Cookie & Web Storage Policy

Technical and statutory disclosures governing cookies, cryptographic session tokens, local storage mechanisms, and diagnostic telemetry for CAfirmOS, a proprietary software product engineered and operated by TriVergeTech Private Limited ("TriVergeTech", "Company", "we", "us", or "our").

Effective Date: January 1, 2026
Entity: TriVergeTech Private Limited (India)
Standard: Zero Third-Party Advertising Trackers
NO SURVEILLANCE & NO THIRD-PARTY ADVERTISING TRACKINGCAFIRMOS IS A SECURE ENTERPRISE PRACTICE PLATFORM FOR CHARTERED ACCOUNTANTS. WE DO NOT DEPLOY CROSS-SITE RETARGETING PIXELS, BEHAVIORAL PROFILING SCRIPTS, OR ADVERTISING IDENTIFIERS. COOKIES AND LOCAL WEB STORAGE ARE UTILIZED STRICTLY TO MAINTAIN ENCRYPTED USER SESSIONS, PRESERVE APPLICATION WORKFLOW DRAFTS, PREVENT CROSS-SITE ATTACKS (CSRF), AND ENSURE TENANT ISOLATION.
01

Preamble, Corporate Standing & Statutory Scope

1.1. Corporate Entity: This Cookie and Web Storage Policy ("Policy") is issued by TriVergeTech Private Limited, an incorporated technology entity under the Companies Act, 2013, with corporate offices in India ("TriVergeTech", "Company", "We", "Us", or "Our").

1.2. Product Relation: CAfirmOS ("CAfirmOS", "Software", "System", or "Platform") is a proprietary practice management software-as-a-service (SaaS) platform engineered, owned, and operated by TriVergeTech Private Limited for professional Chartered Accountants, auditors, tax practitioners, and corporate accounting consortiums.

1.3. Regulatory Compliance: This Policy explains how and why cookies, pixel tags, web beacons, and browser-side storage objects (HTML5 LocalStorage, SessionStorage, IndexedDB) are utilized across CAfirmOS in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and global telemetry guidelines.


02

Technical Definitions: Cookies & Storage Technologies

In this Policy, technical terms have the following established meanings:

  • "Cookies" refers to small alphanumeric text files placed on your browser or hard drive by web servers to uniquely identify your session, preserve cryptographic security state, and maintain user preferences.
  • "Session Cookies" are temporary memory objects that persist only during an active browser session and are automatically expunged when you log out or terminate the browser.
  • "Persistent Cookies" are secure tokens that remain stored across multiple browser sessions until an explicit expiration date or until manual clearance, used to remember firm tenant identifiers or UI view settings.
  • "HTML5 Web Storage" encompasses browser-level key-value datastores (localStorage and sessionStorage) that allow large structured client-side caching of offline draft workpapers without transmitting data in HTTP request headers.

03

Strict Necessity vs. Consent under Indian Law

3.1. Strictly Necessary Exemption: In alignment with Section 4 and Section 7 of the DPDP Act, 2023, cookies and storage tokens that are technically essential to provision the digital service requested by the user (such as authentication verification, tenant routing, and cryptographic encryption) do not require prior opt-in consent because the service cannot function securely in their absence.

3.2. Optional Functional Enhancements: Non-essential functional preferences (such as collapsed sidebar state or active calendar viewing modes) are stored locally on your device and can be cleared at your discretion without terminating your account.


04

Core Classifications of Cookies Utilized

1. Strictly Necessary

Essential for authentication, secure multi-tenant boundary isolation, session keep-alive, and protection against unauthorized credential replay attacks.

2. Functional & Preference

Maintains UI personalization, such as active dashboard filters, task layout view (Kanban vs. Table), and client reconciliation preferences.

3. Diagnostics & Telemetry

Anonymized technical metrics (API latency, uncaught JavaScript errors, network packet drops) used exclusively to maintain our 99.9% uptime SLA.


05

The Zero Ad-Tracking & Anti-Surveillance Covenant

ABSOLUTE BAN ON THIRD-PARTY ADVERTISING NETWORKSTriVergeTech warrants that CAfirmOS does NOT embed advertising tracking scripts, Facebook Pixel, Google AdSense, behavioral data brokers, or cross-app tracking SDKs. We do not monetize user attention or sell advertising space.

Your firm's login activity, client lists, tax filings, and document intake sessions are strictly shielded from public commercial ad networks.


