Cookie Policy
This policy explains the cookies and similar technologies this website uses, what each one is for, and how you can control them.
Last updated 1 September 2026
1. Introduction
This Cookie Policy explains how CipherCru Innovations Private Limited (“CipherCru”, “we”, “us”, or “our”) uses cookies and similar tracking technologies on our website at https://www.ciphercru.com and any associated subdomains (collectively, the “Website”).
This Policy should be read together with our Privacy Policy, which sets out the full details of how we collect, use, and protect your personal data, including data collected through cookies.
By continuing to use our Website after being presented with our cookie consent banner, you acknowledge this Policy and, where required by law, consent to the placement of non-essential cookies as indicated through our Cookie Preference Centre.
Who We Are. CipherCru is a technology services company incorporated under the Companies Act 2013, with its registered office at 602, The Elysian, A-31, Swej Farm Circle, Swej Farm, New Sanganer Road, Sodala, Jaipur, Rajasthan 302019, India. For data protection purposes, CipherCru is the Data Fiduciary (under the DPDP Act 2023) and data controller (under the GDPR) in respect of personal data collected through cookies on the Website.
2. What are cookies?
2.1 Definition. Cookies are small text files that are placed on your device (computer, smartphone, tablet, or other internet-connected device) when you visit a website. Cookies are widely used to make websites work efficiently, to provide a better user experience, and to supply information to website owners.
2.2 How Cookies Work. When you visit our Website, our server (or the server of a third-party service we use) places a cookie file on your device. The next time you visit the Website, or another website that uses the same cookie, the cookie is read and recognised. This enables the website to remember your preferences, maintain your session, or track your behaviour across visits.
2.3 Session cookies versus persistent cookies. Session cookies are temporary cookies that exist only for the duration of your browsing session. They are automatically deleted when you close your browser, and are used for essential functions such as maintaining your session while you navigate the Website. Persistent cookies remain on your device after your browser session ends, until they expire or you manually delete them, and are used to remember your preferences across visits and to measure how you use the Website over time.
2.4 First-party versus third-party cookies. First-party cookies are set directly by CipherCru, the website you are visiting. Third-party cookies are set by third parties whose content, services, or scripts are embedded in or referenced by our Website, for example analytics providers, social media platforms, or advertising networks. Third-party cookies are governed by the privacy policies of those third parties.
3. Other tracking technologies
In addition to cookies, we may use the following similar tracking technologies.
3.1 Web Beacons (Pixel Tags). Web beacons are tiny invisible images, typically one pixel square, embedded in web pages or emails. They are used to track whether a page or email has been opened, to count visitors, and to verify system integrity. Web beacons may work alongside cookies and may collect similar information.
3.2 Local Storage. Local storage is a browser feature that allows websites to store data on your device beyond a single session, similar to persistent cookies but with a larger storage capacity. We may use local storage to remember your preferences and session information.
3.3 Session Storage. Session storage is similar to local storage but stores data only for the duration of the browser session. It is automatically cleared when the browser tab or window is closed.
3.4 JavaScript Tags. We use two JavaScript-based tools: Google Tag Manager, which loads Google Analytics 4, and the HubSpot tracking code. What each one collects, and when it runs, is described in Section 4.2 and in the inventory at Section 5.
3.5 UTM Parameters. When you arrive at our Website via a marketing campaign, whether by email, social media or advertising, the URL may contain UTM parameters such as utm_source, utm_medium or utm_campaign. Our analytics tools process them to measure the effectiveness of marketing campaigns. If you accept performance and analytics cookies, the parameters of the visit that first brought you to the Website are kept in a first-party cookie listed in Section 5. If you send us an enquiry, the parameters of your visit are stored with it, as described in our Privacy Policy.
References to “cookies” in this Policy include all of the above tracking technologies unless the context requires otherwise. Cookieless measurement, described in Section 4.2, is not a cookie in that sense: it places nothing on your device and reads nothing from it.
4. Categories of cookies we use
We use four categories of cookies, as described below. The legal basis for each category is addressed in Section 6.
4.1 Strictly necessary cookies
What they are. Strictly necessary cookies are essential for the Website to function. Without these cookies, the Website cannot operate correctly. They enable core functions such as page navigation, security, session management, and access to secure areas of the Website.
