask once, on your first visit, and we ask nothing again unless this policy changes materially.
Nothing on this site is behind a cookie wall. If you refuse the optional cookies, every part of Staffcoder still works, and no feature is withheld.
You can change your mind whenever you like: opens the same choices again, and a Cookie settings link sits in the footer of every page. Turning analytics off deletes the analytics cookies immediately and reloads the page, so the code that sets them stops running.
Your choice is stored in a cookie called sc_consent, described in the next section. We also keep a dated record of each choice on our side, so we can show what was agreed and when, as the law requires us to be able to do. That record holds a random identifier from the cookie, the choice itself, and your browser type. It is linked to your account only if you were signed in at the time, and it never contains your IP address.
These run the site. Without them you could not sign in, forms could not be protected, and the practice environment could not open. They carry no advertising identifier and are never used to profile you, so we do not ask consent for them.
| Cookie | What it does | Lasts |
|---|---|---|
| staffcoder_access | Holds your signed-in session. Not readable by scripts. | 1 hour |
| staffcoder_refresh | Renews the session above without making you sign in again. Sent only to the one endpoint that renews it. | 7 days |
| staffcoder_csrf | Proves a form or request came from our own pages rather than another site. | 7 days |
| sc_consent | Remembers the cookie choice you made here, so we stop asking. | 6 months |
| code-server session | Authenticates your browser to the practice IDE, which runs on its own address for each session. | The session |
| Cloudflare Turnstile | Set on the sign-in, sign-up, verification and password-reset forms to tell a person from a bot. Set by Cloudflare, who act for us. | Up to 30 days |
These exist only because you chose something and we kept it. They stay on your device, we cannot read them from our servers, and clearing them costs you nothing but the setting itself.
| What we remember | Where it is kept | Lasts |
|---|---|---|
| Whether the app sidebar is collapsed | A cookie named sidebar_state | 7 days |
| Light, dark or system appearance | Local storage | Until cleared |
| Which organisation you last worked in | Local storage | Until cleared |
| Cards and notices you dismissed, so they stay dismissed | Local storage | Until cleared |
| Your name and plan, cached so pages draw before the server replies | Local storage | Cleared when you sign out |
| The practice session you have open, so the page can reopen it | Session storage | Until the tab closes |
We use Google Analytics 4 to count visits and see which pages are used, so we know what to improve. It is the only optional thing on this site, and the only reason we ask for consent at all.
If you do not accept, Google’s code is never loaded and neither cookie below is set. Accepting loads it; withdrawing deletes both cookies and reloads the page. We have advertising and personalisation signals permanently switched off, because we do not advertise.
| Cookie | What it does | Lasts |
|---|---|---|
| _ga | Tells one returning browser from another, so repeat visits are not counted as new people. | 2 years |
| _ga_1MJMXXGMPN | Tracks the current visit for this specific property. | 2 years |
Both are set by Google as our processor, on the staffcoder.com domain. What Google does with the data is governed by Google’s Privacy Policy.
We take payments through Razorpay. Their checkout code is not on the page while you browse: it loads only when you start a payment, and only then. If you never buy anything, it never runs.
Once it does load, Razorpay sets its own cookies on its own domains to carry the payment through and to spot fraud. Those cookies are under Razorpay’s control, not ours, so we cannot switch them off from here and we do not offer a toggle that pretends otherwise. See Razorpay’s Privacy Policy. Our own billing terms are in the Terms of Service.
You can sign in with Google, GitHub or LinkedIn. Choosing one sends you to that provider, where they set their own cookies on their own domain to log you in. That happens on their site under their policy, not ours, and it only happens because you chose that button.
They tell us your verified email address and your name so we can create or find your account. What we then do with it is covered by our Privacy Policy.
Your browser can block or delete cookies independently of the choice you make here, and its settings override ours. The controls sit under:
Blocking strictly necessary cookies will sign you out and stop the practice environment from opening. That is not a restriction we impose; those cookies are how the features work.
If we add a cookie, or use an existing one for something new, we update this page and change the date at the top. A change that needs your consent resets it, so the choice is put to you again rather than assumed from the old one.
Questions about cookies, and requests about the personal data behind them, go to support@staffcoder.com. Your wider rights, and how to complain, are set out in the Privacy Policy.
Questions about this document, and grievances under the Information Technology Act, 2000, go to support@staffcoder.com.