1. What this policy covers
This Cookie Policy explains how Tripkoz Technologies ("Tripkoz", "we", "us") uses cookies and similar technologies on the Tripkoz website and web dashboard, and the choices available to you.
It should be read together with our Privacy Policy, which explains how we handle personal data more generally, and our Terms & Conditions.
The Tripkoz Android application does not use browser cookies. It stores a small amount of data on your device — your sign-in session and your app settings — which is described in the Privacy Policy rather than here.
2. What cookies and similar technologies are
A cookie is a small text file placed on your device by a website. It lets the site recognise your browser on a later request — for example, to keep you signed in between page loads.
We also use technologies that behave like cookies without being cookies:
- localStorage and sessionStorage — browser storage the dashboard uses to hold your session tokens, theme choice and language;
- Pixels and beacons — small requests used to count whether a page or email was opened;
- Device and browser identifiers — values a payment or mapping provider may read to detect fraud or serve the right map tiles.
Where this policy says "cookies", it means all of these unless stated otherwise.
3. Why we use them
We use cookies for a small, deliberate set of purposes:
- To keep you signed in, and to move you securely between the dashboard and the payment gateway;
- To remember choices you have already made, such as light or dark theme, language, and your cookie preferences themselves;
- To protect the Service against automated abuse, credential stuffing and fraudulent payments;
- To understand, in aggregate, which pages are used and where people get stuck, so we can improve the product.
We do not use cookies to build advertising profiles, and we do not sell or share cookie data with advertising networks.
4. The categories we use
Strictly necessary — always on. Without these the Service cannot work, so they are set as soon as you arrive and cannot be switched off. They carry your sign-in session, your CSRF protection, the routing that keeps a request on one server, and the record of your cookie choices.
Functional — off until you allow them. These remember preferences that make the Service pleasanter but are not required: your theme, your language, whether you have dismissed a particular notice, and the last dashboard view you used.
Analytics — off until you allow them. These count page views and feature usage in aggregate so we can see what to improve. Where analytics are enabled, IP addresses are truncated before storage and we do not attempt to identify individuals.
Payment and fraud prevention — set by Razorpay when, and only when, you open a checkout. They protect a transaction in progress, and are treated as strictly necessary for that transaction because a payment cannot be completed safely without them.
5. The cookies and storage we set
Set by Tripkoz:
- access_token and refresh_token (localStorage, strictly necessary) — your signed-in session. The access token is short-lived; the refresh token persists until you sign out or the session is revoked.
- user (localStorage, strictly necessary) — the name, role and organisation shown in the dashboard shell, so the page can render before the first API call returns.
- last_activity (localStorage, strictly necessary) — the idle timer that signs you out after 15 minutes of inactivity.
- tripkoz_cookie_consent (localStorage, strictly necessary) — the categories you have accepted and the policy version you accepted them under. Retained for 12 months.
- theme (localStorage, functional) — your light, dark or system preference.
- tripkoz_lang (localStorage, functional) — your chosen interface language.
Set by our providers:
- Razorpay — payment session and fraud-prevention cookies, set on the checkout domain when a checkout is opened. Governed by Razorpay’s own privacy policy.
- Google Maps — preference and performance cookies set when a map is displayed, used to serve map tiles and remember map settings. Governed by Google’s privacy policy.
- Our hosting and CDN provider — a routing cookie that keeps a session on one server, and short-lived security cookies used for bot mitigation.
Cookie names used by third parties are chosen by those parties and can change without notice to us. The categories above describe what they are for.
6. How long they last
Session cookies are deleted when you close your browser. Persistent cookies remain for a stated period unless you delete them sooner.
Our own persistent storage is kept as follows: cookie choices for 12 months; theme and language until you change or clear them; session tokens until you sign out, are signed out for inactivity, or the session is revoked.
Third-party cookie lifetimes are set by those providers and are typically between a single session and 24 months.
7. Your choices
The simplest way to change your choices is the Cookie Preferences page at /cookie-preferences. It shows each non-essential category with a switch, and saving takes effect immediately.
When you first visit, nothing beyond strictly necessary cookies is set. The banner lets you accept all, reject everything non-essential, or open preferences and choose per category. Rejecting is a single click, exactly like accepting.
You can also control cookies in your browser settings, including blocking or deleting them entirely. Blocking strictly necessary storage will stop you being able to sign in.
Withdrawing consent does not affect processing that already happened lawfully while consent was in place.
8. Do Not Track and global privacy signals
There is still no agreed standard for how sites should respond to the browser "Do Not Track" header, so we do not act on that header alone.
We do honour the Global Privacy Control (GPC) signal where a browser sends one: a GPC signal is treated as a rejection of analytics and functional cookies, and that choice is recorded for you without a banner interaction.
9. Children
Tripkoz accounts are not offered directly to children. Passenger records for children are created and managed by a school, college or company, and children do not sign in to the dashboard.
We do not knowingly set analytics or functional cookies on a device we know to belong to a child, and we do not use cookies to profile children.
10. Changes to this policy
If we add a cookie in a new category, or change what an existing category is used for, we will update this page, raise the version stamp shown above, and ask for your consent again before the change takes effect.
Minor edits — a corrected name, a clarified sentence — are published without asking again.
11. Contact us
Questions about this policy can be sent to privacy@tripkoz.com. Complaints about the handling of personal data may be sent to our Grievance Officer at grievance@tripkoz.com, who will acknowledge within 24 hours and aim to resolve within 15 days.
Related policies
This document sits alongside the rest of our published terms. Together they form the agreement that governs your use of Tripkoz.