Do we need your consent? No. Strictly necessary cookies do not require your consent because they are essential for the provision of the service you have requested. We rely on our legitimate interest in operating the Website as the legal basis for strictly necessary cookies.
- Maintain your session as you navigate between pages
- Store security tokens to protect against cross-site request forgery
- Remember items in enquiry forms as you navigate multi-step processes
- Load-balance traffic across our servers
- Remember the cookie choices you have made
4.2 Performance and analytics cookies
What they are. Performance and analytics cookies show us how the Website is used: which pages are visited, how long is spent on them, where visitors came from, and what errors occur. They are set by Google Analytics and by HubSpot, whose cookies also link the pages you viewed to any enquiry you later send us.
Google Analytics reports this information to us in aggregate, and we use it with Google Signals and Google's advertising features switched off. HubSpot's cookies work differently. If you send us an enquiry, HubSpot connects the pages this browser visited on the Website to that enquiry, so that the member of our team who responds can see what you were interested in. That browsing history then forms part of the personal data we hold about you, as described in our Privacy Policy.
Do we need your consent? Yes. We only place analytics cookies, and only load the HubSpot tracking code, after you have given your consent through our Cookie Preference Centre. If you later withdraw that consent, we remove those cookies from your browser.
- Count the number of visitors to each page
- Record how visitors found the Website (referral source and campaign)
- Identify which pages are most and least popular
- Record which calls to action and forms are used, never what you type into a form
- Measure which sources and pages lead to enquiries
- Track page load speeds and detect errors
- Measure how far down a page visitors scroll
Cookieless measurement. Google Analytics runs in Google's consent mode on every page, from your first visit. Until you accept analytics cookies, and if you decline them, it sets no cookie and reads none. It still sends Google a short measurement signal when a page is viewed or an action is taken. The signal contains the page address, the time, your browser's user agent, the referring page, your consent choice, a random number generated for each page load, and whether your visit came from an advertising link. It carries no identifier that would let us or Google recognise your browser on another page or visit, and we see only aggregated counts.
As with any request to a website, the signal reaches Google from your IP address. Google uses the IP address to derive your approximate location, at city level at most. For visitors in the EEA, Switzerland and the UK, Google states that it performs that lookup on servers in those regions and does not log or store the IP address. The legal basis for cookieless measurement is set out in Section 6.4, and you can stop it entirely with the Google Analytics Opt-Out Browser Add-on described in Section 8.3.
4.3 Functional cookies
What they are. Functional cookies allow the Website to remember choices you make, such as language preferences, region settings, or form pre-fill information, to provide a more personalised experience. These cookies may be set by us or by third-party providers whose services are embedded in our Website.
Do we need your consent? Yes. Functional cookies are not strictly necessary and require your consent.
- Pre-fill contact forms with details you have previously entered
- Store your preferred language or region setting
- Remember display preferences
4.4 Marketing and targeting cookies
What they are. Marketing and targeting cookies track your browsing activity across our Website, and potentially across other websites, to build a profile of your interests and to display advertisements that are relevant to you. These cookies are typically set by third-party advertising networks.
Do we need your consent? Yes. Marketing cookies require your explicit consent. We will not place marketing or targeting cookies without your affirmative opt-in via the Cookie Preference Centre.
Current use. CipherCru does not currently place any marketing or targeting cookies on this Website. This section and the inventory at Section 5 will be updated before any such cookie is introduced.
- Track which website pages you have visited to show you relevant advertisements
- Limit the number of times you see the same advertisement
- Measure the effectiveness of advertising campaigns
- Share data with advertising networks and social media platforms
5. Cookie inventory
The following table describes every cookie this Website currently sets. We review and update this inventory whenever the Website changes. Where we introduce a third-party service that sets cookies, this table is updated before that service goes live, and your consent is sought for any category beyond strictly necessary.
