Legal

Cookie Policy

The public site does not use advertising or analytics cookies. The Private Office uses only the cookies required to keep an authenticated session and, where applicable, complete multi-factor authentication.

Strictly necessary cookies

The Private Office uses the following first-party cookies only when a person uses authenticated features:

  • jra_session — an HttpOnly, secure session cookie used to maintain an authenticated Private Office session.
  • jra_mfa_challenge — a short-lived, HttpOnly challenge cookie used while an eligible staff user completes multi-factor authentication.

These cookies are not advertising identifiers and are not used to track a person across unrelated sites. Disabling them prevents secure sign-in or authenticated portal use.

What we do not use

  • No advertising or marketing cookies.
  • No social-media pixels.
  • No browser fingerprinting, replay, or heatmap tooling.
  • No cross-context behavioral advertising technology.

Server and security logs

Hosting, security, and application services may process ordinary request information to operate the site, prevent abuse, investigate security events, and maintain service reliability. These records are not browser cookies and cannot be controlled through browser cookie settings.

Your choices

Most browsers allow you to inspect or delete stored cookies. Removing necessary Private Office cookies signs you out. If we introduce any non-essential cookie category, this policy and the consent mechanism will be updated before that category is enabled.

Contact

Questions about this policy may be sent to roman@jamesroman.la. For more detail on personal-information handling, read the Privacy Notice.