Legal

Cookie Policy

Last updated: April 13, 2026

1. What Are Cookies

Cookies are small text files stored on your device when you visit a website. They help the website remember your preferences, keep you signed in, and understand how you use the service.

2. Cookies We Use

CookiePurposeDuration
next-auth.session-tokenKeeps you signed in to your account24 hours
onekof-admin-tokenAdmin panel authentication8 hours
next-auth.csrf-tokenProtects against cross-site request forgerySession
themeRemembers your light/dark mode preference1 year
languageRemembers your language selection1 year

3. Essential vs Non-Essential

All cookies used by Onekof are essential. We do not use advertising cookies, social media tracking pixels, or third-party analytics cookies. Every cookie listed above is required for the platform to function correctly.

4. Cookie Security

  • Session cookies are set with HttpOnly flag — they cannot be accessed by JavaScript.
  • In production, all cookies use the Secure flag — they are only sent over HTTPS.
  • Cookies are scoped to your organization's subdomain to prevent cross-tenant access.
  • SameSite=Lax is set on all cookies to prevent CSRF attacks.

5. Managing Cookies

You can delete cookies through your browser settings. However, disabling essential cookies will prevent you from signing in to Onekof. Since we only use essential cookies, there is no opt-out mechanism — all cookies are required for the Service to function.

6. Contact

For questions about our cookie practices, contact us at privacy@onekof.com.