| Cookie name | Provider | Category | Purpose | Type | Duration |
|---|---|---|---|---|---|
| ciphercru-consent | CipherCru | Strictly necessary | Stores the cookie choices you made in the Cookie Preference Centre, the date you made them, the version of this policy they were made against, and a random identifier that links them to our record of that choice (Section 9.3) | Persistent | 12 months |
| ciphercru-first-touch | CipherCru | Performance and analytics | Remembers the campaign parameters of the visit that first brought you to the Website, so that an enquiry you send later can be credited to that campaign | Persistent | 90 days |
| _ga | Google (Google Analytics) | Performance and analytics | Distinguishes one browser from another, so that visits and returning visitors can be counted | Persistent | 2 years |
| _ga_<property ID> | Google (Google Analytics) | Performance and analytics | Keeps the state of the current session, so that the pages viewed in one visit are counted together | Persistent | 2 years |
| __hstc | HubSpot | Performance and analytics | HubSpot's main tracking cookie. Records the time of your first visit, your most recent visit, and the number of visits | Persistent | 6 months |
| hubspotutk | HubSpot | Performance and analytics | Identifies this browser to HubSpot. It is sent with an enquiry you submit, so that your visits can be linked to the enquiry and duplicate records avoided | Persistent | 6 months |
| __hssc | HubSpot | Performance and analytics | Keeps track of the current session, so that HubSpot can tell whether to count a new one | Persistent | 30 minutes |
| __hssrc | HubSpot | Performance and analytics | Records whether you have restarted your browser, so that HubSpot can tell whether a new session has begun | Session | End of session |
Only the first cookie above is set without asking you. It is strictly necessary: it remembers your answer to the consent question, and it is set whichever way you answer. Every other cookie is set only after you accept performance and analytics cookies, and is removed when you withdraw that consent. The Website sets no functional or marketing cookies. Cookieless measurement (Section 4.2) sets no cookie, so it does not appear in this table.
6. Legal bases for cookie processing
6.1 India: DPDP Act 2023 and IT Act 2000
Under Indian law, we rely on the following bases for cookie processing. For strictly necessary cookies, we rely on our legitimate interest in operating a functional and secure website. These cookies are essential to deliver the service you have requested by visiting the Website, and no consent is required. For analytics, functional, and marketing cookies, we rely on your consent as a Data Principal under the DPDP Act 2023. Consent is collected through our Cookie Preference Centre and is freely given, specific, informed, and unambiguous. You may withdraw consent at any time, as described in Section 8.
6.2 European Economic Area and United Kingdom: GDPR and ePrivacy
For users in the EEA and UK, cookie processing is governed by the GDPR and the applicable national implementation of the ePrivacy Directive. Strictly necessary cookies are permitted under legitimate interests (Article 6(1)(f) GDPR) or as technically necessary for the provision of the service, and require no consent. Analytics, functional, and marketing cookies require explicit prior consent (Article 6(1)(a) GDPR; Recital 32) collected through our Cookie Preference Centre. Consent is granular, being sought per cookie category; freely given, not bundled with terms acceptance; and easily withdrawable.
Legitimate Interest Assessment. For any analytical processing where we rely on legitimate interests rather than consent, which we do not do for non-essential cookies but do for cookieless measurement (Section 6.4), we apply a balancing test. The results are available on request.
6.3 California: CCPA and CPRA
For California residents, we note that cookies that share browsing data with third parties, including analytics providers and advertising networks, may constitute “sharing” of personal information under the CCPA and CPRA. We do not sell cookie-derived personal information. If you wish to opt out of the sharing of your personal information through cookies for cross-context behavioural advertising, you may do so through our Cookie Preference Centre or by using the Global Privacy Control browser signal.
6.4 Cookieless measurement
Cookieless measurement, described in Section 4.2, places nothing on your device and reads nothing from it, so it is not subject to the consent requirement that applies to cookies. The limited personal data it can involve, being your IP address as the signal reaches Google and the standard information your browser sends with any request, is processed for one purpose: understanding, in aggregate, how the Website is used.
For individuals in the EEA and UK, we rely on our legitimate interest in that purpose (Article 6(1)(f) GDPR). Our balancing test takes into account that the signal carries no identifier, cannot be used to recognise you across pages or visits, and is not used for advertising, and the assessment is available on request. For individuals in India, the signals are processed only for the purpose set out in this Section and are not combined with any information that identifies you. Wherever you are, you can stop cookieless measurement with the Google Analytics Opt-Out Browser Add-on described in Section 8.3.
