Cookie Policy
Last updated: May 28, 2026
1. Introduction
This Cookie Policy explains how CA Friend ("we", "us", "our") uses cookies and similar tracking technologies on https://cafriend.in and the CA Friend platform. It is published in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and good privacy practice.
2. What are cookies?
Cookies are small text files placed on your device by your browser when you visit a website. They are widely used to make websites work, to make them work efficiently, and to provide information to site owners. Similar technologies include localStorage, sessionStorage, pixels, and device fingerprints.
Cookies set by us are first-party cookies. Cookies set by third parties (such as analytics providers) on our domain are third-party cookies.
3. Why we use cookies
We use cookies for:
- Authentication and session management.
- Security (e.g., detecting CSRF, account takeover attempts).
- Preferences (e.g., your theme, language).
- Anonymous usage analytics to improve the product.
- Optional marketing analytics — only with your explicit consent.
4. Cookie categories
a) Strictly necessary cookies
Required for the platform to operate. Includes session ID, CSRF token, refresh token cookies. These cannot be disabled. Without them you cannot sign in or use the platform.
b) Functional cookies
Remember preferences such as your selected theme (light/dark), language, and last-visited tenant slug. These improve usability but are not strictly required.
c) Analytics cookies
Help us understand how the platform is used (page views, feature adoption, error rates). We use first-party analytics by default. If you opt in, we may also use Google Analytics; we use IP anonymisation and short retention periods.
d) Marketing cookies
Used only with explicit opt-in consent and only on our public marketing pages (not inside the authenticated app). We use these to measure campaign effectiveness and to suppress repeat impressions.
5. Your controls
You have the following controls:
- The Cookie Consent Banner at the bottom of the marketing site lets you accept all, reject non-essential, or customise per category.
- You may change your choice anytime via the "Cookie preferences" link in the footer.
- You can also block or delete cookies through your browser settings — note that disabling strictly necessary cookies will prevent the platform from functioning.
- For Google Analytics specifically, you may install the Google Analytics opt-out browser add-on at tools.google.com/dlpage/gaoptout.
6. DPDP-specific notes
Under the DPDP Act, we treat cookie-driven analytics and marketing identifiers as personal data when they can be linked to an identified or identifiable individual. We rely on your consent (Section 6) for non-essential cookies, and on the lawful basis of performance of contract for strictly necessary cookies. You may withdraw consent at any time without affecting prior lawful processing.
7. Retention
Cookies are set with the following typical lifetimes:
- Session cookies — until you close your browser.
- Authentication refresh tokens — up to 30 days from last use.
- Theme/preference cookies — up to 1 year.
- Analytics cookies — up to 13 months.
- Marketing cookies — up to 90 days unless renewed.
8. Updates to this policy
We may update this Cookie Policy as our cookies or applicable law change. The "Last updated" date above reflects the most recent change. Material updates will be highlighted on the cookie consent banner.
9. Contact
Questions about cookies and tracking technologies?
CA Friend — Office of the DPO
Email: dpo@cafriend.in