🍪Legal & Security

Cookie & Tracking Policy

Every cookie, local storage key, and tracking mechanism we use — and why.

Version 1 · Effective 28 July 2026

🍪Cookie & Tracking Policy
Published v1

Cookie & Tracking Policy

Effective Date: 2026-07-28
Platform: SAVHN AgencyOS · https://agencyos.savhn.in
Contact: legal@savhn.in


Legal Notice: This document reflects the actual cookies and local storage mechanisms used by SAVHN AgencyOS. Review by qualified legal counsel is required before publication.


1. Overview & Scope

This Cookie & Tracking Policy explains how SAVHN AgencyOS ("we", "us") uses cookies, browser localStorage, sessionStorage, and related tracking technologies when you access or use the Platform at https://agencyos.savhn.in.

SAVHN AgencyOS is an enterprise B2B platform. We use only the minimum tracking mechanisms necessary to operate the Platform securely and deliver a personalized, role-appropriate experience. We do not use advertising cookies, third-party behavioral tracking pixels, or sell tracking data.


2. What Are Cookies?

Cookies are small text files placed on your device by a web server. They enable the server to recognize your browser on subsequent visits. SAVHN AgencyOS also uses browser localStorage and sessionStorage for client-side state persistence where cookies are not appropriate (e.g., large UI preferences).


3. Cookies We Use

3.1 Strictly Necessary (Authentication & Security)

These cookies are required for the Platform to function. They cannot be disabled without preventing login.

Cookie Name Purpose Duration
jwt_token Stores your encrypted JSON Web Token for session authentication. Contains your role, organization ID, and email (encrypted). Session / 7 days (if "Remember Me" is selected)
session_id Server-side session identifier used alongside the JWT for double-layer session integrity. Session
csrf_token Cross-Site Request Forgery prevention token. Verified on every state-changing API request. Session
device_trust_id Identifies trusted devices for Admin and Super Admin sessions to reduce re-authentication frequency. 30 days
auth_portal Records which login portal was used (superadmin / admin / employee) to route the user correctly after authentication. Session

3.2 Functional / Preference Cookies

These cookies remember your UI preferences and workspace state.

Cookie / Storage Key Purpose Duration
theme_mode (localStorage) Stores your selected UI theme (Midnight Obsidian, Cyberpunk Glass, Royal Emerald, etc.) Persistent (1 year)
sidebar_collapsed (localStorage) Remembers whether the sidebar navigation is expanded or collapsed. Persistent (1 year)
currency_preference (localStorage) Your selected display currency from the 160+ supported currencies (e.g., USD, EUR, INR). Persistent (1 year)
accent_color (localStorage) Custom accent color selected in User Settings. Persistent (1 year)
density_mode (localStorage) UI density setting (Comfortable / Compact / Airy). Persistent (1 year)
notif_dismissed (sessionStorage) Tracks which in-app notification banners you have dismissed during this session. Session
quick_chat_open (sessionStorage) Remembers whether the floating quick-chat panel was open when you last navigated. Session
kanban_view (sessionStorage) Your last-selected Kanban view mode (Board / Table / Gantt) per project. Session

3.3 Operational / Analytics (First-Party Only)

We collect limited, first-party analytics to improve platform performance. No third-party analytics scripts (Google Analytics, Mixpanel, etc.) are loaded.

Data Collected Purpose Retention
API response latency per route Identify slow queries and backend bottlenecks. 30 days, then aggregated
Feature interaction counts (anonymized) Understand which modules are most used to prioritize development. 90 days
Error stack traces (anonymized) Automated bug detection and resolution. 30 days
Browser type & OS (aggregated) Ensure cross-browser compatibility. 90 days, aggregated only

IP addresses associated with analytics events are anonymized (last octet removed) within 24 hours of collection.


4. Third-Party Cookies From Integrations

When your Super Admin enables optional third-party integrations, those services may set their own cookies. SAVHN AgencyOS does not control these cookies.

Integration Cookie Source Their Policy
Google Meet (Scheduled Reviews) Google LLC policies.google.com
Zoom (Scheduled Reviews) Zoom Video Communications zoom.us/privacy
Stripe (Billing Portal) Stripe Inc. stripe.com/privacy
Razorpay (Payment Processing) Razorpay Software Pvt. Ltd. razorpay.com/privacy

These integrations are enabled only if your organization has explicitly connected them in Super Admin → Settings → Integrations.


5. Focus Sessions & Screen Capture

Focus Sessions do not use cookies. Screen capture is handled via the browser's native getDisplayMedia() Screen Capture API, which:

  • Requires an explicit, unavoidable OS-level permission prompt the user must accept
  • Shows a persistent OS-level indicator that screen sharing is active throughout the session
  • Does not capture data silently or in the background
  • Only captures when the employee has actively started a session

Screenshots are stored server-side under the employee's account and are never processed by cookie-based mechanisms.


6. Attendance & GPS Tracking

GPS geo-fenced attendance check-in is an opt-in feature controlled by the Customer (Super Admin). When enabled:

  • Location coordinates are captured at clock-in time only (not continuously tracked)
  • Coordinates are stored as part of the attendance record, visible to the employee and authorized managers
  • Location capture uses the browser's navigator.geolocation API, which requires explicit browser permission
  • No background location tracking occurs

7. What We Do NOT Do

  • ❌ We do not use advertising or retargeting cookies
  • ❌ We do not load Google Analytics, Facebook Pixel, or similar third-party behavioral trackers
  • ❌ We do not perform cross-site tracking
  • ❌ We do not sell, rent, or share cookie or tracking data with advertisers
  • ❌ We do not fingerprint browsers for cross-session re-identification
  • ❌ We do not capture keystrokes, clipboard content, or application-level activity

8. Managing Cookies

Browser Controls

You can manage, restrict, or delete cookies through your browser settings:

  • Chrome: Settings → Privacy & Security → Cookies and other site data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data
  • Safari: Preferences → Privacy → Manage Website Data
  • Edge: Settings → Privacy, search, and services → Cookies

Important: Disabling strictly necessary cookies (Section 3.1) will prevent you from logging into SAVHN AgencyOS. Functional cookies can be cleared safely; your preferences will reset to defaults.

In-Platform Controls

  • Theme and display preferences: User Settings → Appearance
  • Currency preference: Currency Selector (top navigation bar)
  • Integration cookies: Super Admin → Settings → Integrations (disable integration to remove its cookies)

9. Cookie Policy Updates

When we make material changes to this Policy, we will update the Effective Date and notify logged-in users via an in-platform banner. Continued use of the Platform after the effective date constitutes acceptance.


10. Contact

For questions about this Cookie Policy:
Email: legal@savhn.in
Platform: https://agencyos.savhn.in

Last Updated: 2026-07-28
Document Version: 3.0 (Platform-Specific)

Last published: 28 July 2026

Questions? Contact legal@savhn.in →