7. Third-party cookies
Two third parties place cookies on your device through this Website, and only after you accept performance and analytics cookies. Google places the Google Analytics cookies and HubSpot places the HubSpot tracking cookies, all listed in Section 5. Google Tag Manager, which loads Google Analytics, sets no cookies of its own. We embed no advertising, live-chat or session-recording script.
Google. We use Google Analytics with Google Signals and advertising features switched off. Google's privacy policy is at policies.google.com/privacy, and how Google uses information from websites that use its services is explained at policies.google.com/technologies/partner-sites.
HubSpot. HubSpot is also the customer relationship management system in which we keep enquiries sent through the Website. HubSpot's privacy policy is at legal.hubspot.com/privacy-policy.
Each third party has its own privacy and cookie policies, and CipherCru does not control how it uses the information collected through its cookies beyond the settings and agreements described in this Policy. Where we introduce another such service, we will name the provider and link its privacy and opt-out pages in this section before the service goes live, update the inventory at Section 5, and, for any category beyond strictly necessary, seek your consent before the first cookie is set.
8. How to manage and opt out of cookies
You have multiple ways to control the cookies placed on your device.
8.1 Cookie Preference Centre
The most convenient way to manage your cookie preferences is through our Cookie Preference Centre, which you can open at any time from the "Cookie preferences" control in the footer of any page on this site.
The Cookie Preference Centre allows you to review the cookies we use by category; accept or decline each category of non-essential cookies individually; update your preferences at any time; and withdraw previously given consent.
Your preferences are stored in a first-party cookie (ciphercru-consent) for up to 12 months, after which you will be asked to confirm your preferences again.
8.2 Browser settings
You can control cookies through your browser settings. Most browsers allow you to view cookies currently stored on your device; delete all or selected cookies; block all cookies from being placed; block third-party cookies only; and receive a notification before a cookie is placed.
| Browser | Cookie settings location |
|---|---|
| Google Chrome | Settings, Privacy and security, Cookies and other site data |
| Mozilla Firefox | Settings, Privacy and Security, Cookies and Site Data |
| Apple Safari | Preferences, Privacy, Manage Website Data |
| Microsoft Edge | Settings, Cookies and site permissions, Cookies and site data |
| Opera | Settings, Advanced, Privacy and security, Cookies |
Note that browser-level cookie blocking applies to all websites you visit, not just the CipherCru Website. Blocking all cookies may impair your experience on many websites.
8.3 Third-party opt-out tools
You can opt out of Google Analytics directly with the Google Analytics Opt-Out Browser Add-on, available at tools.google.com/dlpage/gaoptout. It stops Google Analytics sending any information from your browser, including the cookieless measurement described in Section 4.2. The Website uses no advertising cookies. If it does in future, you may also use Google Ad Settings for ad personalisation; the Digital Advertising Alliance opt-out at optout.aboutads.info; the Network Advertising Initiative opt-out at optout.networkadvertising.org; and Your Online Choices at youronlinechoices.com for the EU.
8.4 Global Privacy Control
We recognise and honour the Global Privacy Control (GPC) browser signal. If your browser or browser extension sends a GPC signal and you have not already made a choice, we treat it as a refusal of every non-essential cookie: no performance and analytics, functional or marketing cookie is set, and the HubSpot tracking code does not load. The consent banner still appears and tells you that your signal has been applied, and you remain free to accept any category yourself.
Cookieless measurement (Section 4.2) sets no cookie and is not used for advertising, so it continues for a browser that sends GPC exactly as it does for any visitor who has not accepted analytics cookies. We do not sell or share personal information for cross-context behavioural advertising, so a GPC signal requires no further change. GPC is supported by browsers including Firefox and Brave, and by browser extensions available for Chrome and other browsers.
8.5 Mobile device settings
On mobile devices, you can typically control advertising identifiers (IDFA on iOS, GAID on Android) through your device privacy settings. On iOS, use Settings, Privacy and Security, Tracking, and disable Allow Apps to Request to Track. On Android, use Settings, Privacy, Ads, and opt out of Ads Personalisation.
9. Cookie consent banner and preference centre
9.1 First visit: consent banner
When you first visit the Website, you will be presented with a cookie consent banner that informs you that we use cookies; provides a brief description of each cookie category; allows you to accept all, reject all non-essential cookies, or manage your preferences individually; and links to this Cookie Policy and our Privacy Policy.
