Cookie Policy
1. Scope
This policy applies to cookies and similar technologies (local storage, pixels, SDKs) used on flostac.in (the marketing website) and app.flostac.in (the Flostac web application). For how we handle personal data inside your workspace, see our Privacy Policy.
2. Cookies we use
We use only the cookies strictly necessary to operate the service, plus one optional preference cookie. We do not run advertising or third-party analytics trackers.
Strictly necessary
- Session — keeps you signed in to app.flostac.in. First-party, HTTP-only, expires on logout or browser close.
- CSRF token — protects cross-site request forgery on form submissions. First-party, HTTP-only.
Functional
- Theme preference — remembers your light or dark choice on flostac.in. Optional; the site falls back to your system preference if you decline it.
Analytics
We do not use third-party analytics (no Google Analytics, no Meta Pixel, no Mixpanel, no PostHog) on either domain. If we add analytics, we will update this policy and seek consent where required.
Advertising
We do not run advertising trackers on either domain.
3. How to control cookies
- Use your browser's privacy settings to block or delete cookies.
- Use private / incognito mode (cookies reset when the window closes).
- On app.flostac.in, signing out clears the session cookie.
Blocking strictly necessary cookies will prevent login. Blocking the theme-preference cookie only removes that preference.
4. Do Not Track and Global Privacy Control
Flostac honours the Do Not Track browser signal and the Global Privacy Control header. Because we do not use third-party trackers, the signals do not change behaviour today; if we add tracking later, we will respect them.
5. Changes to this policy
If we add, remove, or change any non-essential cookies, we will update this page and revise the “Last updated” date above. Where consent is required, we will request it before the change takes effect.