Cookie Policy
Last updated: July 18, 2026
1. What we actually set
| Name | Type | Purpose | Duration | Third-party? |
|---|---|---|---|---|
| auth_token | Strictly necessary (first-party) | Keeps you signed in across page loads. | 24 hours | No — set directly by CapitalSync |
Because this cookie is strictly necessary for you to stay logged in — not used for advertising, analytics, or cross-site tracking — it's set automatically when you log in and doesn't require a separate consent banner under most cookie-consent frameworks (which generally exempt strictly-necessary cookies). We still disclose it here in full for transparency.
2. Browser local storage
In addition to the cookie above, the app uses your browser's local storage (not a cookie, but disclosed here for completeness since it serves the same purpose):
| Key | Purpose | Duration |
|---|---|---|
| cs_token / cs_user (localStorage) | Same sign-in purpose as the auth_token cookie, used by the app’s client-side code. | Until you log out or clear browser storage |
3. What we don't use
No advertising cookies, no third-party analytics trackers, no cross-site tracking pixels, and no fingerprinting scripts are set by CapitalSync today. If that changes — for example, if we add a product analytics tool in the future — this page will be updated first, before that cookie is ever set, not after.
4. Third-party cookies from embedded services
When you use a paid-plan checkout flow, our payment processor (Razorpay) loads its own checkout script (checkout.razorpay.com) and may set its own cookies during that flow, governed by Razorpay's own privacy/cookie policy, not this one. We don't control what a third-party payment processor's own secure checkout page does internally.
5. Managing cookies
You can clear the auth_token cookie and local storage at any time by logging out, or by clearing your browser's site data for this domain. Since it's strictly necessary for authentication, blocking it will simply mean you can't stay logged in — the site's core public pages (this one included) will still work.
6. Contact
Questions about this policy: privacy@capitalsync.net. See also our Privacy Policy and Terms of Service.