We do not place non-essential cookies before you have made a choice. If you close the banner without making a choice, only strictly necessary cookies will be placed. Cookieless measurement (Section 4.2) runs from your first page view whichever way you choose, because it places nothing on your device.
9.2 Consent standards
Our cookie consent mechanism is designed to meet the following standards.
- Freely given: consent is not a condition of accessing the Website. You can use the Website with only strictly necessary cookies.
- Specific: consent is sought separately for each category of non-essential cookies.
- Informed: each category is clearly described with examples of the cookies used.
- Unambiguous: consent is obtained through a clear affirmative action, whether clicking Accept or enabling a toggle. There are no pre-ticked boxes.
- Withdrawable: you can withdraw consent at any time through the Cookie Preference Centre.
- Documented: for each consent event we log the timestamp, the choices made, the version of this Policy, and whether a Global Privacy Control signal was present.
9.3 Consent records
We retain records of your consent choices, including the timestamp, the version of the cookie policy in effect at the time, the choices made, and whether your browser sent a Global Privacy Control signal, for a period of three (3) years as evidence of compliance. These records are stored securely in our own database. They are linked to your browser only by a random identifier held in the consent cookie, and do not contain your name or IP address.
9.4 Consent expiry and renewal
Your cookie consent choices are valid for 12 months. After this period, we will ask you to confirm your preferences again. You may update your preferences at any time before this period expires by opening the Cookie Preference Centre.
10. Impact of disabling cookies
If you choose to disable cookies beyond strictly necessary cookies, the following may be affected.
| Category disabled | Potential impact |
|---|---|
| Strictly necessary (if blocked via browser) | The Website may not function correctly. You may not be able to navigate between pages, submit enquiry forms, or access secure sections, and the Website will be unable to remember your cookie choices. We strongly advise against blocking strictly necessary cookies. |
| Analytics | Google Analytics falls back to cookieless measurement, so visits are counted less precisely, and the HubSpot tracking code does not load, so our team will not see which pages you read before contacting us. This does not affect your ability to use the Website or to send us an enquiry. |
| Functional | Personalised features may not work as expected. Your language and display preferences may not be remembered between sessions. |
| Marketing | You will not receive targeted advertisements from CipherCru on other websites or social media platforms. You may still see generic advertisements not tailored to your interests. |
11. Cookies and personal data
11.1 When cookies process personal data
Some cookies, particularly analytics, functional, and marketing cookies, may process personal data about you, including your IP address (even when anonymised, the full IP is briefly processed), device identifiers, browsing behaviour, and inferences about your interests. Where cookies process personal data, the processing is governed by our Privacy Policy. If you accept performance and analytics cookies and later send us an enquiry, HubSpot links the pages this browser visited to that enquiry, and that browsing history becomes part of the personal data we hold about you.
11.2 Data collected through cookies
Through cookies and similar technologies, we may collect:
- IP address, anonymised for analytics purposes where possible
- Browser type, version, and language
- Device type and operating system
- Referring URL and exit URL
- Campaign parameters from the link that brought you to the Website
- Which calls to action and forms you use, but never what you type into a form
- Pages visited and time spent on each page
- Click paths and interaction data
- Geographic location derived from IP address, at country and city level
- Unique device identifiers
11.3 Your data rights
Your rights as a data principal or data subject apply equally to personal data collected through cookies. Please refer to Section 10 of our Privacy Policy for details of your rights and how to exercise them. To exercise your rights in relation to cookie-derived data, contact us at privacy@ciphercru.com.
11.4 Retention of cookie data
Cookies expire after the durations listed in Section 5. Google Analytics keeps the event data it collects, including cookieless measurement, for 14 months. Browsing history that HubSpot links to an enquiry is kept for as long as the enquiry itself, as set out in our Privacy Policy. Consent records are kept for three years (Section 9.3).
12. International considerations
12.1 Data transfers
Google and HubSpot may process data collected through cookies and cookieless measurement outside India and the EEA, including in the United States. Such transfers are subject, in respect of Indian residents, to the DPDP Act and applicable transfer rules, and in respect of EEA and UK residents, to Standard Contractual Clauses or other approved transfer mechanisms under the GDPR. For more details on international data transfers, please refer to our Privacy Policy.
