1. Introduction and Scope
This Cookie Policy ("Policy") constitutes a formal legal disclosure by TheIronStack ("Company", "we", "our", or "us") regarding the implementation, processing, management, and control of cookies, web beacons, local storage objects, and related technical storage primitives across our software platform, web applications, and associated digital services (collectively, the "Services").
This Policy is integrated with, and forms an essential part of, the Company's Terms of Service, Privacy Policy, and Platform License Agreement. By accessing, navigating, or maintaining an active user account across the Services, you acknowledge that you have read, understood, and consented to the storage technologies and data practices detailed herein.
2. Storage Technologies Defined
To ensure operational efficiency, platform security, and seamless session management, the Company utilizes standard browser-based data storage technologies. For the purposes of this Policy, these technologies are defined as follows:
- Cookies: Small data files comprising alphanumeric identifiers transmitted by a web server and stored on your web browser or hardware device. Cookies allow the Services to recognize your browser across successive browsing interactions.
- Session Cookies: Temporary data files that expire automatically upon closing your web browser session.
- Persistent Cookies: Data files that remain stored on your device until a specified expiration date or until manually purged via browser controls.
- Local Storage & Session Storage: Web storage primitives (
localStorageandsessionStorage) provided by modern web browsers that enable the persistent or session-bound client-side storing of key-value pairs without automatically transmitting data headers to servers on every HTTP request. - Cryptographic Session Tokens: Secure, digitally signed tokens utilized to verify authenticated user sessions and authorization rights across API requests.
3. Categorization of Platform Storage Technologies
The Company categorizes its storage mechanisms into distinct functional classifications based on their operational necessity and administrative purpose:
3.1 Strictly Necessary / Essential Technologies
Essential storage primitives are mandatory for the execution of core platform operations. These technologies enable secure authentication, role-based access control, Cross-Site Request Forgery (CSRF) mitigation, load balancing, and infrastructure protection.
Operational Notice: Essential technologies do not require prior user consent under applicable data protection frameworks. Disabling or blocking essential storage mechanisms via custom browser configurations will cause immediate platform malfunction, preventing account access and session authentication.
3.2 Preference & Functional Technologies
Functional storage mechanisms retain user-selected configuration parameters across sessions to deliver an optimized user experience. These include interface color scheme selections (e.g., dark/light mode preferences), language settings, and customized layout attributes.
3.3 Security & Anti-Fraud Technologies
Security-focused storage primitives evaluate device attributes and session identifiers to detect anomalous login patterns, mitigate automated bot operations, prevent credential stuffing, and protect sensitive member and facility records.
3.4 Performance & System Telemetry Technologies
Where active, performance storage mechanisms collect aggregated, non-identifying telemetry regarding page loading speeds, API response latencies, rendering bottlenecks, and system error events. This technical metadata is strictly processed to maintain system health, optimize server capacity, and refine application responsiveness.
4. Storage Technology Inventory
The table below outlines the primary cookies and local storage items deployed across the Services:
| Technical Identifier | Provider | Functional Purpose | Category | Retention Duration |
|---|---|---|---|---|
better-auth.session_token | TheIronStack | Manages cryptographic user session authentication and account authorization. | Essential | Session / 30 Days |
csrf_token | TheIronStack | Prevents Cross-Site Request Forgery (CSRF) exploitation across state-changing API requests. | Security | Session |
theme | TheIronStack | Persists user interface color mode preference (e.g., Dark / Light theme selection). | Functional | 1 Year |
_telemetry_id | TheIronStack | Aggregates system loading performance metrics and client-side error logs. | Performance | 90 Days |
5. Prohibition on Behavioral Tracking and Data Monetization
The Company enforces strict data minimization protocols. At no time shall the Company utilize storage technologies for unauthorized data monetization or invasive tracking activities.
Zero Monetization Commitment: TheIronStack DOES NOT deploy third-party advertising cookies, cross-site behavioral tracking scripts, data broker integration tags, or user profiling tools for marketing, monetization, or AI training purposes.
Specifically, the Company explicitly covenants that it does NOT:
- Deploy targeted advertising cookies or third-party ad networks;
- Track user browsing activities across external, un-affiliated websites;
- Sell, lease, or trade user behavioral data derived from cookies to third-party data brokers;
- Utilize session records or user interaction histories to train external commercial artificial intelligence models.
6. Third-Party Infrastructure Services
Certain essential infrastructure providers integrated into the Services (such as cloud hosting facilities, content delivery networks, database clusters, and security verification gateways) may deploy technical cookies or headers necessary to deliver their respective services securely.
All third-party infrastructure providers operating on behalf of the Company are bound by strict contractual non-disclosure obligations, data processing agreements, and security mandates restricting their data processing activities solely to the delivery of assigned infrastructure operations.
7. User Management and Control Mechanisms
You possess legal rights and administrative options regarding the management of browser storage technologies:
7.1 Browser Configuration Controls
Most modern web browsers permit users to inspect, modify, restrict, or delete stored cookies and local storage objects via browser security settings. Instructions for managing storage settings across standard browsers can be accessed through the following links:
- Google Chrome Settings
- Mozilla Firefox Privacy & Security
- Apple Safari Preferences
- Microsoft Edge Security & Privacy
7.2 Do Not Track (DNT) & Global Privacy Control (GPC) Signals
The Company’s infrastructure is configured to respect recognized statutory browser privacy signals, including Global Privacy Control (GPC) headers, by restricting non-essential telemetry processing upon receipt of an active privacy signal.
8. Amendments and Policy Revisions
The Company reserves the right to amend or update this Cookie Policy periodically to reflect legal amendments, technological upgrades, or modified platform features. Any modifications will become effective upon publication of the updated document. The Last Updated and Effective Date attributes set forth at the top of this Policy indicate the latest revision date.
9. Contact and Regulatory Inquiries
For questions, formal privacy inquiries, or regulatory communications concerning our Cookie Policy or data storage practices, please reach out to our compliance department:
TheIronStack Legal & Privacy Operations
Email: support@theironstack.in