Cookie Notice
This Cookie Notice explains how Varosync, Inc. uses cookies and similar technologies on websites and applications that link to this Notice.
This Cookie Notice explains how Varosync, Inc. uses cookies and similar technologies on websites and applications that link to this Notice.
What these technologies do
A cookie is a small file stored by a browser. Similar technologies include local storage, pixels, tags, and software development kits that store or read information on a device. They may keep a requested feature working, maintain security, remember a preference, or measure use of a site.
Cookies identified in the order-room source
| Name | Provider | Purpose | Duration | Category |
|---|---|---|---|---|
__Host-order-[Order ID] | Varosync | Holds the server-generated session used to read and administer one Order in the browser that created it. The cookie is HttpOnly, Secure, SameSite=Lax, and limited to the host. | 30 days, unless revoked earlier | Strictly necessary |
__Host-request-[request ID] | Varosync | Holds the server-generated session used to read and update one invoice, procurement, or forwarding request in the browser that created it. The cookie is HttpOnly, Secure, SameSite=Lax, and limited to the host. | 30 days, unless revoked earlier | Strictly necessary |
sidebar_state | Varosync | A source component can remember whether a navigation panel is open or closed. No use of that component was found in the reviewed application. | 7 days if the component is used | Functional |
On a local HTTP development server, the two access-cookie names begin with vs-dev- because a browser cannot set a Secure __Host- cookie over HTTP. That development form must not be used as a production configuration.
The presence of a cookie setter in an unused component does not establish that the functional cookie is set in production. The reviewed source did not contain an advertising pixel, session-replay tool, or behavior-analytics library. This is a source-code finding, not a production inventory. Hosting, access-control, payment, embedded-content, and security providers may set technologies that do not appear in the application source.
Strictly necessary technologies
Varosync may use technologies required to deliver a page or feature you request, maintain a session, authenticate a user, route traffic, prevent fraud, or protect a system. Where law permits, these technologies operate without optional consent because the requested service cannot operate securely without them.
Functional technologies
Functional technologies remember a choice that is useful but not essential. Where consent is required, Varosync will not set them until you allow that category.
Analytics and advertising
Varosync does not currently authorize advertising cookies, cross-site behavioral advertising, or session replay in the private order room. Analytics may not be added to the order room if it captures agreement text, form contents, project labels, payment fields, scientific information, or private-data classifications.
If Varosync introduces optional analytics on a public site, this Notice and the consent control must name the provider, exact purpose, information collected, and duration before that technology is enabled for users whose consent is required.
Payment pages and linked sites
If you choose hosted payment, the payment provider may use cookies on its own domain to complete payment, prevent fraud, and comply with law. Its privacy and cookie notices govern those pages. A link to a public source or another third-party site may also open a site with its own technologies.
Your choices
Where a consent control appears, “Reject optional” must be as easy to select as “Allow optional”. You may change your choice at any time through “Cookie settings” in the footer. Blocking strictly necessary technologies in the browser may prevent a requested page or account feature from working.
Contact
Questions about this Notice may be sent to privacy@varosync.com.