Cookies Policy
Last updated: 11 July 2026
This policy explains every cookie and similar technology Vtag uses on getvtag.com and the Vtag dashboard, why, how long each one lasts, and how to control them. It supplements our Privacy Policy, which covers personal data more broadly.
On this page
1. What this policy covers2. What a cookie is3. Strictly necessary / authentication cookies4. Security cookies5. Functional cookies & local storage6. Analytics7. Marketing & advertising cookies8. The Public Scanner device fingerprint (not a cookie)9. Third-party cookies during payment10. Retention periods at a glance11. Consent management12. Browser controls13. Do Not Track signals14. Legal compliance15. Children16. Changes to this policy17. Contact us1. What this policy covers
"Cookies" here means actual browser cookies and any comparable technology that stores or reads information on your device — including local storage. Where we use a technology that looks similar but works differently, like the device signal described in Section 8, we say so explicitly rather than lumping it in with cookies for convenience.
2. What a cookie is
A cookie is a small text file a website asks your browser to store, then reads back on later visits — for example, to remember that you're logged in, or to count how many people visited a page. Cookies can be first-party (set by the site you're on, here, getvtag.com) or third-party (set by another domain a page loads content from, like a payment provider's checkout script).
3. Strictly necessary / authentication cookies
When you log in, we set a session cookie (prefixed sb-) that keeps you signed in as you move between pages and the dashboard. This cookie is essential to the Service — without it, you'd have to re-authenticate on every page load — so it is set automatically and cannot be individually opted out of while remaining logged in. It is refreshed automatically while you're active and cleared when you log out.
4. Security cookies
We use Cloudflare Turnstile to tell human visitors apart from bots on our OTP and scanner verification flows, without the intrusive puzzle-based CAPTCHAs older tools use. Turnstile sets its own short-lived challenge cookie, under Cloudflare's domain rather than ours, purely to complete that one verification — see Cloudflare's own documentation for exactly how long it persists, since we don't control that directly. We use this only where genuinely necessary for fraud prevention (OTP requests, scanner verification), never to track you across the rest of the site.
5. Functional cookies & local storage
We use local storage (not a cookie, but a similar on-device technology) for lightweight preferences that make the site nicer to use — for example, remembering a light/dark theme choice or an in-progress form. This data stays on your device, is never transmitted to our servers as part of a request unless it's functionally required (like submitting the form itself), and is cleared if you clear your browser's site data.
6. Analytics
We use Plausible Analytics, which by design does not use cookies and does not collect data that identifies you individually — it reports aggregate counts (page views, referrers, device type) without a persistent identifier tied to your browser. We disclose it here for transparency even though, strictly speaking, it falls outside what a cookie policy needs to cover. Full detail is in our Privacy Policy Section 7.
7. Marketing & advertising cookies
We don't use any
No advertising cookies, no retargeting pixels, no cross-site tracking, and no cookie-based audience-building for any ad platform. If you receive Vtag marketing communications, that's governed by opt-in consent under our Privacy Policy Section 5, not by a tracking cookie.
8. The Public Scanner device fingerprint (not a cookie)
On the Public Scanner Portal, we compute a hashed device fingerprint from characteristics your browser already exposes (things like screen and device properties), fresh, each time it's needed. This is deliberately notwritten to a cookie or to local storage on your device — nothing persists client-side. We send the computed hash to our servers, where it's matched against a short-lived trusted-session record to decide whether you need to re-verify by OTP. Full detail, including how long that server-side record lasts, is in our Public Scanner & Emergency Alert Terms. We describe it here, separately from the cookie table in Section 10, because conflating a computed device signal with an actual cookie would be inaccurate — the two are similar in purpose but different in mechanism, and we'd rather be precise than convenient.
9. Third-party cookies during payment
When you check out, our payment processor Razorpay loads its own checkout interface, which may set cookies under Razorpay's own domain for fraud prevention and to complete your payment session. These are set and controlled by Razorpay, not by Vtag, and are active only during an active checkout. See Razorpay's own privacy and cookie disclosures for detail on what they set.
10. Retention periods at a glance
| Cookie | Set by | Purpose | Typical duration |
|---|---|---|---|
Session cookie (sb-*) | Vtag (first-party) | Keep you logged in | Duration of your session, refreshed while active; cleared on logout |
| Turnstile challenge cookie | Cloudflare (third-party) | Bot/human verification | Short-lived, set per Cloudflare's own policy |
| Razorpay checkout cookie | Razorpay (third-party) | Payment fraud prevention | Duration of checkout, set per Razorpay's own policy |
| Theme / form preference | Vtag (local storage, first-party) | Remember your preference | Until you clear browser site data |
Plausible Analytics and the Section 8 device fingerprint aren't in this table because neither is a cookie — see those sections for how each actually works.
11. Consent management
We don't show a cookie-consent banner today. That's a deliberate choice given what we actually use, not an oversight: every cookie in Section 10 is either strictly necessary to provide the Service you've asked for (login, fraud prevention during checkout and verification) or a first-party preference you control through your own browser. We don't use the category — advertising and non-essential tracking cookies — that legal frameworks like India's DPDP Act and the EU's ePrivacy rules are principally concerned with gating behind consent. If that changes — if we ever introduce a marketing or advertising cookie — we will build a proper consent mechanism before we do, not after, consistent with the GDPR-readiness commitment in our Privacy Policy Section 17.
12. Browser controls
You can view, block, or delete cookies directly through your browser's settings — typically under Privacy & Security, or Site Settings for a specific site like getvtag.com. This works the same way for any website, not just Vtag: Chrome, Firefox, Safari, and Edge all offer a way to clear cookies for one site or all sites, and to block third-party cookies globally.
Blocking the session cookie will log you out
Since the sb-*cookie in Section 3 is how the dashboard knows you're logged in, blocking or deleting it — or blocking first-party cookies for getvtag.com entirely — will sign you out and prevent you from logging back in until you allow it again. The Public Scanner Portal itself doesn't depend on this cookie, since Scanners don't hold accounts.
13. Do Not Track signals
Some browsers send a "Do Not Track" (DNT) signal. There's no single legal or technical standard defining what a website must do in response, and we don't currently change our behaviour based on it — in practice this makes little difference either way, since we don't deploy tracking or advertising cookies regardless of the DNT setting your browser sends.
14. Legal compliance
We process cookie-related data consistently with the DPDP Act, 2023, as described in our Privacy Policy. Where a cookie involves a cross-border transfer (for example, to Cloudflare or Razorpay's infrastructure), that transfer is covered by the same DPDP Act analysis in our Privacy Policy Section 9. Our current cookie mix — strictly necessary and first-party functional cookies only, no marketing or advertising cookies — would not require consent-banner-gated opt-in even under the EU's stricter ePrivacy framework, since that framework's consent requirement is specifically aimed at non-essential tracking cookies, which we don't use.
15. Children
We don't knowingly direct any cookie described here at, or use it to build a profile of, a child under 18 — consistent with our Privacy Policy Section 13.
16. Changes to this policy
If we add a new category of cookie — particularly any marketing or advertising cookie — we will update this policy first, build the consent mechanism described in Section 11, and post a new "Last updated" date here.
17. Contact us
Questions about this policy: email grievance@getvtag.com.