Cookie Policy

Last Updated: 8 May 2026  ·  Effective From: 8 May 2026

This Cookie Policy explains what cookies and similar browser storage technologies we use on the Zapwa platform, why we use them, and how you can control them.

1. Introduction

This Cookie Policy is published by Etechinfo Consultant Pvt. Ltd., the company that operates the Zapwa WhatsApp Business SaaS platform ("Zapwa", "we", "our", or "us"). Our registered office is at H-187, Sector 63, Noida, Uttar Pradesh 201301, India.

This policy covers our use of cookies and similar technologies on zapwa.in (our marketing website) and app.zapwa.in (our platform application). It should be read alongside our Privacy Policy.

We have designed Zapwa with a strong privacy-first approach. We use only the minimum number of cookies and storage mechanisms necessary to operate the Service securely. We do not use advertising cookies, cross-site tracking, or third-party analytics platforms.

2. What Are Cookies?

Cookies are small text files that a website places on your device (computer, smartphone, or tablet) when you visit it. They are stored in your browser and sent back to the website on subsequent visits, allowing the website to remember information about you or your session.

Cookies can be categorised in several ways:

  • First-party cookies — Set by the website you are visiting (in this case, Zapwa). These are the only type of cookies we set directly.
  • Third-party cookies — Set by a domain other than the website you are visiting. Zapwa does not set third-party cookies on its own domains, but third-party services we use (such as Meta and payment gateways) may set their own cookies when you interact with them. See Section 6 for details.
  • Session cookies — Temporary cookies that are deleted when you close your browser. They are used to maintain your session during a single visit.
  • Persistent cookies — Cookies that remain on your device for a specified period or until you delete them. They allow the website to remember your preferences across visits.

In addition to cookies, Zapwa uses browser localStorage — a mechanism built into modern browsers that allows websites to store data locally on your device without an expiry date. Unlike cookies, localStorage data is not sent to our servers with every request; it is accessed and modified only by JavaScript running on our domain.

3. Why We Use Cookies

Zapwa uses cookies and browser storage technologies for the following purposes:

  • Authentication: To identify you as a logged-in user and maintain your session securely across pages and requests. Without authentication cookies and storage, you would be required to log in on every page request.
  • Security: To prevent Cross-Site Request Forgery (CSRF) attacks, which are a class of security vulnerability where a malicious website tricks your browser into making unauthorised requests to a site where you are logged in.
  • User preferences: To remember your preferred theme (light or dark mode) and, in future, language settings, so you do not need to reconfigure them on every visit.
  • Performance and error monitoring: We collect first-party, aggregated data about platform performance and errors to detect and resolve issues. This data does not identify individual users and is not shared with third parties.

We do not use cookies for:

  • Advertising or retargeting (we run no ad campaigns that require tracking cookies);
  • Cross-site behavioural tracking;
  • Third-party analytics such as Google Analytics or Adobe Analytics;
  • Social media tracking (no Facebook Pixel, Twitter Pixel, or similar);
  • Profiling users for marketing purposes.

4. Types of Cookies We Use

Strictly Necessary Cookies

These cookies are essential for the Zapwa platform to function. Without them, you cannot log in, navigate between pages securely, or use core features of the Service. Because these cookies are strictly necessary, we do not require your consent to set them, and they cannot be disabled without breaking the platform.

Strictly necessary cookies include your authentication token (JWT), CSRF protection token, and session management cookies.

Functional Cookies

These cookies and localStorage items allow the platform to remember choices you make (such as your preferred theme or language) to provide a more personalised experience. They are not essential to the core function of the Service — if you disable them, the Service will still work, but you may lose your saved preferences.

Functional storage includes your UI theme preference (light/dark mode) and language preference.

Analytics Cookies

We collect first-party, aggregated usage analytics on the Zapwa platform — such as which features are most used, which pages generate the most errors, and overall platform performance metrics. This data is collected without identifying individual users and is never shared with third-party analytics providers. We do not use Google Analytics, Mixpanel, Amplitude, Heap, or any other third-party analytics platform. Our analytics cookies and storage do not track you across other websites.

Marketing Cookies

We currently do not use marketing, retargeting, or advertising cookies on any Zapwa domain. If we introduce any marketing cookies in the future — for example, to measure the effectiveness of our own advertising campaigns — we will update this policy, add these cookies to the table in Section 5, and obtain your prior consent before setting them.

