Cookie Notice
Last updated July 16, 2026
This Cookie Notice explains how SmartVault (operated by SmartVault Technologies LTD) uses cookies and similar technologies on smartvaultapp.io and the SmartVault platform. It supplements our Privacy Policy.
The short version. SmartVault uses only the cookies it needs to sign you in, remember your choices, and protect its forms from bots. We do not use advertising cookies, we do not use analytics cookies, and we do not track you across other websites. We do not sell or share your information for advertising.
1. What cookies are
A cookie is a small text file a website stores on your device. Cookies let a site remember things between page loads and visits — for example, that you are signed in. Some cookies are set by us (first-party); a small number are set by a service we use to secure our forms (third-party).
2. The cookies we use
SmartVault uses two kinds of cookie only: strictly necessary (the platform cannot work without them) and functional (they remember your choices or your place in a flow). We use no advertising, marketing, or cross-site tracking cookies.
| Cookie | Type | Purpose | Retention |
|---|---|---|---|
next-auth.session-token (first-party) | Strictly necessary | Keeps you signed in to your account after you log in. Without it you would be logged out on every page. | Session; up to 30 days if you choose “stay connected”. |
next-auth.csrf-token (first-party) | Strictly necessary | Protects the sign-in form against cross-site request forgery. Set by our authentication library. | Session. |
next-auth.callback-url (first-party) | Strictly necessary | Remembers where to return you after you sign in. Set by our authentication library. | Session. |
smartvault-facility-id (first-party) | Functional | Remembers which facility you last selected in the facility switcher, so you return to the same site view. | Up to 1 year. |
sv-demo-lead (first-party) | Functional | Set only if you enter the product demo, so you are not asked for your details again on a return visit. | Up to 1 year. |
sv-onboard (first-party) | Strictly necessary (sign-up) | Set only during operator sign-up, to preserve your progress through the sign-up steps. | Up to 7 days. |
| Cloudflare Turnstile (third-party) | Strictly necessary (security) | Set by Cloudflare on our sign-in and sign-up forms (login, operator sign-up, and member registration) to distinguish real people from bots. It performs a bot check, not advertising. | Short-lived, per Cloudflare. |
The three next-auth.* cookies are set by our authentication library; in production they carry the browser security prefixes __Secure- or __Host- (for example __Secure-next-auth.session-token). Because every cookie above is either strictly necessary or a functional cookie you trigger by using a specific feature, SmartVault does not display a cookie consent banner: there are no advertising or analytics cookies to consent to.
3. What we do not use
- No advertising or marketing cookies, and no ad-network trackers.
- No analytics cookies and no cross-site or behavioural tracking.
- No selling or “sharing” of your information for targeted advertising (as those terms are defined under applicable US state laws).
4. Managing cookies
Most browsers let you view, block, or delete cookies through their settings. Because our cookies are strictly necessary or functional, blocking them will affect how the platform works — for example, blocking the session cookie will stop you being able to stay signed in.
5. Changes to this notice
If we ever introduce a new category of cookie, we will update this notice and the cookie section of our Privacy Policy before doing so, and — where the law requires consent — ask for it first.
6. Contact
Questions about this notice? Email us at legal@smartvaultapp.io.