Cookie Policy
Last Updated: July 26, 2026
This Cookie Policy explains how Shield Spire Ops ("Shield Spire Ops," "we," "us," or "our") uses cookies, session technologies, and related mechanisms in connection with the Shield Spire Ops platform, website, and operational systems (collectively, the "Platform").
Because Shield Spire Ops is an enterprise-grade, multi-tenant operations platform, cookies and similar technologies are not used solely for basic browsing. They are integral to authentication, tenant isolation, role-based access, real-time workflows, auditability, and system security.
This Cookie Policy should be read together with the Privacy Policy and Terms of Service.
1.Purpose and Role of Cookies in the Platform
Cookies and related technologies are used to support core platform functions, including:
- secure authentication and session continuity
- enforcement of multi-tenant isolation
- role-based dashboard routing
- operational workflow continuity (DAR, incidents, dispatch)
- real-time activity tracking and updates
- compliance and audit traceability
- API and integration security
- system performance and reliability
Unlike marketing-oriented websites, Shield Spire Ops uses cookies primarily to operate and secure a live operational system, not to serve advertising or behavioral tracking.
2.Technologies We Use
Shield Spire Ops may use a combination of:
- HTTP cookies (including secure and HTTP-only cookies)
- session tokens
- refresh tokens
- browser local storage and session storage
- mobile secure storage on supported devices
- device identifiers
- mobile push notification tokens
- API authentication tokens
- request and event identifiers
These technologies may operate together to ensure secure and continuous platform functionality.
3.Strictly Necessary Operational Cookies
These cookies are essential to the functioning of the Platform and cannot be disabled without impacting usability.
They support:
- login authentication
- tenant identification and isolation
- session persistence
- role-based routing (Admin, Employee, Client, Applicant, Platform Owner)
- permission enforcement
- dashboard access control
- navigation across modules
Because Shield Spire Ops operates in a multi-role, multi-tenant environment, these cookies are critical to ensuring that users only access authorized data and functionality.
4.Authentication and Session Integrity
Shield Spire Ops uses cookies and token-based mechanisms to maintain secure sessions.
These technologies enable:
- persistent login across secure sessions
- token refresh cycles to maintain session continuity
- enforcement of multi-factor authentication (MFA) where required
- session expiration and timeout management
- secure logout and session invalidation
Session technologies also support:
- prevention of unauthorized session reuse
- detection of abnormal login behavior
- tracking of session lifecycle events for audit purposes
5.Security, Monitoring, and Abuse Prevention
Cookies and related mechanisms play a key role in platform security.
They are used to:
- detect suspicious login attempts
- monitor failed authentication events
- enforce bot protection systems (e.g., hCaptcha)
- identify abnormal API usage patterns
- support rate limiting and access controls
- link session activity to audit logs
- detect unauthorized access attempts
These capabilities are essential for maintaining system integrity, tenant protection, and operational security.
6.Operational Workflow Continuity
Because Shield Spire Ops supports real-time operations, cookies and session technologies help maintain continuity across workflows such as:
- Daily Activity Reports (DAR)
- incident reporting and response workflows
- dispatch and communication threads
- patrol tracking and checkpoint verification
- scheduling and attendance validation
- compliance and training workflows
- client portal interactions
For example:
- a supervisor reviewing an incident retains session context across modules
- a field officer submitting a DAR maintains continuity between entries
- dispatch activity remains linked to a valid session state
These mechanisms ensure that operational actions are consistent, attributable, and auditable.
7.Compliance, Audit, and Accountability
Cookies and session identifiers contribute to the Platform's audit and compliance model.
They support:
- linking actions to authenticated users
- maintaining traceable session history
- recording operational events tied to specific sessions
- enabling audit log integrity
- supporting SLA tracking and accountability
Because Shield Spire Ops is used in regulated and compliance-driven environments, session-level traceability is an essential part of the platform's design.
8.Multi-Tenant Context Enforcement
Cookies and tokens are used to maintain strict tenant boundaries.
They help ensure that:
- users remain scoped to their assigned tenant
- cross-tenant data access is prevented
- platform owner actions are logged and controlled during context switching
- client users access only their permitted data
- employee and supervisor views remain role-restricted
This is critical to maintaining the integrity of the platform's multi-tenant architecture.
9.API, Integration, and Automation Support
Where API access or integrations are enabled, cookies and tokens support:
- API authentication and authorization
- scope-based access control
- request validation and integrity
- rate limiting enforcement
- webhook validation
- usage tracking for billing and monitoring
These mechanisms ensure that integrations remain:
- secure
- controlled
- auditable
10.Mobile and Field Operations Technologies
For mobile-enabled workflows, Shield Spire Ops may use:
- push notification tokens (e.g., Firebase Cloud Messaging)
- mobile session tokens
- secure device storage for authentication material
- device-level session tracking
- connectivity state indicators
These technologies enable:
- real-time alerts and notifications
- field reporting continuity while connected
- secure mobile session management
Mobile and field workflows generally require an active internet or mobile data connection. Offline workflow capabilities remain under development and are not generally available.
11.Marketing Website Analytics
The Shield Spire Ops marketing website uses a first-party analytics mechanism to understand how visitors reach and move through the site. This mechanism records:
- page views and navigation paths
- a randomly generated session identifier stored in browser session storage
- referral source and campaign parameters (for example, UTM values)
- conversion events such as demo requests and scheduling clicks
- general device and browser information
This information is transmitted to our own infrastructure. It is not sold, is not used for advertising networks, and is not combined into cross-site behavioral profiles. Session storage is cleared automatically when the browser tab is closed.
12.Third-Party Services
Shield Spire Ops may rely on third-party services that use cookies or similar technologies, including:
- infrastructure and database providers (e.g., Supabase)
- payment processors (e.g., Stripe, Stripe Connect)
- messaging and notification systems (e.g., Firebase Cloud Messaging)
- mapping services (e.g., Mapbox)
- email delivery services (e.g., Resend)
- SMS and voice communications providers (e.g., Twilio)
- bot protection services (e.g., hCaptcha)
- meeting scheduling services embedded on our website (e.g., Calendly)
- artificial intelligence infrastructure and model providers used to deliver AI-assisted functionality
- third-party systems that a tenant chooses to connect to its own account
These services may use their own cookies or identifiers according to their respective privacy policies.
13.No Advertising or Cross-Site Tracking
Shield Spire Ops does not use cookies for:
- advertising networks
- cross-site behavioral tracking
- selling user data
- third-party marketing profiling
Cookies are used strictly for:
- platform functionality
- security
- operational workflows
- system performance
14.Managing Cookies
Users may manage cookies through browser settings. However:
Disabling cookies may:
- prevent login functionality
- break session continuity
- disrupt operational workflows
- limit access to platform features
Because many cookies are strictly necessary, restricting them may significantly impact the usability of the Platform.
15.Retention of Cookie and Session Data
Different technologies have different lifecycles:
- session cookies expire after logout or inactivity
- authentication tokens refresh periodically
- security-related logs may be retained longer
- API usage identifiers may be retained for monitoring and billing
- audit-related session records may be retained to support compliance
Retention is aligned with:
- security requirements
- auditability
- operational accountability
16.Updates to This Cookie Policy
We may update this Cookie Policy to reflect:
- platform enhancements
- new features or workflows
- security improvements
- legal or regulatory requirements
The "Last Updated" date will reflect the latest revision.
17.Contact Information
For questions regarding this Cookie Policy:
Shield Spire Ops operates as part of the GEEC AI Platform ecosystem.