Cookies and related browser storage help QS Assets keep you signed in, remember preferences, and (only with consent) measure anonymous product usage. We do not use third-party advertising pixels.
2. Taxonomy of Storage Elements We Implement
Storage Category
Operational Purpose
Retention Window
Consent Requirement
Essential Authentication
HttpOnly Secure session cookies and CSRF token for dashboard / portal access.
Cleared on logout or cookie expiry.
Required — Core Security
Functional Settings
Theme (light/dark) and UI layout preferences in first-party local storage.
Until cleared by the user.
Functional
Anonymized Analytics
Aggregated usage metrics (routes visited, feature counts). Off by default.
Per consent choice; cleared when consent is revoked.
Opt-in Consent Required
3. Mandatory Essential Storage (Always Active)
These are required for sign-in and security:
qs_access_token / qs_refresh_token — HttpOnly Secure cookies (not readable by page JavaScript).
qs_csrf — Double-submit CSRF token for cookie-authenticated mutations.
theme — UI preference stored in first-party storage (light mode).
qs_cookie_consent — Records your analytics preference.
4. Optional Analytics Storage (Consent Required)
Analytics are off by default. If you opt in, we capture aggregated, anonymized usage telemetry (paths visited, feature usage counts). We do not track form field contents, passwords, or device inventory names in analytics.
5. Zero Third-Party Cookie Policy
There are zero Facebook pixels, Google Analytics trackers, HubSpot scripts, or ad networks on our domains. Metrics that you opt into are handled by our own services.
6. Revocation & Storage Management
Clear site data in your browser to purge local storage and cookies.
Blocking all site storage will prevent sign-in.
7. Compliance Foundation (DPDP Act 2023)
Essential auth: Processed for providing the service.
Analytics: Processed only with your explicit consent.