5. Specific Cookies and Storage Items

The following table lists all cookies and browser storage items currently used by the Zapwa platform. This table is kept up to date as we add or remove technologies:

NameTypeStorage MechanismPurposeExpiry3rd Party?
zapwa_access_tokenEssentiallocalStorage (browser)Stores your JWT authentication token so you remain logged in during and across sessions. Cleared automatically when you log out.Session / until logoutNo
__Host-zapwa-csrfEssentialCookie (HttpOnly, Secure)CSRF (Cross-Site Request Forgery) protection token. Prevents malicious websites from making unauthorised requests to our platform on your behalf.SessionNo
zapwa_refresh_tokenEssentialCookie (HttpOnly, Secure, SameSite=Strict)Stores an encrypted refresh token to allow seamless re-authentication when your access token expires, without requiring you to log in again.30 daysNo
zapwa_themeFunctionallocalStorage (browser)Stores your preferred UI theme (light or dark mode) so your preference is remembered across sessions.Persistent (until cleared)No
zapwa_langFunctionallocalStorage (browser)Stores your preferred interface language. Currently defaults to English; additional languages may be added in future.Persistent (until cleared)No
__next_hmr_refreshTechnical (Dev Only)CookieNext.js development-only hot module replacement signal. This cookie is NEVER present in the production environment. It appears only in local development builds.SessionNo

This table was last reviewed on 8 May 2026. We update it whenever we add or remove cookies or storage items.

6. Third-Party Cookies

While Zapwa does not set third-party cookies on its own domains, the following third-party services may set cookies on their own domains when you interact with them through Zapwa:

Meta / WhatsApp (Embedded Signup)

When you connect your WhatsApp Business Account using Meta's Embedded Signup flow, a Meta popup or iframe is loaded in your browser. Meta may set its own cookies on the facebook.com or whatsapp.com domains during this process. These cookies are set by Meta, not by Zapwa, and are governed by Meta's Cookie Policy. Zapwa does not read or control these cookies.

Payment Gateway (Razorpay / Stripe)

When you make a payment through our subscription checkout, you are redirected to or presented with an interface from our payment gateway (Razorpay for Indian customers; Stripe for international customers). These payment providers may set their own cookies for fraud prevention, session management, and payment security. These cookies are governed by Razorpay's and Stripe's own privacy and cookie policies. Zapwa does not receive or store any payment card information; only a transaction ID and payment status are shared with us.

We have no control over the cookies set by Meta or payment gateways. We recommend reviewing their respective cookie policies if you have concerns about those cookies.

7. How to Control Cookies

You have several options for controlling cookies. Please be aware that blocking essential cookies will prevent you from logging in to Zapwa and using the platform, as these cookies are required for authentication and security.

Browser Settings

Most browsers allow you to view, manage, and delete cookies through their settings. You can typically: view what cookies are stored, delete individual cookies or all cookies, block cookies from specific sites, and set your browser to block all third-party cookies. Below are links to cookie management instructions for major browsers:

Clearing localStorage

Browser localStorage is not cleared by the cookie deletion tools in most browsers. To clear localStorage data stored by Zapwa, you can:

  • Log out of Zapwa (this clears the authentication token stored in localStorage);
  • Use your browser's Developer Tools: press F12 (or Cmd + Option + I on Mac), navigate to the Application tab, select Local Storage in the sidebar, then right-click on https://app.zapwa.in and select Clear.

Important: Blocking or deleting essential cookies (particularly the authentication token and CSRF token) will prevent you from logging in to Zapwa. If you need to use the Service, these cookies must be permitted for the app.zapwa.in domain.

8. Do Not Track Signals

Some browsers include a "Do Not Track" (DNT) feature that signals to websites that you do not want to be tracked. There is currently no universally agreed standard for how websites should respond to DNT signals, and the DNT specification has not been formally adopted by any Indian regulatory body or by the DPDP Act framework.

Zapwa does not currently alter its behaviour in response to DNT signals, because we do not perform cross-site behavioural tracking regardless of whether a DNT signal is present. We do not place advertising cookies, we do not use third-party analytics platforms, and we do not share browsing data with advertising networks. In this respect, we already behave as though DNT is always enabled for all users.

If the Government of India issues guidance or regulations under the DPDP Act 2023 that require a specific response to DNT signals, we will update our practices and this policy accordingly.

9. Updates to This Cookie Policy

We may update this Cookie Policy from time to time to reflect changes in the technologies we use, changes in applicable law, or improvements to our privacy practices. When we add new cookies or remove existing ones, we update the table in Section 5 and revise the "Last Updated" date at the top of this page.

For material changes — such as the introduction of analytics or functional cookies that we do not currently use — we will notify you via email to your registered address and/or via an in-app notice at least 30 days before the change takes effect, and will obtain your consent where required by law.

We encourage you to review this Cookie Policy periodically to stay informed about our cookie practices.

10. Contact

If you have questions or concerns about our use of cookies or this Cookie Policy, please contact us:

Email: privacy@zapwa.in

General: hello@zapwa.in

Phone: +91 9953153142

Address: Etechinfo Consultant Pvt. Ltd., H-187, Sector 63, Noida, Uttar Pradesh 201301, India

For data deletion requests or to exercise your rights under the DPDP Act 2023, please see our Data Deletion Instructions or our full Privacy Policy.