Skip to main content

Version: COOKIES-v2.0 • Effective Date: August 17, 2026

1. About this policy

This Cookies Policy explains how Bitscaled LLC ("Bitscaled," "we," "us," or "our") uses cookies and similar technologies on https://bitscaled.tech and related Bitscaled-operated web applications. It should be read with our Privacy Policy and Terms of Service.

The tables below are generated from our public cookie inventory so the names, providers, durations, and purposes stay aligned with what the site actually sets.

2. What cookies are

Cookies are small text files a site stores in your browser. They can be first-party (set by Bitscaled) or third-party (set by a provider such as Google or Datadog). Session cookies expire when you close the browser. Persistent cookies last until they expire or you delete them.

3. Local storage is not a cookie

Some preferences are stored in browser localStorage, not as HTTP cookies. They are listed here so the distinction is clear:

  • Cookie consent: localStorage key bitscaled-cookie-consent. Stores whether you allowed analytics or marketing cookies. This is localStorage, not a cookie.
  • Theme preference: localStorage key bitscaled-theme (bitscaled-theme). Remembers light or dark appearance. This is not a cookie.

bitscaled-cookie-consent and bitscaled-theme are not cookies. Clearing site data in your browser removes them along with cookies. They do not transmit to our servers on every request the way an HTTP cookie does.

4. Essential cookies

Essential cookies are required for signed-in sessions, CSRF protection, and abuse prevention on public forms. They do not require consent and cannot be switched off through Cookie Settings. Without them, login, Workspace, Intranet, Admin, and protected forms will not work reliably.

NameProviderDurationPurpose
auth-sessionBitscaledUp to 7 daysEncrypted HTTP-only session for signed-in Workspace, Intranet, and Admin users.
x-csrf-tokenBitscaledSession / aligned with the auth cookieHttpOnly CSRF token compared to the request header on state-changing API calls.
x-csrf-token-jsBitscaledSession / aligned with the auth cookieJavaScript-readable CSRF token copy used by authenticated browser clients.
refresh-tokenBitscaledUp to 7 daysHttpOnly refresh credential used to renew signed-in sessions.
bitscaled_affBitscaledUp to 90 days (program default; admin-configurable 1–365 days)First-party affiliate referral attribution after someone uses a Bitscaled affiliate link. Not a Partner Program cookie.
_GRECAPTCHAGoogle reCAPTCHASet by Google (typically up to 6 months)Abuse and bot protection on public forms such as contact, login, invitation acceptance, and VaultSandbox spoof-test submissions.

Current essential cookies are auth-session, refresh-token, x-csrf-token, x-csrf-token-js, bitscaled_aff (first-party affiliate referral attribution), and _GRECAPTCHA (Google reCAPTCHA on public forms such as contact, login, invitation acceptance, and VaultSandbox spoof-test submissions).

5. Analytics cookies (consent required)

Analytics cookies load on public pages only after you allow analytics in the consent banner or Cookie Settings. They help us understand how the public site is used. They are not required to read the site.

NameProviderDurationPurpose
_gaGoogle Analytics 4Up to 13 months (Google default; loaded only after analytics consent)Distinguish unique visitors on public website pages.
_ga_*Google Analytics 4Up to 13 months (loaded only after analytics consent)Persist GA4 session state for consented measurement.
_gidGoogle Analytics 424 hours (loaded only after analytics consent)Distinguish visitors for a 24-hour window.
_dd_sDatadog RUMSession (loaded only after analytics consent on public pages)Real-user performance and optional session replay on public pages when Datadog is configured.

Current analytics cookies are _ga, _ga_*, and _gid (Google Analytics 4) and _dd_s (Datadog RUM on public pages when Datadog is configured). Session replay may run only if enabled in our Datadog configuration and after the same analytics consent; it is not guaranteed on every visit.

6. Marketing cookies

Marketing cookies would be used for advertising or conversion tracking across sites. The consent banner includes a marketing category so we can ask before any such cookies are introduced. No marketing cookies are currently active on the public website.

The public cookie inventory has no marketing-category rows at this time. If that changes, we will add the cookies to this table and request consent before loading them.

7. Cookieless measurement

Vercel Web Analytics and Vercel Speed Insights are cookieless. They do not set the cookies listed in this policy and are not part of the analytics-consent toggle. They measure aggregated page performance and traffic on the hosted site.

8. Google Maps (Intranet CRM only)

Google Maps address lookup is used in Intranet CRM (for example, company address autocomplete). It is not loaded on public website pages. Any Google Maps cookies or local data that appear are limited to authenticated Intranet use of that feature, not the public website cookie inventory.

9. How to change preferences

Use Cookie Settings in the website footer, or the consent banner when it is shown, to allow or reject analytics (and marketing, if we later activate that category). Essential cookies stay on. Choosing Essential Only prevents Google Analytics and public Datadog RUM cookies from loading.

Changing Cookie Settings updates the localStorage consent record described above. It does not by itself delete cookies already stored by Google or Datadog; use your browser controls if you want those files removed immediately.

10. Browser controls

You can also delete or block cookies in your browser settings. Blocking essential cookies will break signed-in features and some forms. Help for common browsers is published by the browser vendor.

Personal information collected through cookies and similar technologies is handled as described in the Privacy Policy. Use of the site is also governed by the Terms of Service.

12. Contact

Questions about cookies: privacy@bitscaled.tech or legal@bitscaled.tech.

Explore our other legal documents

Related policies that explain how we operate, protect your data, and provide our services transparently.

Essential

Privacy Policy

How we handle website, account, newsletter, VaultTools, and managed-service data.

Read Privacy Policy
Essential

Terms of Service

The rules for using our website, client portal, public tools, and managed services.

Read Terms of Service
Essential

Acceptable Use Policy

What you may and may not do on our website, Client Workspace, public tools, and managed environments.

Read Acceptable Use Policy

Cookies Policy

Named cookies, localStorage consent, and how to change analytics preferences.

Read Cookies Policy
Essential

Data Processing Agreement

Processor terms for Client Data in managed services and hosted Workspace content.

Read Data Processing Agreement

Subprocessors

Vendors that may process Website Data or Client Data, including optional tools.

Read Subprocessors

DMCA Policy

Copyright notices, counter-notices, and designated agent contact.

Read DMCA Policy

Vulnerability Disclosure

How to report security issues in Bitscaled-operated systems in good faith.

Read Vulnerability Disclosure

Security & Compliance

These documents explain how we handle privacy, terms, cookies, data processing, and acceptable use without implying certifications outside the written policies.

Privacy practices documented
Service terms published
Data processing terms available
Cookie preferences supported

Questions About Our Legal Policies?

If you have questions about any of our legal documents or need clarification on our policies, our legal team is here to help.