Legal

Cookie notice

Version 1.0 · Effective from September 9, 2026

This notice lists every cookie and every browser-storage entry the YouSignDigital platform uses. It is generated from the platform's live configuration rather than written by hand, so the names and lifetimes below are the ones your browser really receives.

1. What cookies and local storage are

A cookie is a small text file the platform asks your browser to keep and to send back with each request; local storage is a similar space that stays in your browser and is never sent to our servers. We use them only for what is strictly necessary to operate the Service: keeping you signed in and remembering a display preference. No consent banner is shown because no optional cookie exists.

2. Cookies set by the platform

The table below is the complete inventory. The session cookie PHPSESSID is created as soon as you open the sign-in page (it carries the anti-forgery token of the sign-in form) and is used for the whole signed-in session; the persistent cookie REMEMBERME (7 days) is only issued when a sign-in explicitly asks to be remembered.

Name Purpose When it is set Lifetime Protection
PHPSESSID
Strictly necessary
Keeps you signed in and protects forms against cross-site request forgery. When you open the sign-in page and while you are signed in Until you close your browser
Server-side: discarded after 24 minutes of inactivity
HttpOnly (not readable by scripts)
SameSite=lax
Secure (sent over HTTPS only)
REMEMBERME
Strictly necessary
Keeps you signed in across browser restarts when you asked to be remembered; it is signed with your credentials, so it is invalidated as soon as they change or your account is deactivated. Never on this installation — the sign-in form offers no "remember me" option, so this cookie is not issued (a successful sign-in even asks your browser to delete it). It is listed because the firewall still defines it and it would be issued if that option were added. 7 days HttpOnly (not readable by scripts)
SameSite=lax
Secure (sent over HTTPS only)
Anti-forgery token Protects forms and state-changing actions against cross-site request forgery. When a protected form is displayed Same as the session Stored server-side inside the session — no separate cookie
theme
Local storage (not a cookie)
Remembers your light/dark theme preference. When you toggle the theme Until you clear your browser storage Never sent to the server

3. No tracking, no advertising

The platform sets no analytics, advertising or social-media cookie and no third-party cookie. The API and the SDK use bearer tokens and API keys sent in request headers, never cookies. The public tracking pages set no cookie at all. Measurement here does not use cookies, but it does exist without them: notification e-mails embed a 1×1 open-tracking image and tracking links are logged, both recording the date and time, the IP address and the browser identification of the reader — see "Public tracking pages" in the privacy policy. The only third-party servers your browser contacts are the following resource hosts, which receive your IP address as a technical necessity of serving the file:

  • fonts.googleapis.com, fonts.gstatic.com — Inter web font delivered by Google Fonts (Google LLC) — loaded by every page that uses the application stylesheet: the administration interface, the sign-in page and these legal pages

4. Browser local storage

The administration interface stores your light/dark theme preference in your browser's local storage under the key "theme". It contains only the chosen theme, never leaves your browser and can be cleared from your browser settings at any time.

5. Managing cookies

You can delete or block cookies in your browser settings. Blocking the session cookie makes it impossible to sign in to the administration portal; the public tracking pages and this page keep working without it. Signing out deletes the session and the remember-me cookie.

6. Changes to this notice

Because this inventory is generated from the configuration, it always reflects the cookies currently in use. The version number and the effective date above change when the wording of this notice changes.

MITRA — pondy — veeravel.pichaimuthu@it-mitra.com

Version 1.0 · Effective from September 9, 2026