Cookie & Tracking Policy
Effective Date: 2026-07-28
Platform: SAVHN AgencyOS · https://agencyos.savhn.in
Contact: legal@savhn.in
Legal Notice: This document reflects the actual cookies and local storage mechanisms used by SAVHN AgencyOS. Review by qualified legal counsel is required before publication.
1. Overview & Scope
This Cookie & Tracking Policy explains how SAVHN AgencyOS ("we", "us") uses cookies, browser localStorage, sessionStorage, and related tracking technologies when you access or use the Platform at https://agencyos.savhn.in.
SAVHN AgencyOS is an enterprise B2B platform. We use only the minimum tracking mechanisms necessary to operate the Platform securely and deliver a personalized, role-appropriate experience. We do not use advertising cookies, third-party behavioral tracking pixels, or sell tracking data.
2. What Are Cookies?
Cookies are small text files placed on your device by a web server. They enable the server to recognize your browser on subsequent visits. SAVHN AgencyOS also uses browser localStorage and sessionStorage for client-side state persistence where cookies are not appropriate (e.g., large UI preferences).
3. Cookies We Use
3.1 Strictly Necessary (Authentication & Security)
These cookies are required for the Platform to function. They cannot be disabled without preventing login.
| Cookie Name | Purpose | Duration |
|---|---|---|
jwt_token |
Stores your encrypted JSON Web Token for session authentication. Contains your role, organization ID, and email (encrypted). | Session / 7 days (if "Remember Me" is selected) |
session_id |
Server-side session identifier used alongside the JWT for double-layer session integrity. | Session |
csrf_token |
Cross-Site Request Forgery prevention token. Verified on every state-changing API request. | Session |
device_trust_id |
Identifies trusted devices for Admin and Super Admin sessions to reduce re-authentication frequency. | 30 days |
auth_portal |
Records which login portal was used (superadmin / admin / employee) to route the user correctly after authentication. | Session |
3.2 Functional / Preference Cookies
These cookies remember your UI preferences and workspace state.
| Cookie / Storage Key | Purpose | Duration |
|---|---|---|
theme_mode (localStorage) |
Stores your selected UI theme (Midnight Obsidian, Cyberpunk Glass, Royal Emerald, etc.) | Persistent (1 year) |
sidebar_collapsed (localStorage) |
Remembers whether the sidebar navigation is expanded or collapsed. | Persistent (1 year) |
currency_preference (localStorage) |
Your selected display currency from the 160+ supported currencies (e.g., USD, EUR, INR). | Persistent (1 year) |
accent_color (localStorage) |
Custom accent color selected in User Settings. | Persistent (1 year) |
density_mode (localStorage) |
UI density setting (Comfortable / Compact / Airy). | Persistent (1 year) |
notif_dismissed (sessionStorage) |
Tracks which in-app notification banners you have dismissed during this session. | Session |
quick_chat_open (sessionStorage) |
Remembers whether the floating quick-chat panel was open when you last navigated. | Session |
kanban_view (sessionStorage) |
Your last-selected Kanban view mode (Board / Table / Gantt) per project. | Session |
3.3 Operational / Analytics (First-Party Only)
We collect limited, first-party analytics to improve platform performance. No third-party analytics scripts (Google Analytics, Mixpanel, etc.) are loaded.
| Data Collected | Purpose | Retention |
|---|---|---|
| API response latency per route | Identify slow queries and backend bottlenecks. | 30 days, then aggregated |
| Feature interaction counts (anonymized) | Understand which modules are most used to prioritize development. | 90 days |
| Error stack traces (anonymized) | Automated bug detection and resolution. | 30 days |
| Browser type & OS (aggregated) | Ensure cross-browser compatibility. | 90 days, aggregated only |
IP addresses associated with analytics events are anonymized (last octet removed) within 24 hours of collection.
4. Third-Party Cookies From Integrations
When your Super Admin enables optional third-party integrations, those services may set their own cookies. SAVHN AgencyOS does not control these cookies.
| Integration | Cookie Source | Their Policy |
|---|---|---|
| Google Meet (Scheduled Reviews) | Google LLC | policies.google.com |
| Zoom (Scheduled Reviews) | Zoom Video Communications | zoom.us/privacy |
| Stripe (Billing Portal) | Stripe Inc. | stripe.com/privacy |
| Razorpay (Payment Processing) | Razorpay Software Pvt. Ltd. | razorpay.com/privacy |
These integrations are enabled only if your organization has explicitly connected them in Super Admin → Settings → Integrations.
5. Focus Sessions & Screen Capture
Focus Sessions do not use cookies. Screen capture is handled via the browser's native getDisplayMedia() Screen Capture API, which:
- Requires an explicit, unavoidable OS-level permission prompt the user must accept
- Shows a persistent OS-level indicator that screen sharing is active throughout the session
- Does not capture data silently or in the background
- Only captures when the employee has actively started a session
Screenshots are stored server-side under the employee's account and are never processed by cookie-based mechanisms.
6. Attendance & GPS Tracking
GPS geo-fenced attendance check-in is an opt-in feature controlled by the Customer (Super Admin). When enabled:
- Location coordinates are captured at clock-in time only (not continuously tracked)
- Coordinates are stored as part of the attendance record, visible to the employee and authorized managers
- Location capture uses the browser's
navigator.geolocationAPI, which requires explicit browser permission - No background location tracking occurs
7. What We Do NOT Do
- ❌ We do not use advertising or retargeting cookies
- ❌ We do not load Google Analytics, Facebook Pixel, or similar third-party behavioral trackers
- ❌ We do not perform cross-site tracking
- ❌ We do not sell, rent, or share cookie or tracking data with advertisers
- ❌ We do not fingerprint browsers for cross-session re-identification
- ❌ We do not capture keystrokes, clipboard content, or application-level activity
8. Managing Cookies
Browser Controls
You can manage, restrict, or delete cookies through your browser settings:
- Chrome: Settings → Privacy & Security → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy → Manage Website Data
- Edge: Settings → Privacy, search, and services → Cookies
Important: Disabling strictly necessary cookies (Section 3.1) will prevent you from logging into SAVHN AgencyOS. Functional cookies can be cleared safely; your preferences will reset to defaults.
In-Platform Controls
- Theme and display preferences: User Settings → Appearance
- Currency preference: Currency Selector (top navigation bar)
- Integration cookies: Super Admin → Settings → Integrations (disable integration to remove its cookies)
9. Cookie Policy Updates
When we make material changes to this Policy, we will update the Effective Date and notify logged-in users via an in-platform banner. Continued use of the Platform after the effective date constitutes acceptance.
10. Contact
For questions about this Cookie Policy:
Email: legal@savhn.in
Platform: https://agencyos.savhn.in
Last Updated: 2026-07-28
Document Version: 3.0 (Platform-Specific)