CatalystBoxMarketplace

Browser storage and sessions

Cookies & Storage Policy

The cookies, local storage, session records and first-party analytics used by CatalystBox Marketplace.

Version 1.1Effective 28 July 2026Last updated 28 July 2026

1. What this covers

This Policy explains the cookies and similar technologies we use on marketplace.catalystbox.in, operated by CATALYSTBOX (OPC) PRIVATE LIMITED. It sits alongside our Privacy Policy.

"Cookies and similar technologies" means cookies, browser local storage and session storage, and the identifiers we generate to keep you signed in, keep the Platform secure, and understand how it is used.

2. The short version

  • We use what is needed to sign you in and keep the Platform secure.
  • We collect first-party usage analytics so we can see which features work and where the Platform is failing.
  • We use no advertising cookies, no remarketing, no advertising pixels, and no cross-site tracking. We do not share browsing data with advertising networks or data brokers. This is a permanent commitment.

3. What we use

3.1 Strictly necessary — always on

These cannot be switched off. Without them the Platform will not work.

WhatPurposeTypeDuration
Authentication tokenKeeps you signed in and authorises your requestsLocal storage, set by our authentication providerShort-lived — see clause 4
Session refresh tokenRenews your session so you are not signed out mid-taskLocal storageSee clause 4
Security and abuse-prevention identifiersDetect unusual sign-in patterns, prevent duplicate and automated submissionsServer-side recordSee clause 3.4
Consent recordRemembers the cookie choices you madeLocal storage12 months

3.2 Functional — used when you request it

WhatPurposeTypeDuration
Interface preferencesRemembers theme, layout, and display choicesLocal storageUntil you clear it
Draft statePreserves partly written messages and forms so you do not lose workLocal storageUntil submitted or cleared

Functional storage is created only when you use a feature that asks the browser to remember a preference or draft. It is not analytics and is not controlled by the analytics choice. You can remove it through the relevant feature where available or by clearing this site's browser storage.

We record usage events on our own systems. We do not use Google Analytics, Meta Pixel, or any third-party behavioural analytics service.

What each event contains: an event name, a session identifier, your account identifier if you are signed in, your role, the page or screen, the referring page within the Platform, and a timestamp.

What we use it for: understanding which features are used, finding where flows break, measuring whether a page performs, and prioritising engineering work.

What we do not use it for: advertising, profiling you as an individual, building a marketing profile, selling to anyone, or making any decision that affects your account, your ranking, or your access.

Retention: 13 months, then deleted or reduced to aggregates.

Your control: you can decline analytics. The Platform works normally without it.

3.4 Device and notification records

These are stored on our servers rather than in your browser, but you should know about them.

WhatPurposeRetention
Login device record, including a hashed device identifierRecognises devices you have signed in from, so we can flag a sign-in from somewhere new and protect your account12 months from last use
Push notification subscription, including a device label and browser user-agent stringDelivers browser notifications, but only where you have enabled themUntil you disable notifications or remove the device

The device identifier is hashed — we store a one-way value, not a readable fingerprint. It is used only for account security. It is never used for advertising, cross-site tracking, or building a behavioural profile, and it is never shared with any third party for those purposes.

You can review and remove your recognised devices in Account → Security, and turn off push notifications in Account → Notifications or in your browser settings.

4. How long you stay signed in

Your signed-in session is maintained by two tokens:

  • A short-lived access token, which is ordinarily refreshed about once an hour while you are active.
  • A refresh token, which issues a new access token when the old one expires.

The Marketplace signs this browser out after 12 hours without activity. While you remain active, a short-lived access token is ordinarily refreshed about once an hour. Signing out revokes the selected refresh session immediately. A previously issued short-lived access token may remain valid until it expires, ordinarily within about one hour; sensitive operations also validate the live session. You can end the current, other, or all sessions from Account → Security & sessions.

We publish this because a vague statement about session security is not worth reading. If you use a shared or public computer, sign out when you finish.

5. Third-party cookies

The Platform relies on third-party services, some of which set their own cookies when their functionality is used:

ServiceWhen it appliesGoverned by
RazorpayOnly when you go through checkout or manage a paymentRazorpay's privacy policy
SupabaseAuthentication and storageSupabase's privacy policy
VercelHosting and content deliveryVercel's privacy policy

None of these is an advertising cookie. We do not permit any third party to place advertising or tracking technology on the Platform.

6. Managing your choices

  • On the Platform — use the cookie banner shown on first visit, or change your choice any time at Account → Privacy and cookies.
  • In your browser — you can block or delete cookies and clear local storage through your browser settings. Blocking strictly necessary items will sign you out and stop the Platform working.
  • Withdrawing consent is as easy as giving it, and does not affect processing already carried out.

7. Do Not Track

There is no common standard for how sites should respond to browser Do Not Track signals. We do not track users across sites in any event, so a Do Not Track signal makes no difference to what we do.

8. Changes

See the standing rule at the top of this document. The current version is always at marketplace.catalystbox.in/cookies.

9. Contact

Grievance Officer Name: Yatesh Srivastava CATALYSTBOX (OPC) PRIVATE LIMITED P-10, K-376, Chinhat, Ganeshpur Rahmanpur, Lucknow, Uttar Pradesh — 226028, India Email: hello@catalystbox.in

Marketplace policies