Skip to content

Cookie Policy

Exactly what we store in your browser, and why

Last updated: 19 July 2026

This Cookie Policy explains how Shally, operated by Sumvaik Management Consulting Private Limited, uses cookies and similar browser storage. It supplements our Privacy Policy. Cookies are small text files a website stores in your browser; local storage is a similar browser mechanism that persists until cleared.

Shally is deliberately light on tracking: every cookie we set today is first party, and we currently set no analytics or advertising cookies. The consent manager includes Analytics and Marketing categories so that, if we ever introduce such cookies, they stay off unless you opt in.

1. Cookies We Set

NameProviderCategoryPurposeDuration
shally_tokenShally (first party)Strictly necessaryKeeps you signed in to your workspace. HttpOnly session token — not readable by page scripts.30 days
shally-csrfShally (first party)Strictly necessaryProtects forms and API requests against cross-site request forgery (double-submit pattern).24 hours
shally_cookie_consentShally (first party)Strictly necessaryRecords the cookie choices you made in the consent banner so we do not ask again.182 days (~6 months)
meta_oauth_csrfShally (first party)Strictly necessaryShort-lived security state while you connect a Meta (Facebook/Instagram) integration.15 minutes
email_oauth_stateShally (first party)Strictly necessaryShort-lived security state while you connect an email account integration.15 minutes

The integration sign-in cookies (meta_oauth_csrf, email_oauth_state) are only set during the few minutes you are connecting that integration, and only if you use it.

2. Local Storage We Use

KeyCategoryPurposeDuration
shally_cookie_consentStrictly necessaryLocal copy of your cookie choices (mirrors the consent cookie).Until you clear browser data
shally_chat_sessionFunctionalRemembers your live-chat conversation so it survives a page reload.Until you clear browser data
shally_support_dismissedFunctionalRemembers that you dismissed the live-chat prompt.Until you clear browser data

3. Third-Party Services

  • Sentry (error monitoring): we use Sentry to capture application errors. In our configuration Sentry does not set cookies, does not receive personal data by default, and session replay is off except when an error occurs.
  • Payment pages: checkout pages hosted by Razorpay or Stripe run on their own domains and may set their own cookies there, governed by their policies. We never see or store your card details.

4. Managing Your Choices

You can change your consent for non-essential categories at any time with the “Manage cookie preferences” button above (also available on the Privacy Policy and Your Privacy Choices pages). You can also delete or block cookies in your browser settings — blocking the strictly necessary cookies will prevent sign-in from working.

5. Changes to This Policy

If we add, remove or change a cookie, we will update this page and the last-updated date above. If a change introduces a new non-essential category, we will ask for your consent again before it activates.

6. Contact

Questions about cookies or this policy: hello@shally.io