1. What are cookies?
Cookies are small text files stored on your device when you visit a website. Similar technologies include local storage, session storage, pixels, and software development kits that store or read identifiers on your device. For simplicity, we refer to all of these as “cookies” in this Policy.
2. How we use cookies
We use cookies to:
- Keep you signed in and protect accounts (essential)
- Remember security and session state (essential)
- Store your cookie consent choices (essential)
- Measure product usage and performance when you opt in (analytics)
- Support optional marketing or campaign measurement when you opt in (marketing)
Essential cookies are required to operate the Services and do not require consent in most jurisdictions. Non-essential cookies are used only after you accept them via our consent banner or Cookie settings, except where a different legal basis applies.
3. Cookie categories
3.1 Essential
These cookies enable core functionality such as authentication (including Auth.js / NextAuth session cookies), CSRF or security protections, load distribution, and remembering your consent preferences. The Services cannot function properly without them.
3.2 Analytics
These cookies help us understand how the product is used (for example feature adoption and performance). They are disabled until you opt in. We do not use analytics cookies to sell your personal information.
3.3 Marketing
These cookies may be used for relevant product communications and measuring the effectiveness of campaigns when enabled. They remain off until you opt in.
4. Examples of cookies we use
Exact cookie names may change as we improve the platform. Typical examples include:
- Session / auth cookies — maintain your signed-in state across requests (essential; duration: session or as configured by the auth provider).
autocertify_consent— stores a compact record of your cookie preferences (essential; up to 12 months).- Local storage key
autocertify.cookie-consent— detailed preference JSON used by the consent UI (essential preference storage). - Organization preference keys (for example active organization ID in local storage) — remember workspace context while you use the dashboard (functional / essential to product UX).
- Analytics / marketing identifiers — only if you opt in and only when such tools are enabled in your environment.
5. Managing your preferences
You can control non-essential cookies by:
- Using our on-site consent banner (Accept all, Reject non-essential, or Customize)
- Opening Cookie settings from the website footer at any time
- Adjusting your browser settings to block or delete cookies (note: blocking essential cookies may break sign-in and core features)
Where required by law (including GDPR-style consent rules), we will not set non-essential cookies until you consent. Under US state privacy laws, you may also have rights to opt out of certain “sale” / “sharing” of personal information; our consent controls are designed to support those choices for cookie-based technologies.
6. Third-party cookies
Some features rely on third parties (for example Google sign-in, Razorpay checkout, email infrastructure, or cloud hosting). Those parties may set their own cookies subject to their policies when you interact with their services. We encourage you to review their documentation.
7. Retention
Cookie lifetimes vary: session cookies expire when you close your browser; persistent cookies remain until they expire or you delete them. Consent records are typically retained for up to 12 months, after which we may ask you to confirm preferences again.
8. Updates
We may update this Cookie Policy when our practices or technologies change. The “Last updated” date at the top of this page reflects the latest revision.
9. More information
For broader privacy practices, see our Privacy Policy. Questions: privacy@autocertify.in.