How Bitscaled uses cookies and similar technologies on bitscaled.tech, including essential cookies, consent-gated analytics, advertising cookies after marketing opt-in, and cookieless Vercel measurement.
Version: COOKIES-v2.1 • Effective Date: August 17, 2026
This Cookies Policy explains how Bitscaled LLC ("Bitscaled," "we," "us," or "our") uses cookies and similar technologies on https://bitscaled.tech and related Bitscaled-operated web applications. It should be read with our Privacy Policy and Terms of Service.
The tables below are generated from our public cookie inventory so the names, providers, durations, and purposes stay aligned with what the site actually sets.
Cookies are small text files a site stores in your browser. They can be first-party (set by Bitscaled) or third-party (set by a provider such as Google or Datadog). Session cookies expire when you close the browser. Persistent cookies last until they expire or you delete them.
Some preferences are stored in browser localStorage, not as HTTP cookies. They are listed here so the distinction is clear:
bitscaled-cookie-consent and bitscaled-theme are not cookies. Clearing site data in your browser removes them along with cookies. They do not transmit to our servers on every request the way an HTTP cookie does.
Essential cookies are required for signed-in sessions, CSRF protection, and abuse prevention on public forms. They do not require consent and cannot be switched off through Cookie Settings. Without them, login, Workspace, Intranet, Admin, and protected forms will not work reliably.
| Name | Provider | Duration | Purpose |
|---|---|---|---|
| auth-session | Bitscaled | Up to 7 days | Encrypted HTTP-only session for signed-in Workspace, Intranet, and Admin users. |
| x-csrf-token | Bitscaled | Session / aligned with the auth cookie | HttpOnly CSRF token compared to the request header on state-changing API calls. |
| x-csrf-token-js | Bitscaled | Session / aligned with the auth cookie | JavaScript-readable CSRF token copy used by authenticated browser clients. |
| refresh-token | Bitscaled | Up to 7 days | HttpOnly refresh credential used to renew signed-in sessions. |
| bitscaled_aff | Bitscaled | Up to 90 days (program default; admin-configurable 1–365 days) | First-party affiliate referral attribution after someone uses a Bitscaled affiliate link. Not a Partner Program cookie. |
| _GRECAPTCHA | Google reCAPTCHA | Set by Google (typically up to 6 months) | Abuse and bot protection on public forms such as contact, login, invitation acceptance, and VaultSandbox spoof-test submissions. |
Current essential cookies are auth-session, refresh-token, x-csrf-token, x-csrf-token-js, bitscaled_aff (first-party affiliate referral attribution), and _GRECAPTCHA (Google reCAPTCHA on public forms such as contact, login, invitation acceptance, and VaultSandbox spoof-test submissions).
Analytics cookies load on public pages only after you allow analytics in the consent banner or Cookie Settings. They help us understand how the public site is used. They are not required to read the site.
| Name | Provider | Duration | Purpose |
|---|---|---|---|
| _ga | Google Analytics 4 | Up to 13 months (Google default; loaded only after analytics consent) | Distinguish unique visitors on public website pages. |
| _ga_* | Google Analytics 4 | Up to 13 months (loaded only after analytics consent) | Persist GA4 session state for consented measurement. |
| _gid | Google Analytics 4 | 24 hours (loaded only after analytics consent) | Distinguish visitors for a 24-hour window. |
| _dd_s | Datadog RUM | Session (loaded only after analytics consent on public pages) | Real-user performance and optional session replay on public pages when Datadog is configured. |
Current analytics cookies are _ga, _ga_*, and _gid (Google Analytics 4) and _dd_s (Datadog RUM on public pages when Datadog is configured). Session replay may run only if enabled in our Datadog configuration and after the same analytics consent; it is not guaranteed on every visit.
Marketing cookies are used for advertising measurement and conversion tracking after you opt in via Cookie Settings. They are not set until advertising storage is granted. Google may also set additional advertising cookies on google.com / doubleclick.net domains that this site cannot delete from first-party JavaScript.
| Name | Provider | Duration | Purpose |
|---|---|---|---|
| _gcl_au | Google Ads / GA4 Conversion Linker | Up to 90 days (loaded only after advertising/marketing consent) | Store ad click information so Google Analytics can measure conversions after you allow advertising storage. |
| _gcl_aw | Google Ads / GA4 Conversion Linker | Up to 90 days (loaded only after advertising/marketing consent) | Attribute Google Ads clicks to later conversions on bitscaled.tech. |
| _gcl_gb | Google Ads / GA4 Conversion Linker | Up to 90 days (loaded only after advertising/marketing consent) | Attribute Google Ads app-to-web or gbraid clicks to later conversions. |
Vercel Web Analytics and Vercel Speed Insights are cookieless. They do not set the cookies listed in this policy and are not part of the analytics-consent toggle. They measure aggregated page performance and traffic on the hosted site.
Google Maps address lookup is used in Intranet CRM (for example, company address autocomplete). It is not loaded on public website pages. Any Google Maps cookies or local data that appear are limited to authenticated Intranet use of that feature, not the public website cookie inventory.
Use Cookie Settings in the website footer, or the consent banner when it is shown, to allow or reject analytics (and marketing, if we later activate that category). Essential cookies stay on. Choosing Essential Only prevents Google Analytics and public Datadog RUM cookies from loading.
Changing Cookie Settings updates the localStorage consent record described above. It does not by itself delete cookies already stored by Google or Datadog; use your browser controls if you want those files removed immediately.
You can also delete or block cookies in your browser settings. Blocking essential cookies will break signed-in features and some forms. Help for common browsers is published by the browser vendor.
Personal information collected through cookies and similar technologies is handled as described in the Privacy Policy. Use of the site is also governed by the Terms of Service.
Questions about cookies: privacy@bitscaled.tech or legal@bitscaled.tech.
Related policies that explain how we operate, protect your data, and provide our services transparently.
How we handle website, account, newsletter, VaultTools, and managed-service data.
Read Privacy PolicyThe rules for using our website, client portal, public tools, and managed services.
Read Terms of ServiceWhat you may and may not do on our website, Client Workspace, public tools, and managed environments.
Read Acceptable Use PolicyNamed cookies, localStorage consent, and how to change analytics preferences.
Read Cookies PolicyProcessor terms for Client Data in managed services and hosted Workspace content.
Read Data Processing AgreementVendors that may process Website Data or Client Data, including optional tools.
Read SubprocessorsCopyright notices, counter-notices, and designated agent contact.
Read DMCA PolicyHow to report security issues in Bitscaled-operated systems in good faith.
Read Vulnerability DisclosureThese documents explain how we handle privacy, terms, cookies, data processing, and acceptable use without implying certifications outside the written policies.
If you have questions about any of our legal documents or need clarification on our policies, our legal team is here to help.