Cookie Policy
Effective from: 10 August 2026. This Cookie Policy describes what cookies and equivalent tracking technologies Cloudrms Pty Ltd sets on cloudrms.org, on what legal basis, for what purpose and for how long. It is drafted to comply with the Privacy Act 1988 (Cth), the Australian Privacy Principles and the Spam Act 2003 (Cth), and reflects the guidance issued by the Office of the Australian Information Commissioner (OAIC).
Independence and non-affiliation
Cloudrms is an independent third-party shop and is not affiliated with, sponsored by or endorsed by RMS Cloud Pty Ltd or its parent company. No cookie or tracker described in this policy is set on our behalf by, or transmits data to, RMS Cloud Pty Ltd.
1. What are cookies?
A cookie is a small text file that the cloudrms.org web server writes to your device (computer, tablet or smartphone) when you visit the site. Cookies allow a website to recognise a device, to remember user preferences and to analyse navigation behaviour. This policy treats cookies and equivalent technologies uniformly: local storage, session storage, IndexedDB, service worker caches, pixel tags, canvas fingerprinting, HTTP ETag tracking and similar technologies. The rules described below apply to all of them.
2. Categories of cookies we use
2.1 Strictly necessary cookies
These cookies are indispensable to the operation of the site and to the delivery of a service you have expressly requested (Client Area session, cart persistence, form security). They are not subject to the cookie banner. They cannot be refused without breaking the site.
2.2 Functional cookies
Functional cookies remember choices you make to improve your experience, such as your preferred language and your response to the cookie banner. They are set only after your explicit acceptance and can be withdrawn at any time.
2.3 Analytics cookies
We use a privacy-first, self-hosted analytics tool that does not use cross-site cookies, does not fingerprint devices and does not send data to any third party outside our infrastructure. Where possible, analytics are collected cookie-less through hashed and salted daily identifiers that cannot be reconciled with a natural person and are rotated every 24 hours. Where a cookie is nonetheless required (for example to distinguish a returning visitor within a session), it is set only after your explicit acceptance.
2.4 Third-party cookies
cloudrms.org sets no third-party advertising, retargeting or social-media cookies. The only third-party cookies that may appear during a visit are those set by our payment service provider, and only if you actively proceed to the checkout redirect. In that case, the cookies are set by the payment domain and are governed by the payment provider’s own cookie policy.
3. Cookie table
| Name | Category | Provider | Purpose | Retention |
|---|---|---|---|---|
cr_session | Strictly necessary | Cloudrms | Authenticated Client Area session identifier issued after magic-link sign-in. | Session (deleted when browser is closed) |
cr_csrf | Strictly necessary | Cloudrms | Anti-CSRF token protecting forms against cross-site request forgery. | 24 hours |
cr_magic_nonce | Strictly necessary | Cloudrms | Single-use nonce validating a magic-link click. | 15 minutes |
cr_cart (LocalStorage) | Strictly necessary | Cloudrms | Persists the contents of your shopping cart between visits. | Until manually cleared |
cr_cookie_consent | Strictly necessary | Cloudrms | Records your response to the cookie banner (accept, refuse or per-category). | 12 months |
cr_lang | Functional | Cloudrms | Remembers your language preference across visits. | 1 year |
cr_banner_dismissed | Functional | Cloudrms | Remembers that you have dismissed a non-critical notification banner. | 30 days |
cr_analytics_id | Analytics (opt-in) | Cloudrms (self-hosted analytics) | Rotating daily identifier used to distinguish visits within a 24-hour window. | 24 hours (rotated) |
cr_ab | Analytics (opt-in) | Cloudrms | Assigns you to an A/B test variant so the experience remains consistent between page loads. | 30 days |
payment_* | Third-party (checkout only) | Payment provider | Cookies set on the payment domain when you proceed to a hosted payment page. Governed by the payment provider’s cookie policy. | Per payment provider policy |
4. How to manage cookies
4.1 Cookie banner
On your first visit, a banner appears at the bottom of the screen offering three options: Accept all, Decline non-essential or Manage per category. The choice is recorded in the cr_cookie_consent cookie for twelve (12) months; you may change it at any time from the link «Cookie preferences» in the site footer.
4.2 Browser settings
You may block or delete cookies at any time from the settings of your web browser. Instructions are available on the support pages of Chrome, Firefox, Safari and Edge. Blocking strictly necessary cookies will break the Client Area and the shopping cart.
4.3 Do Not Track
cloudrms.org respects the Do Not Track signal (DNT) issued by your browser. When DNT is set, no analytics cookies are placed and no analytics event is recorded, regardless of the choice recorded in the cookie banner.
4.4 Global Privacy Control
cloudrms.org also respects the Global Privacy Control (GPC) signal. GPC is treated as an unambiguous refusal of non-essential cookies for the browsing session in which it is set.
5. Consent record
Where consent is required, we record it in a way consistent with the OAIC’s guidance on consent: date and time of consent, categories accepted or refused, exact wording of the banner shown, and the version of this Cookie Policy in force at that time. This record is kept for twelve (12) months from the date of the last renewal and produced on request to demonstrate compliance.
6. Consent renewal
Your consent is renewed after twelve (12) months. On the first visit after that period, the cookie banner is displayed again and no non-essential cookie is set until you have responded.
7. Withdrawing consent
You may withdraw your consent at any time, without adverse consequence, using the «Cookie preferences» link in the footer. Withdrawal takes effect immediately: functional and analytics cookies already stored are deleted, and no new cookie of those categories is set. Strictly necessary cookies remain in place because they are required to operate the site.
8. Children
Cloudrms is a professional service intended for hotel operators. It is not directed at children. We do not knowingly collect personal information from children under 15. If we become aware that we have collected such information, we delete it without undue delay.
9. Cross-border disclosure (APP 8)
All cookie-related handling takes place on infrastructure located within Australia (Sydney data centre). We do not disclose cookie data to overseas recipients within the meaning of APP 8.
10. Changes to this policy
This Cookie Policy may be updated to reflect changes to the cookies we set or to applicable law. The version in force and its effective date are always published at cloudrms.org/cookies. A material change to the categories of cookies set or to the purposes of handling triggers a fresh consent request through the cookie banner.
11. Related documents
This policy complements the Privacy Policy, the Terms and Conditions and the Data Processing Agreement. In the event of contradiction, the document with the most protective effect for the individual prevails.
12. Contact for cookie questions
Any question about this Cookie Policy or a request to exercise your rights over cookie data may be sent to:
Cloudrms Pty Ltd
42 Pitt Street, Level 8, Sydney NSW 2000, Australia
Director: James Whitmore
Telephone: +61 2 8756 3421
Email: privacy@cloudrms.org · support@cloudrms.org
ABN: 47 856 234 891 — ACN: 654 789 123
Bank: Westpac Banking Corporation, BSB 032-123, Account 456789012
Regulator: Office of the Australian Information Commissioner (OAIC).
Effective from 10 August 2026. Next scheduled review: 10 February 2027.