Effective August 20, 2026
This policy explains how SoraCore uses cookies and similar browser storage technologies when you use the platform. It applies to the SoraCore web application and its public website.
SoraCore itself sets no tracking cookies. The application uses your browser's local storage — a similar but more modern technology — to keep you signed in and remember your preferences. Local storage behaves like a cookie for the purposes of this policy: it's a small amount of data your browser keeps on your device between visits, but it is only ever sent to our servers when your browser makes an explicit request (unlike cookies, which are attached automatically to every request).
There is one exception, and it is limited to two pages. On the checkout and subscription-renewal pages we embed Stripe, our payment provider, to collect card details securely. Stripe sets its own cookies on those pages to detect fraudulent payments. They are set by Stripe rather than by us, they are not used for advertising or cross-site profiling, and they are not present anywhere else in the application — including every page you use for day-to-day work.
All storage used by SoraCore is essential or functional — none of it is used for advertising, cross-site tracking, or building a profile of you for marketing purposes.
| Storage item | Purpose | How long it's kept |
|---|---|---|
| Authentication session | Keeps you signed in between page loads and refreshes your session automatically, so you aren’t logged out mid-task. | Until you sign out, or your session expires |
| Language & theme preference | Remembers your selected language and light/dark theme so the interface looks the way you left it next time you visit. | Until you change it or clear your browser data |
| Notice dismissal | Remembers which company-wide notice you’ve already seen and dismissed, so it isn’t shown to you again. | Until a new notice is published |
| Session activity timer | Tracks the time of your last activity so you can be automatically signed out after a period of inactivity, protecting your account on shared devices. | Continuously updated while you’re active |
| Active company / entity selection | Where your Organization has more than one legal entity, remembers which one you were last working in so you return to the same view. | Until you switch entity or clear your browser data |
| Reminder alarm settings | Stores your personal check-in/check-out reminder times on your own device. These are never sent to our servers. | Until you change or disable them |
| Notification read marker | Remembers which notifications you have already seen so the unread indicator is accurate. | Until you clear your browser data |
| Payment provider (Stripe) cookies | Set by Stripe only on the checkout and subscription-renewal pages, to detect fraudulent payments. Set by Stripe, not by SoraCore, and not used for advertising. | Up to 1 year (Stripe’s retention, not ours) |
When you check in or out for attendance, SoraCore converts your GPS coordinates into a readable location name using a third-party mapping lookup service. This is a server-to-server request made on your behalf and does not set any cookies or tracking storage in your browser.
Stripe. Our payment provider's script runs only on the checkout and renewal pages and sets the fraud-prevention cookies described in Section 2. Stripe processes that data as its own controller under its own privacy policy; SoraCore never receives your full card details.
SoraCore does not use advertising cookies, analytics trackers, or social media tracking pixels anywhere. As an internal workforce management tool, we have no need to track your behavior for marketing purposes. The only third-party cookies present are Stripe's fraud-prevention cookies on the two payment pages, described above — these are strictly necessary to take a payment safely, not a marketing technology.
Because the storage we use is strictly necessary or functional (not advertising or cross-site tracking), the separate opt-in consent banners used for tracking cookies are generally not required under Singapore's Personal Data Protection Act (PDPA). If we ever introduce non-essential or analytics storage, or if the law of your own country requires consent for the storage we already use, we will ask for your consent first. You remain in control and can clear this storage at any time (see below).
You can clear SoraCore's local storage at any time through your browser's settings (usually under "Privacy" or "Site settings" → "Clear browsing data" / "Clear site data" for this site). Doing so will sign you out and reset your saved language and theme preferences the next time you visit — it will not affect any data stored in your Organization's account on our servers.
We may update this Cookie Policy if the technologies we use change. Material changes will be communicated to Organization Admins, and the "Effective" date above will be updated.
Questions about this Cookie Policy should be directed to your Organization's HR or Admin team, who can escalate to us. Our registered office is: SAGBRAIN GLOBAL PTE. LTD. (UEN 202611585N), 100D Pasir Panjang Road #05-03, MEISSA, Singapore 118520. Privacy queries may also be sent to support@soracore.net.