Cookie Policy

Last updated: July 18, 2026

This is a genuinely complete, itemized list of what CapitalSync sets in your browser — not a generic template listing categories of cookies we don't actually use. As of this writing, we set exactly one first-party cookie.

1. What we actually set

NameTypePurposeDurationThird-party?
auth_tokenStrictly necessary (first-party)Keeps you signed in across page loads.24 hoursNo — set directly by CapitalSync

Because this cookie is strictly necessary for you to stay logged in — not used for advertising, analytics, or cross-site tracking — it's set automatically when you log in and doesn't require a separate consent banner under most cookie-consent frameworks (which generally exempt strictly-necessary cookies). We still disclose it here in full for transparency.

2. Browser local storage

In addition to the cookie above, the app uses your browser's local storage (not a cookie, but disclosed here for completeness since it serves the same purpose):

KeyPurposeDuration
cs_token / cs_user (localStorage)Same sign-in purpose as the auth_token cookie, used by the app’s client-side code.Until you log out or clear browser storage

3. What we don't use

No advertising cookies, no third-party analytics trackers, no cross-site tracking pixels, and no fingerprinting scripts are set by CapitalSync today. If that changes — for example, if we add a product analytics tool in the future — this page will be updated first, before that cookie is ever set, not after.

4. Third-party cookies from embedded services

When you use a paid-plan checkout flow, our payment processor (Razorpay) loads its own checkout script (checkout.razorpay.com) and may set its own cookies during that flow, governed by Razorpay's own privacy/cookie policy, not this one. We don't control what a third-party payment processor's own secure checkout page does internally.

5. Managing cookies

You can clear the auth_token cookie and local storage at any time by logging out, or by clearing your browser's site data for this domain. Since it's strictly necessary for authentication, blocking it will simply mean you can't stay logged in — the site's core public pages (this one included) will still work.

6. Contact

Questions about this policy: privacy@capitalsync.net. See also our Privacy Policy and Terms of Service.

CapitalSync — Raise Money. Know Your Worth. Close Deals.