Legal and trust/Cookie Notice

Cookie Notice

Revised 21 August 2026

This Cookie Notice explains how Varosync, Inc. uses cookies and similar technologies on websites and applications that link to this Notice.

This Cookie Notice explains how Varosync, Inc. uses cookies and similar technologies on websites and applications that link to this Notice.

What these technologies do

A cookie is a small file stored by a browser. Similar technologies include local storage, pixels, tags, and software development kits that store or read information on a device. They may keep a requested feature working, maintain security, remember a preference, or measure use of a site.

Cookies identified in the order-room source

NameProviderPurposeDurationCategory
__Host-order-[Order ID]VarosyncHolds the server-generated session used to read and administer one Order in the browser that created it. The cookie is HttpOnly, Secure, SameSite=Lax, and limited to the host.30 days, unless revoked earlierStrictly necessary
__Host-request-[request ID]VarosyncHolds the server-generated session used to read and update one invoice, procurement, or forwarding request in the browser that created it. The cookie is HttpOnly, Secure, SameSite=Lax, and limited to the host.30 days, unless revoked earlierStrictly necessary
sidebar_stateVarosyncA source component can remember whether a navigation panel is open or closed. No use of that component was found in the reviewed application.7 days if the component is usedFunctional

On a local HTTP development server, the two access-cookie names begin with vs-dev- because a browser cannot set a Secure __Host- cookie over HTTP. That development form must not be used as a production configuration.

The presence of a cookie setter in an unused component does not establish that the functional cookie is set in production. The reviewed source did not contain an advertising pixel, session-replay tool, or behavior-analytics library. This is a source-code finding, not a production inventory. Hosting, access-control, payment, embedded-content, and security providers may set technologies that do not appear in the application source.

Strictly necessary technologies

Varosync may use technologies required to deliver a page or feature you request, maintain a session, authenticate a user, route traffic, prevent fraud, or protect a system. Where law permits, these technologies operate without optional consent because the requested service cannot operate securely without them.

Functional technologies

Functional technologies remember a choice that is useful but not essential. Where consent is required, Varosync will not set them until you allow that category.

Analytics and advertising

Varosync does not currently authorize advertising cookies, cross-site behavioral advertising, or session replay in the private order room. Analytics may not be added to the order room if it captures agreement text, form contents, project labels, payment fields, scientific information, or private-data classifications.

If Varosync introduces optional analytics on a public site, this Notice and the consent control must name the provider, exact purpose, information collected, and duration before that technology is enabled for users whose consent is required.

Payment pages and linked sites

If you choose hosted payment, the payment provider may use cookies on its own domain to complete payment, prevent fraud, and comply with law. Its privacy and cookie notices govern those pages. A link to a public source or another third-party site may also open a site with its own technologies.

Your choices

Where a consent control appears, “Reject optional” must be as easy to select as “Allow optional”. You may change your choice at any time through “Cookie settings” in the footer. Blocking strictly necessary technologies in the browser may prevent a requested page or account feature from working.

Contact

Questions about this Notice may be sent to privacy@varosync.com.