EN / ES
Sign In Start Free Trial

Cookie Policy

Last Updated: June 14, 2026 · Effective Date: June 14, 2026

1. Introduction

This Cookie Policy explains how Sefton ("Sefton," "we," "us," or "our") uses cookies and similar tracking technologies on our website and platform. This policy should be read in conjunction with our Privacy Policy.

Important: Sefton is a healthcare business administration platform built to support HIPAA compliance. We do NOT use cookies to store Protected Health Information (PHI) or any sensitive healthcare data. All PHI is stored securely in our backend database, never in browser storage or cookies accessible to JavaScript.

2. What Are Cookies?

Cookies are small text files that are placed on your device (computer, tablet, or mobile) when you visit a website. They are widely used to make websites work more efficiently and provide information to website owners.

Cookies can be "persistent" (remain on your device until deleted or expired) or "session" cookies (deleted when you close your browser).

3. Types of Cookies We Use

3.1 Essential Cookies (Required)

These cookies are strictly necessary for the website to function and cannot be switched off. They are usually set in response to actions made by you, such as setting your privacy preferences, logging in, or filling in forms.

  • Authentication Cookies: HttpOnly, Secure, SameSite cookies used for user authentication and session management
  • Security Cookies: Cookies that help prevent security threats and unauthorized access
  • Session Management: Cookies that maintain your session while using the platform

Important: Our authentication cookies are HttpOnly, meaning they cannot be accessed by JavaScript. This ensures that PHI and authentication tokens are never exposed to client-side code, maintaining HIPAA compliance.

3.2 Functional Cookies (Optional)

These cookies enable enhanced functionality and personalization. They may be set by us or by third-party providers whose services we have added to our pages.

  • User Preferences: Cookies that remember your preferences (language, display settings)
  • Feature Flags: Cookies that enable or disable certain features based on your account type

Note: User preferences are primarily stored in our secure backend database, not in cookies. Cookies are only used for temporary session preferences.

3.3 Analytics Cookies (Not Currently Used)

We do NOT currently use analytics cookies, advertising cookies, or any third-party tracking cookies that would expose PHI or compromise HIPAA compliance.

If we implement analytics in the future, we will:

  • Only use HIPAA-compliant analytics solutions
  • Ensure no PHI is transmitted to analytics providers
  • Obtain appropriate consent where required
  • Update this Cookie Policy to reflect any changes

4. What We Do NOT Use

To maintain HIPAA compliance and protect your privacy, Sefton does NOT use:

  • Marketing Cookies: We do not use cookies for marketing or advertising purposes
  • Third-Party Tracking: We do not use third-party analytics or advertising cookies
  • Social Media Cookies: We do not use social media tracking cookies
  • Browser Storage for PHI: We NEVER store PHI in localStorage, sessionStorage, or JavaScript-accessible cookies
  • Cross-Site Tracking: We do not use cookies to track you across different websites

5. Cookie Settings and Management

5.1 Browser Settings

Most web browsers allow you to control cookies through their settings preferences. However, limiting cookies may impact your ability to use Sefton, as essential cookies are required for authentication and security.

You can manage cookies in your browser settings:

  • Chrome: Settings → Privacy and Security → Cookies and other site data
  • Firefox: Options → Privacy & Security → Cookies and Site Data
  • Safari: Preferences → Privacy → Cookies and website data
  • Edge: Settings → Privacy, search, and services → Cookies and site permissions

5.2 Impact of Disabling Cookies

If you disable essential cookies, you may not be able to:

  • Log in to your Sefton account
  • Access secure areas of the platform
  • Use features that require authentication
  • Maintain your session while using the platform

We recommend keeping essential cookies enabled to ensure full functionality of Sefton.

6. Third-Party Cookies

Sefton does not currently use third-party cookies. All cookies we use are first-party cookies set directly by Sefton.

If we integrate third-party services in the future that require cookies, we will:

  • Ensure all third-party services are HIPAA-compliant
  • Maintain Business Associate Agreements (BAAs) with all third-party service providers
  • Ensure no PHI is transmitted via third-party cookies
  • Update this Cookie Policy to disclose any third-party cookie usage

7. HIPAA Compliance and Cookies

Sefton's cookie usage is designed to maintain HIPAA compliance:

  • HttpOnly Cookies: Authentication cookies are HttpOnly, preventing JavaScript access to authentication tokens
  • Secure Cookies: All cookies are transmitted over encrypted HTTPS connections only
  • SameSite Protection: Cookies use SameSite attributes to prevent cross-site request forgery (CSRF) attacks
  • No PHI in Cookies: Protected Health Information is NEVER stored in cookies
  • Backend Storage: All PHI and sensitive data are stored in secure backend databases, never in browser storage

8. Data Retention

Cookie retention periods:

  • Session Cookies: Deleted when you close your browser
  • Authentication Cookies: Expire based on your session timeout settings (typically 24 hours of inactivity)
  • Preference Cookies: May persist for up to 1 year, but preferences are primarily stored in our backend database

9. Updates to This Cookie Policy

We may update this Cookie Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of material changes by:

  • Posting the updated Cookie Policy on this page
  • Updating the "Last Updated" date
  • Sending email notification to registered users (for material changes)

Your continued use of Sefton after changes become effective constitutes your acceptance of the updated Cookie Policy.

10. Contact Information

If you have questions about this Cookie Policy or our use of cookies:

Sefton Health, Inc. (operating the Sefton platform)

Email: privacy@sefton.health

© 2026 Sefton Health, Inc. All rights reserved.

sefton

Bilingual to the core — care, documentation, and billing in one platform.

Product

  • Features
  • Pricing
  • FAQ
  • Sign in
  • Start free trial

Legal

  • Privacy policy
  • Terms of service
  • Cookie policy
  • Accessibility

Compliance

  • Security
  • Business Associate Agreement
  • Legal center

Company

  • Contact
© Sefton — bilingual, billing-first practice management for allied health.