Cookie Policy
Plain language summary: We use essential browser storage to keep you signed in and privacy-limited first-party measurement to understand acquisition and form progression. We rely on legitimate interests for this measurement and provide an opt-out. We do not use Google Analytics, Google Ads tags, advertising pixels, cross-site trackers, or session replay.
1. What Is a Cookie?
A cookie is a small text file stored on your device by a website. Cookies help websites remember information about your visit — like whether you're logged in — so you don't have to re-enter it every time.
There are also similar technologies like localStorage and sessionStorage, which store data locally in your browser. Risiti uses these for authentication, security, saved preferences, and first-party journey measurement.
2. Cookies & Local Storage We Use
| Name / Key | Type | Purpose | Duration |
|---|---|---|---|
__convexAuthJWT |
Essential | Stores your authentication token so you remain logged in. Without this, you would need to re-verify your phone number on every visit. | Session / until token expires (~1 hour, auto-refreshed) |
__convexAuthRefreshToken |
Essential | Stores a refresh token that allows your session to be silently renewed without re-entering your OTP. Stored in localStorage. | Up to 30 days (cleared on sign out) |
risiti_analytics_consent |
Preference | Records whether you acknowledged the analytics notice or opted out. | Until you clear site data or change the preference |
risiti_vid |
Analytics | A random first-party visitor identifier that connects acquisition, page journeys, and an eventual waitlist or account record. It contains no phone number, name, KRA PIN, or form value and is removed when you opt out. | Until you clear site data or choose essential only |
risiti_sid |
Analytics | A random session identifier used to measure page progression and engagement within one browser session. | Current browser session |
risiti_thumbmark |
Analytics | A pseudonymous first-party browser fingerprint hash used as a secondary identity signal when a random visitor ID is unavailable or changes. It helps connect a pre-signup journey to the resulting account and prevent duplicate attribution. Risiti stores the hash, not the browser components used to calculate it. | Until you clear site data or choose essential only |
| Cloudflare performance beacon | Analytics | Provides aggregate delivery, reliability, and page-performance information. Risiti does not use it to build customer advertising profiles. | Cookieless |
What We Do NOT Use
- Google Analytics, Google Ads tags, or Google Tag Manager
- Facebook Pixel or other third-party advertising pixels
- Session replay, keystroke recording, or collection of form values in analytics events
- Cookies that build personal advertising profiles
- Cross-site tracking identifiers
3. Essential vs. Non-Essential Cookies
Essential (Required)
The authentication tokens (__convexAuthJWT and __convexAuthRefreshToken) are strictly necessary for the Service to function. Without them, you cannot stay logged in. These do not require your consent under the Kenya Data Protection Act, 2019, as they are necessary for service delivery.
Analytics (Non-Essential)
Risiti records first-party events such as page views, acquisition source, country and coarse region, browser and device category, CTA clicks, elapsed engagement time, form start, the name of a completed field, form submission, and the last field reached before abandonment. We also calculate a pseudonymous browser fingerprint hash as a secondary identity signal. Analytics events never contain the value entered into a field, an IP address, exact coordinates, raw fingerprint components, or a cross-site identifier.
If you opt out or enable your browser's Do Not Track signal, Risiti removes the persistent analytics visitor identifier and fingerprint hash from your browser and stops optional journey events. Previously received records remain subject to the retention periods in our Privacy Policy. Source parameters submitted with a waitlist form may still be stored with that waitlist record so we can understand the context of the request you sent us.
4. How to Manage Cookies
Browser Settings
You can control or delete cookies through your browser settings. Here's how:
- Chrome: Settings → Privacy and Security → Cookies and other site data
- Safari (iPhone): Settings → Safari → Advanced → Website Data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Edge: Settings → Privacy, Search, and Services → Cookies
Note: Clearing the essential authentication tokens will log you out of Risiti. You will need to verify your phone number again to log back in.
Opting Out of Analytics
- Risiti first-party analytics: Choose “Opt out” in the privacy notice, enable Do Not Track, or clear Risiti site data and choose that option on your next visit.
- Cloudflare performance data: Use browser privacy controls such as Do Not Track where supported.
5. Mobile App
The Risiti mobile app (iOS and Android) does not use browser cookies. It uses device-local storage (AsyncStorage / SecureStore) to maintain your authenticated session, equivalent to the localStorage entries described above. The same data retention rules apply.
6. Lawful Basis and Choice
Risiti relies on legitimate interests for limited first-party product analytics: understanding how people find the service, whether pages work, and where signup becomes difficult. We document this purpose, minimise the fields collected, do not use the data for advertising, and provide an opt-out.
For essential authentication tokens, processing is necessary to deliver the service you requested. Marketing communications remain consent-based.
If we introduce advertising, cross-site tracking, session replay, or another materially different purpose, we will update this policy and seek consent where required.
7. Changes to This Policy
We will update this Cookie Policy if we change the cookies or tracking technologies we use. Material changes will be communicated via in-app notification. The current version is always available at getrisiti.com/cookie-policy.
8. Contact
For questions about this Cookie Policy:
- Email: hello@getrisiti.com
- Company: PesaStack Limited, Nairobi, Kenya