06

Detailed Technical Cookie & Storage Inventory

Below is the exhaustive inventory of first-party technical cookies and tokens deployed on CAfirmOS:

Cookie / Token KeyClassificationOperational PurposeLifespan
caos_auth_tokenStrictly NecessaryEncrypted JWT bearer token verifying authenticated partner / staff sessionSession / 7 Days
caos_tenant_idStrictly NecessaryEnsures database multi-tenant isolation and prevents cross-firm data accessPersistent (30 Days)
caos_csrf_tokenSecurityCryptographic anti-CSRF token protecting against cross-site form tamperingSession
caos_ui_prefsFunctionalStores user interface preferences (table row density, active calendar filters)Persistent (1 Year)

07

HTML5 Web Storage (LocalStorage & IndexedDB)

7.1. Local Storage Objects: Unlike legacy cookies, modern web applications utilize HTML5 localStorage to store client-side draft buffers (e.g., auto-saved tax notes, unfinished GSTR-2B match filters, or offline UI state) directly on your device.

7.2. Zero Remote Leakage: Data maintained inside HTML5 Web Storage is sandboxed strictly to the origin domain (cafirmos.com) and is never transmitted automatically to third-party endpoints.


08

Cryptographic CSRF Tokens & Session Integrity

8.1. SameSite & Secure Flags: All session cookies set by CAfirmOS backend clusters enforce SameSite=Strict (or SameSite=Lax where necessary for API handshakes) and mandatory Secure flags, ensuring cookies are transmitted exclusively over encrypted HTTPS connections.

8.2. HttpOnly Enforcement: Sensitive session tokens are protected via the HttpOnly attribute, rendering them inaccessible to client-side scripts and neutralizing cross-site scripting (XSS) session hijacking risks.


09

Infrastructure Telemetry & Diagnostic Logging

9.1. Uptime & Latency Monitoring: To ensure our 99.9% uptime SLA, our servers collect aggregate, pseudonymous diagnostic data regarding API response times and fatal JavaScript crashes.

9.2. No Personal Tax Data in Logs: Crash reporting pipelines are programmatically scrubbed to prevent Permanent Account Numbers (PAN), Aadhaar numbers, client bank balances, or confidential ledger entries from entering diagnostic logging buckets.


10

Sovereign Domestic Processing & Storage Bounds

All server-side telemetry endpoints and session storage databases are hosted in Tier-IV enterprise cloud facilities located strictly within the Republic of India (Mumbai and Hyderabad regions), in strict compliance with the sovereign data residency directives of the DPDP Act, 2023.


11

User Empowerment: How to Manage & Delete Cookies

You retain full autonomy to inspect, restrict, or purge cookies through your browser settings:

  • Google Chrome: Navigate to Settings > Privacy and Security > Third-party cookies to view, block, or delete cookies.
  • Apple Safari: Navigate to Settings > Safari > Advanced > Privacy > Block All Cookies.
  • Microsoft Edge: Navigate to Settings > Cookies and site permissions > Manage and delete cookies.
  • Mozilla Firefox: Navigate to Options > Privacy & Security > Cookies and Site Data > Clear Data.

12

Technical Ramifications of Disabling Essential Cookies

IMPORTANT OPERATIONAL NOTICEBecause CAfirmOS uses cookies strictly for authentication and tenant isolation, disabling strictly necessary cookies will immediately prevent you from logging into your firm dashboard, loading client documents, or performing statutory e-filing actions.

13

Do Not Track (DNT) & Global Privacy Control (GPC)

While no universal commercial standard exists for Do Not Track (DNT) browser signals, CAfirmOS inherently complies with the core principles of Global Privacy Control (GPC) by maintaining a permanent, non-negotiable ban on cross-site profiling and third-party advertising trackers.


14

Policy Audits, Amendments & Statutory Contact Details

TriVergeTech conducts bi-annual technical audits of all browser storage keys and telemetry payloads. Revisions are published on this page with updated statutory version references.

Office of Data Protection & Information Security
Operating Entity: TriVergeTech Private Limited
Product: CAfirmOS Practice Management Suite
Compliance Desk: Privacy & Regulatory Affairs Division
Cookie & Data Protection Desk: grevance@cafirmos.com
Corporate Office: TriVergeTech Private Limited, Connaught Place, New Delhi 110001, India

All technical inquiries regarding browser data storage are addressed by our engineering and security team within forty-eight (48) working hours.