Cookies Policy
How Bitscaled uses cookies and similar technologies on bitscaled.tech, including essential cookies, consent-gated analytics, and cookieless Vercel measurement.
Version: COOKIES-v2.0 • Effective Date: August 17, 2026
1. About this policy
This Cookies Policy explains how Bitscaled LLC ("Bitscaled," "we," "us," or "our") uses cookies and similar technologies on https://bitscaled.tech and related Bitscaled-operated web applications. It should be read with our Privacy Policy and Terms of Service.
The tables below are generated from our public cookie inventory so the names, providers, durations, and purposes stay aligned with what the site actually sets.
2. What cookies are
Cookies are small text files a site stores in your browser. They can be first-party (set by Bitscaled) or third-party (set by a provider such as Google or Datadog). Session cookies expire when you close the browser. Persistent cookies last until they expire or you delete them.
3. Local storage is not a cookie
Some preferences are stored in browser localStorage, not as HTTP cookies. They are listed here so the distinction is clear:
- Cookie consent: localStorage key bitscaled-cookie-consent. Stores whether you allowed analytics or marketing cookies. This is localStorage, not a cookie.
- Theme preference: localStorage key bitscaled-theme (bitscaled-theme). Remembers light or dark appearance. This is not a cookie.
bitscaled-cookie-consent and bitscaled-theme are not cookies. Clearing site data in your browser removes them along with cookies. They do not transmit to our servers on every request the way an HTTP cookie does.
4. Essential cookies
Essential cookies are required for signed-in sessions, CSRF protection, and abuse prevention on public forms. They do not require consent and cannot be switched off through Cookie Settings. Without them, login, Workspace, Intranet, Admin, and protected forms will not work reliably.
| Name | Provider | Duration | Purpose |
|---|---|---|---|
| auth-session | Bitscaled | Up to 7 days | Encrypted HTTP-only session for signed-in Workspace, Intranet, and Admin users. |
| x-csrf-token | Bitscaled | Session / aligned with the auth cookie | HttpOnly CSRF token compared to the request header on state-changing API calls. |
| x-csrf-token-js | Bitscaled | Session / aligned with the auth cookie | JavaScript-readable CSRF token copy used by authenticated browser clients. |
| refresh-token | Bitscaled | Up to 7 days | HttpOnly refresh credential used to renew signed-in sessions. |
| bitscaled_aff | Bitscaled | Up to 90 days (program default; admin-configurable 1–365 days) | First-party affiliate referral attribution after someone uses a Bitscaled affiliate link. Not a Partner Program cookie. |
| _GRECAPTCHA | Google reCAPTCHA | Set by Google (typically up to 6 months) | Abuse and bot protection on public forms such as contact, login, invitation acceptance, and VaultSandbox spoof-test submissions. |
Current essential cookies are auth-session, refresh-token, x-csrf-token, x-csrf-token-js, bitscaled_aff (first-party affiliate referral attribution), and _GRECAPTCHA (Google reCAPTCHA on public forms such as contact, login, invitation acceptance, and VaultSandbox spoof-test submissions).
5. Analytics cookies (consent required)
Analytics cookies load on public pages only after you allow analytics in the consent banner or Cookie Settings. They help us understand how the public site is used. They are not required to read the site.
| Name | Provider | Duration | Purpose |
|---|---|---|---|
| _ga | Google Analytics 4 | Up to 13 months (Google default; loaded only after analytics consent) | Distinguish unique visitors on public website pages. |
| _ga_* | Google Analytics 4 | Up to 13 months (loaded only after analytics consent) | Persist GA4 session state for consented measurement. |
| _gid | Google Analytics 4 | 24 hours (loaded only after analytics consent) | Distinguish visitors for a 24-hour window. |
| _dd_s | Datadog RUM | Session (loaded only after analytics consent on public pages) | Real-user performance and optional session replay on public pages when Datadog is configured. |
Current analytics cookies are _ga, _ga_*, and _gid (Google Analytics 4) and _dd_s (Datadog RUM on public pages when Datadog is configured). Session replay may run only if enabled in our Datadog configuration and after the same analytics consent; it is not guaranteed on every visit.
6. Marketing cookies
Marketing cookies would be used for advertising or conversion tracking across sites. The consent banner includes a marketing category so we can ask before any such cookies are introduced. No marketing cookies are currently active on the public website.
The public cookie inventory has no marketing-category rows at this time. If that changes, we will add the cookies to this table and request consent before loading them.
7. Cookieless measurement
Vercel Web Analytics and Vercel Speed Insights are cookieless. They do not set the cookies listed in this policy and are not part of the analytics-consent toggle. They measure aggregated page performance and traffic on the hosted site.
8. Google Maps (Intranet CRM only)
Google Maps address lookup is used in Intranet CRM (for example, company address autocomplete). It is not loaded on public website pages. Any Google Maps cookies or local data that appear are limited to authenticated Intranet use of that feature, not the public website cookie inventory.
9. How to change preferences
Use Cookie Settings in the website footer, or the consent banner when it is shown, to allow or reject analytics (and marketing, if we later activate that category). Essential cookies stay on. Choosing Essential Only prevents Google Analytics and public Datadog RUM cookies from loading.
Changing Cookie Settings updates the localStorage consent record described above. It does not by itself delete cookies already stored by Google or Datadog; use your browser controls if you want those files removed immediately.
10. Browser controls
You can also delete or block cookies in your browser settings. Blocking essential cookies will break signed-in features and some forms. Help for common browsers is published by the browser vendor.
11. Related policies
Personal information collected through cookies and similar technologies is handled as described in the Privacy Policy. Use of the site is also governed by the Terms of Service.
12. Contact
Questions about cookies: privacy@bitscaled.tech or legal@bitscaled.tech.
Explore our other legal documents
Related policies that explain how we operate, protect your data, and provide our services transparently.
Privacy Policy
How we handle website, account, newsletter, VaultTools, and managed-service data.
Read Privacy PolicyTerms of Service
The rules for using our website, client portal, public tools, and managed services.
Read Terms of ServiceAcceptable Use Policy
What you may and may not do on our website, Client Workspace, public tools, and managed environments.
Read Acceptable Use PolicyCookies Policy
Named cookies, localStorage consent, and how to change analytics preferences.
Read Cookies PolicyData Processing Agreement
Processor terms for Client Data in managed services and hosted Workspace content.
Read Data Processing AgreementSubprocessors
Vendors that may process Website Data or Client Data, including optional tools.
Read SubprocessorsDMCA Policy
Copyright notices, counter-notices, and designated agent contact.
Read DMCA PolicyVulnerability Disclosure
How to report security issues in Bitscaled-operated systems in good faith.
Read Vulnerability DisclosureSecurity & Compliance
These documents explain how we handle privacy, terms, cookies, data processing, and acceptable use without implying certifications outside the written policies.
Questions About Our Legal Policies?
If you have questions about any of our legal documents or need clarification on our policies, our legal team is here to help.
