Cookie Policy
Every cookie canopussoft.com sets, named individually, with its purpose and lifetime — and a plain account of what will change on the checkout page once online payment is live.
This site sets exactly two cookies, both strictly necessary: a CSRF token and a session cookie, each required for the enquiry form to submit. There is no analytics, no tag manager and no advertising or cross-site tracking, so there is no consent banner. This page names both cookies and explains what changes when checkout goes live.
1. What this policy covers
A cookie is a small text file a website asks your browser to store and send back on later requests. Most sites use them for three jobs — keeping a session working, measuring traffic, and following you across other sites for advertising. Canopus IT Solutions Private Limited uses them for the first job only.
This policy applies to canopussoft.com and describes the position as at the date above. It sits alongside our privacy policy, which covers the personal data you send us in an enquiry and what we do with it afterwards. Where software we build for a client sets cookies, that is the client's site and the client's policy, not this one — see data processing for how that split works.
2. The two cookies this site sets
Both are first-party, set by canopussoft.com itself. Neither is read by any third party, and neither is available to any other domain.
| Cookie | Purpose | Lifetime | Flags |
|---|---|---|---|
XSRF-TOKEN | Cross-site request forgery token. The enquiry form sends this value back with your submission; if it is missing or does not match, the submission is rejected. It is what stops another site posting a form to us in your name. | Two hours, reissued while you keep browsing | Readable by the page's own script so the form can attach it; samesite=lax |
canopus-it-solutions-session | Identifies your browser's session on our server for the duration of a visit, so a form you started filling in is still associated with you when you press send, and a validation error comes back with your text intact. | Two hours | httpOnly — unreadable by JavaScript; samesite=lax; encrypted value |
Scroll the table sideways for the full detail.
That is the complete list. Neither cookie contains your name, email address or anything you typed. Neither builds a profile, recognises you on a return visit weeks later, or follows you onto another website — the samesite=lax flag on both means your browser will not send them to us from a third-party context. If you never submit the enquiry form, nothing about your visit is recorded on our side beyond the ordinary server request log our host keeps for security and diagnostics.
3. What we deliberately do not run
This site carries no Google Analytics or other analytics product, no Google Tag Manager or comparable container, no advertising or remarketing pixels from Meta, LinkedIn or Google Ads, no session-recording or heatmap tool, no A/B testing script, no chat widget, no embedded social buttons, and no third-party font or script host that would see your IP address on page load.
This is a decision, not a gap. We build analytics pipelines for clients, so the absence is not inexperience: for a business where one qualified enquiry a week matters more than a traffic chart, the tracking was not worth what it costs the person reading the page. If that is ever reversed, this page changes before the script is added, and a consent banner appears with it.
4. Why there is no consent banner
Consent is required for cookies that are not necessary to provide the service you asked for; it is not required for strictly necessary ones. The EU ePrivacy Directive and the UK's PECR both exempt a cookie used solely to provide a service the user has explicitly requested — which is what a CSRF token and a session cookie do for a form you chose to fill in.
Because the two cookies above are the only two we set, there is nothing on this site for you to consent to or refuse. Showing a banner anyway would ask you to accept something we are not doing. If a non-essential cookie is ever introduced, it will be set only after you have actively agreed, with refusal as easy as acceptance and no pre-ticked boxes.
5. Controlling cookies in your browser — and what breaks
You do not need our permission, and there is no setting on our site to change. Every browser lets you block or delete cookies under Settings → Privacy — "Site settings" in Chrome, "Privacy" in Safari, "Cookies and Site Data" in Firefox, "Cookies and site permissions" in Edge. You can block all cookies, block them for canopussoft.com only, or clear what is stored.
Here is the consequence, stated rather than buried: if you block cookies for this site, the enquiry form stops working. Without XSRF-TOKEN the server cannot verify the submission and rejects it, and without the session cookie a validation message cannot be returned to you with what you typed preserved. The rest of the site — every page, every link, every word of content — reads correctly with cookies disabled, because nothing else on it depends on them.
If you would rather not accept cookies at all, email [email protected] or call +91 817 979 7732. An engineer replies within one business day, and email reaches the same person the form would have.
6. What will change when online payment goes live
We are in the process of enabling online invoice payment. It is not live at the time of writing, and nothing in this section runs on the site today — this is advance notice, not a description of current behaviour.
A checkout page will then be added for paying an issued invoice. Card details will be entered on the payment provider's own hosted page or embedded field, never on a form we control, so we do not see or store a card number. The provider handling that transaction will set its own cookies there, typically for fraud screening, 3-D Secure authentication and keeping the payment session intact while you complete it.
The providers we are adopting are Razorpay, CCAvenue, Cashfree and PayU for payments in India, and Stripe and PayPal for international payments. Which one appears will depend on the currency of your invoice and where you are paying from. Two commitments about how they load:
- Checkout page only. Payment provider scripts will load on the checkout page and nowhere else. They will not run on the home page, service pages, case studies or contact page. A visitor who never opens an invoice will never meet them.
- This page updates first. Before a checkout page accepts a live payment, this policy will be updated with the specific cookie names, purposes and lifetimes each provider sets, and a link to that provider's own cookie notice. We will not switch it on and document it afterwards.
Those cookies will be necessary to complete a payment you chose to make, so the same exemption applies. If a provider sets a cookie that is not necessary for the transaction, it will sit behind a consent choice on that page rather than being set on arrival. For how invoices are raised and what a charge on your statement corresponds to, see payment terms.
7. Cookies in software we build for clients
This policy covers canopussoft.com only. When we build an application for a client, the cookies it sets are decided by that client's requirements, and the client publishes its own cookie notice as the controller of that site.
What we bring to those builds: session cookies configured httpOnly and secure by default, samesite chosen deliberately rather than left to whatever the framework ships with, consent captured before any non-essential tag fires where the client's users are in a jurisdiction that requires it, and a written inventory of every cookie the application sets, handed over at go-live so the client's legal team is not reverse-engineering it a year later. Our responsibilities when we handle data on a client's behalf are set out in data processing.
8. Changes to this policy
The date at the top is the date this version took effect. Any change to what this site sets — a new cookie, a changed lifetime, a provider added at checkout — is reflected here at the same time as the change, not afterwards. We keep no public archive of earlier versions; if you need the text as it stood on a given date, ask and we will send it.
9. Questions about cookies
If anything here is unclear, or you believe this site set a cookie not listed above, write to [email protected] or use the form on our contact page. Send the cookie name and the page you saw it on; we will trace it and correct this document if it is ours.
For what happens to the details you send us, read the privacy policy. For the rights you can exercise over that data and how to escalate if our answer does not satisfy you, see grievance redressal.