Cookie Policy
- Version:
- 0.9-beta
- Last updated:
- 2026-10-03
- Effective:
- [set at launch]
Beta (draft) version under legal review before public launch — may change before taking effect. You will be asked to accept again after any material change.
In short
- We use only two cookies: one strictly necessary for login session security, and one to remember your language.
- We use no analytics, advertising or third-party tracking cookies.
- Your login token is never stored in the browser's local storage.
- The platform caches public pages so it can work offline, without any personal data.
- If we ever add non-essential cookies, we will only enable them with your consent.
1. What Cookies Are
- Cookies are small text files that a browser stores at a website's request to remember information between visits.
- This policy also covers similar storage technologies the platform uses in your browser.
- This policy should be read with the "Privacy Policy".
2. Cookies We Use
| Name | Category | Purpose | Duration | Set by |
|---|---|---|---|---|
| sm_refresh | Strictly necessary | Keeps and renews a secure login session; httpOnly and secure, so page scripts cannot read it | About 30 days, renewed on use | The platform |
| NEXT_LOCALE | Functional | Remembers the interface language you chose | [For review: language cookie duration as set by the i18n library] | The platform |
2.1 Strictly necessary cookies
- The login service cannot run securely without sm_refresh, so it does not require prior consent.
- If you block it in your browser, you will not be able to stay signed in.
2.2 Functional cookies
- The language cookie only stores your preference and is not used to track you.
- If you delete it, the interface returns to the default language. [For review: whether consent is required for the language cookie in any target country]
3. What We Do Not Use
- We do not use analytics or audience-measurement cookies.
- We do not use advertising or retargeting cookies.
- We do not allow any third party to place tracking cookies through the platform.
- We do not store the access token in localStorage or sessionStorage; it stays in page memory only and is lost when the page is closed.
4. Service Worker and Offline Storage
- The platform uses a service worker that caches public pages and static assets (such as fonts and images) and an "offline" page.
- This cache contains no personal data or content specific to your account.
- You can remove it by clearing site data in your browser settings.
5. Payment Pages
When you move to the Kashier payment gateway page, the gateway may set its own cookies under its own policy, which is outside the scope of this policy.
6. Controlling Cookies
- You can delete or block cookies in your browser settings.
- Blocking the necessary cookie prevents sign-in; blocking the language cookie returns the interface to the default language.
7. Changes
- If we ever need a non-essential cookie, we will update this policy and ask for your consent before enabling it, which you can withdraw at any time.
- Questions: privacy@octasolutions.net.