ruledoc.io v0.2
Features Pricing About Contact
Sign in Get started
Legal · Policy ruledoc.io / cookies

Cookie Policy

Privacy Terms DPA Sub-processors Cookies

Effective date: 2026-05-31 Last updated: 2026-05-31


What this policy covers

This Cookie Policy explains how ruledoc.io (operated by RFPvault (registered in Sweden), contact privacy@ruledoc.io) uses cookies and similar technologies (collectively, "Cookies") on its website and Service. It should be read together with our Privacy Policy.

This Policy is informed by:

  • GDPR (Regulation (EU) 2016/679) - where Cookies process personal data
  • ePrivacy Directive (2002/58/EC, as amended), Art. 5(3) - consent for storage of information on a user's device
  • The Swedish Electronic Communications Act (Lag (2022:482) om elektronisk kommunikation), § 9 ch. 28 (Swedish implementation of ePrivacy Art. 5(3))

Summary

ruledoc.io uses only strictly-necessary cookies. We do not use analytics cookies, advertising cookies, social-media plugins, or any form of cross-site tracking. We do not display a cookie banner because strictly-necessary cookies do not require consent under ePrivacy Art. 5(3) and the Swedish Electronic Communications Act.

If this changes in the future (for example, if we add product-analytics), we will update this Policy, deploy a compliant consent banner, and obtain your prior consent before any non-essential Cookie is set.

Cookies we set

Cookie name Purpose Type Set by Duration Personal data
ruledoc_sid Maintains your authenticated session after login Strictly necessary (ePrivacy Art. 5(3) exemption) ruledoc.io (first-party) Session (cleared on browser close) or 30 days if "remember me" is selected Session identifier (not your password); linked server-side to your account

Cross-site request forgery (CSRF) protection uses a token stored inside your session and submitted as a hidden form field; it is not a separate cookie.

Strictly-necessary status

The Cookies listed above are exempt from the consent requirement of ePrivacy Art. 5(3) because their sole purpose is strictly necessary in order to provide a service explicitly requested by you (session authentication for the Service you are using). This is consistent with European Data Protection Board (EDPB) Guidelines 5/2020 on consent and EDPB Guidelines on the use of cookies (where applicable).

Checkout (Paddle)

Our checkout and payment pages load Paddle, our Merchant of Record. Paddle may set its own strictly-necessary cookies or local storage needed to run the payment and prevent fraud during a purchase. These are set only when you start a purchase on the checkout flow. See Paddle's cookie and privacy notices for details.

Cookies we do NOT set

For full transparency:

  • No analytics, advertising, social-media, session-replay, or A/B-testing cookies.
  • No CDN tracking cookies (the Service is served directly).

If we ever introduce any of the above, we will (a) update this Policy, (b) deploy a compliant consent banner with equally prominent "Accept" and "Reject" controls (no dark patterns), (c) default all non-essential Cookies to OFF, and (d) only set them after explicit affirmative consent that is as easy to withdraw as to give (Art. 7(3) GDPR).

Other tracking technologies

We do not use:

  • Pixel tags / web beacons set by third parties
  • Browser fingerprinting
  • localStorage or sessionStorage for tracking purposes (we may use localStorage for storing UI preferences such as light/dark theme; this data stays in your browser and is not personal data unless it identifies you)
  • IndexedDB for tracking
  • Server-side identifiers tied to a fingerprint

Embedded content from other websites

Articles or pages on ruledoc.io may include embedded content (for example, images or documentation snippets). Embedded content from other websites behaves in the same way as if you visited the other website directly. Those websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content.

At present, ruledoc.io does not embed third-party content.

Your choices

Because we use only strictly-necessary Cookies, no consent is required and no opt-out is available without breaking the Service (you cannot maintain a logged-in session without the session cookie).

You can still control Cookies at the browser level:

  • Most browsers allow you to block all cookies, block third-party cookies only, delete cookies on close, or manage cookies per-site.
  • Blocking the ruledoc_sid cookie will prevent you from logging in.

If we add non-essential Cookies in the future, we will offer per-purpose opt-in toggles in a consent preference centre, and your refusal will not affect access to the Service (Art. 7(4) GDPR - no detriment for refusal).

Updates to this Policy

We may update this Policy from time to time. The "Last updated" date at the top reflects the most recent change. If we materially change our use of Cookies, we will notify customers by email and (where required by law) obtain consent before the change takes effect.

Contact

For questions about this Cookie Policy, contact privacy@ruledoc.io.

For complaints, you may contact:

Integritetsskyddsmyndigheten (IMY) - the Swedish Authority for Privacy Protection Box 8114, SE-104 20 Stockholm, Sweden Web: https://www.imy.se/

All legal documents Operated by RFPvault · privacy@ruledoc.io
ruledoc.io

Audit-grade firewall compliance reports for six frameworks. Built for security engineers who would rather not write the report themselves.

service live

Product

  • Features
  • Pricing
  • Sample report

Company

  • About
  • Contact

Legal

  • Privacy
  • Terms
  • DPA
  • Sub-processors
  • Cookies

Contact

  • support@ruledoc.io
  • sales@ruledoc.io
  • privacy@ruledoc.io
© 2026 RFPvault (registered in Sweden).