12.2 EEA and UK visitors
For visitors from the EEA or UK, our cookie consent mechanism is designed to comply with the requirements of the GDPR and the applicable national ePrivacy law implementing EU Directive 2002/58/EC as amended. We obtain prior, informed, and specific consent before placing non-essential cookies. Cookieless measurement, which stores and reads nothing on your device, relies on the legitimate interest described in Section 6.4.
12.3 Indian visitors
For visitors from India, our cookie consent mechanism is designed to comply with the DPDP Act 2023 and the IT Act 2000. We seek consent before placing non-essential cookies and provide clear mechanisms for withdrawing consent. Cookieless measurement is processed only for the purpose described in Section 6.4.
12.4 United States visitors
For visitors from California, we honour opt-out requests via the Cookie Preference Centre and the Global Privacy Control signal, as described in Section 8.4. We do not sell cookie-derived personal information, and we do not use sensitive personal information collected via cookies for targeted advertising.
13. Changes to this Cookie Policy
13.1 Updates. We update this Cookie Policy periodically to reflect changes in the cookies we use, changes in applicable law, or changes in third-party services integrated into the Website. We will update the last-updated date at the top of this Policy whenever we make changes.
13.2 Material Changes. If we make material changes, for example adding a new category of cookies, adding new third-party providers whose cookies may process your personal data in new ways, or changing the legal basis for cookie processing, we will display a prominent notice on the Website and reset your cookie consent banner so that you can review and re-confirm your preferences, and may also send an email notification to subscribers or registered contacts where we hold your email address.
13.3 Review Your Preferences. We encourage you to review this Policy and your cookie preferences periodically. You can update your preferences at any time from the "Cookie preferences" control in the footer of any page on this site.
14. Contact us
For questions, concerns, or requests relating to our use of cookies or this Cookie Policy, please contact us at:
- Entity
- CipherCru Innovations Private Limited, attention: Privacy and Cookie Compliance
- Registered office
- 602, The Elysian, A-31, Swej Farm Circle, Swej Farm, New Sanganer Road, Sodala, Jaipur, Rajasthan 302019, India
- privacy@ciphercru.com
- Cookie Preference Centre
- Open it from the "Cookie preferences" control in the footer of any page on this site
For complaints relating to cookie-based personal data processing, you may also contact our Grievance Officer as detailed in our Privacy Policy, or raise a complaint with the relevant supervisory authority: the Data Protection Board of India, the ICO for UK residents, or your national supervisory authority for EEA residents.
Schedule A: Definitions
- Analytics Cookies
- Cookies that collect information about how visitors use the Website. Google Analytics reports it in aggregate; HubSpot can link it to an enquiry you send.
- CCPA and CPRA
- California Consumer Privacy Act and California Privacy Rights Act.
- Cookie
- A small text file placed on your device by a website server.
- Cookie Preference Centre
- CipherCru's online tool allowing users to manage their cookie preferences.
- Cookieless Measurement
- The measurement signals Google Analytics sends without setting or reading any cookie or identifier on your device, described in Section 4.2.
- DPDP Act
- Digital Personal Data Protection Act 2023 (India).
- ePrivacy Directive
- EU Directive 2002/58/EC on privacy and electronic communications, as amended.
- First-Party Cookie
- A cookie set directly by the CipherCru Website.
- Functional Cookies
- Cookies that enable personalised features and preference-remembering.
- GDPR
- General Data Protection Regulation (EU) 2016/679.
- GPC
- Global Privacy Control, a browser signal indicating opt-out of data sharing.
- IT Act
- Information Technology Act 2000 (India).
- Marketing and Targeting Cookies
- Cookies used to deliver relevant advertisements and track campaign performance.
- Persistent Cookie
- A cookie that remains on your device after your browser session ends.
- Session Cookie
- A temporary cookie deleted when you close your browser.
- Strictly Necessary Cookies
- Cookies essential for the Website to function, not requiring consent.
- Third-Party Cookie
- A cookie set by a domain other than the CipherCru Website.
- UK GDPR
- GDPR as retained in UK law following Brexit.
- Website
- https://www.ciphercru.com and all associated subdomains operated by CipherCru.