Preamble, Corporate Standing & Statutory Scope
1.1. Corporate Entity: This Cookie and Web Storage Policy ("Policy") is issued by TriVergeTech Private Limited, an incorporated technology entity under the Companies Act, 2013, with corporate offices in India ("TriVergeTech", "Company", "We", "Us", or "Our").
1.2. Product Relation: CAfirmOS ("CAfirmOS", "Software", "System", or "Platform") is a proprietary practice management software-as-a-service (SaaS) platform engineered, owned, and operated by TriVergeTech Private Limited for professional Chartered Accountants, auditors, tax practitioners, and corporate accounting consortiums.
1.3. Regulatory Compliance: This Policy explains how and why cookies, pixel tags, web beacons, and browser-side storage objects (HTML5 LocalStorage, SessionStorage, IndexedDB) are utilized across CAfirmOS in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and global telemetry guidelines.
Technical Definitions: Cookies & Storage Technologies
In this Policy, technical terms have the following established meanings:
- "Cookies" refers to small alphanumeric text files placed on your browser or hard drive by web servers to uniquely identify your session, preserve cryptographic security state, and maintain user preferences.
- "Session Cookies" are temporary memory objects that persist only during an active browser session and are automatically expunged when you log out or terminate the browser.
- "Persistent Cookies" are secure tokens that remain stored across multiple browser sessions until an explicit expiration date or until manual clearance, used to remember firm tenant identifiers or UI view settings.
- "HTML5 Web Storage" encompasses browser-level key-value datastores (
localStorageandsessionStorage) that allow large structured client-side caching of offline draft workpapers without transmitting data in HTTP request headers.
Strict Necessity vs. Consent under Indian Law
3.1. Strictly Necessary Exemption: In alignment with Section 4 and Section 7 of the DPDP Act, 2023, cookies and storage tokens that are technically essential to provision the digital service requested by the user (such as authentication verification, tenant routing, and cryptographic encryption) do not require prior opt-in consent because the service cannot function securely in their absence.
3.2. Optional Functional Enhancements: Non-essential functional preferences (such as collapsed sidebar state or active calendar viewing modes) are stored locally on your device and can be cleared at your discretion without terminating your account.
Core Classifications of Cookies Utilized
Essential for authentication, secure multi-tenant boundary isolation, session keep-alive, and protection against unauthorized credential replay attacks.
Maintains UI personalization, such as active dashboard filters, task layout view (Kanban vs. Table), and client reconciliation preferences.
Anonymized technical metrics (API latency, uncaught JavaScript errors, network packet drops) used exclusively to maintain our 99.9% uptime SLA.
The Zero Ad-Tracking & Anti-Surveillance Covenant
Your firm's login activity, client lists, tax filings, and document intake sessions are strictly shielded from public commercial ad networks.
Detailed Technical Cookie & Storage Inventory
Below is the exhaustive inventory of first-party technical cookies and tokens deployed on CAfirmOS:
| Cookie / Token Key | Classification | Operational Purpose | Lifespan |
|---|---|---|---|
| caos_auth_token | Strictly Necessary | Encrypted JWT bearer token verifying authenticated partner / staff session | Session / 7 Days |
| caos_tenant_id | Strictly Necessary | Ensures database multi-tenant isolation and prevents cross-firm data access | Persistent (30 Days) |
| caos_csrf_token | Security | Cryptographic anti-CSRF token protecting against cross-site form tampering | Session |
| caos_ui_prefs | Functional | Stores user interface preferences (table row density, active calendar filters) | Persistent (1 Year) |
HTML5 Web Storage (LocalStorage & IndexedDB)
7.1. Local Storage Objects: Unlike legacy cookies, modern web applications utilize HTML5 localStorage to store client-side draft buffers (e.g., auto-saved tax notes, unfinished GSTR-2B match filters, or offline UI state) directly on your device.
7.2. Zero Remote Leakage: Data maintained inside HTML5 Web Storage is sandboxed strictly to the origin domain (cafirmos.com) and is never transmitted automatically to third-party endpoints.
Cryptographic CSRF Tokens & Session Integrity
8.1. SameSite & Secure Flags: All session cookies set by CAfirmOS backend clusters enforce SameSite=Strict (or SameSite=Lax where necessary for API handshakes) and mandatory Secure flags, ensuring cookies are transmitted exclusively over encrypted HTTPS connections.
8.2. HttpOnly Enforcement: Sensitive session tokens are protected via the HttpOnly attribute, rendering them inaccessible to client-side scripts and neutralizing cross-site scripting (XSS) session hijacking risks.
Infrastructure Telemetry & Diagnostic Logging
9.1. Uptime & Latency Monitoring: To ensure our 99.9% uptime SLA, our servers collect aggregate, pseudonymous diagnostic data regarding API response times and fatal JavaScript crashes.
9.2. No Personal Tax Data in Logs: Crash reporting pipelines are programmatically scrubbed to prevent Permanent Account Numbers (PAN), Aadhaar numbers, client bank balances, or confidential ledger entries from entering diagnostic logging buckets.
Sovereign Domestic Processing & Storage Bounds
All server-side telemetry endpoints and session storage databases are hosted in Tier-IV enterprise cloud facilities located strictly within the Republic of India (Mumbai and Hyderabad regions), in strict compliance with the sovereign data residency directives of the DPDP Act, 2023.
User Empowerment: How to Manage & Delete Cookies
You retain full autonomy to inspect, restrict, or purge cookies through your browser settings:
- Google Chrome: Navigate to
Settings > Privacy and Security > Third-party cookiesto view, block, or delete cookies. - Apple Safari: Navigate to
Settings > Safari > Advanced > Privacy > Block All Cookies. - Microsoft Edge: Navigate to
Settings > Cookies and site permissions > Manage and delete cookies. - Mozilla Firefox: Navigate to
Options > Privacy & Security > Cookies and Site Data > Clear Data.
Technical Ramifications of Disabling Essential Cookies
Do Not Track (DNT) & Global Privacy Control (GPC)
While no universal commercial standard exists for Do Not Track (DNT) browser signals, CAfirmOS inherently complies with the core principles of Global Privacy Control (GPC) by maintaining a permanent, non-negotiable ban on cross-site profiling and third-party advertising trackers.
Policy Audits, Amendments & Statutory Contact Details
TriVergeTech conducts bi-annual technical audits of all browser storage keys and telemetry payloads. Revisions are published on this page with updated statutory version references.
All technical inquiries regarding browser data storage are addressed by our engineering and security team within forty-eight (48) working hours.