1. What Are Cookies & Web Storage Technologies?
Cookies are compact text files stored on your computer, tablet, or mobile device by your web browser when you access websites and digital applications.
In addition to traditional HTTP cookies, our platform may utilize related browser storage technologies including Local Storage, Session Storage, and IndexedDB to maintain necessary application state, secure user sessions, and store non-sensitive interface preferences between visits.
2. How LayBuild AI Uses Cookies
LayBuild AI relies on cookies and local storage strictly to provide secure, authenticated access to the platform, authenticate administrative operations, protect against cross-site request forgery, and remember user interface settings.
Commitment to Privacy: We do not deploy third-party advertising tracking cookies, behavioral profiling scripts, or data-broker pixels on authenticated customer workspaces or administrative dashboards. We never monetize, sell, or rent cookie telemetry to external advertisers.
3. Categories of Cookies We Deploy
We organize the storage technologies deployed on the Service into three distinct categories:
1. Strictly Necessary Cookies: Essential for platform navigation, user sign-in, session authentication, and security defenses. Disabling these cookies prevents account login and core application functionality.
2. Functional & Preference Cookies: Used to remember user choices (such as preferred dashboard color theme, sidebar collapse status, and conversation panel layout) so your workspace remains customized across browser sessions.
3. Performance & Diagnostic Telemetry: Deployed to measure API latency, identify routing errors, and track platform stability under heavy traffic. Telemetry data is aggregated, pseudonymized, and used solely for platform reliability maintenance.
4. Inventory of Primary Cookies Deployed
Below is an inventory of the primary cookies utilized across the LayBuild AI web application:
- laybuild_token: Strictly Necessary. Stores your encrypted JSON Web Token (JWT) session credential for API authentication. Expiration: 7 days. Attribute: SameSite=Lax; Secure; HttpOnly where supported.
- csrf_token: Strictly Necessary. Protects forms and mutating API requests from Cross-Site Request Forgery attacks. Expiration: End of browser session.
- theme_preference: Functional. Preserves your preferred UI theme configuration across visits. Expiration: 1 year.
- sidebar_state: Functional. Remembers whether navigation sidebars are expanded or collapsed. Expiration: 180 days.
- widget_session_id: Strictly Necessary (Live Chat Widget). Maintains conversation continuity for end-users chatting with customer support agents. Expiration: 24 hours.
5. Third-Party Technologies & Payment Gateways
When you perform billing transactions, our PCI-DSS Level 1 compliant payment gateway providers (Stripe, PayU, and Razorpay) deploy fraud prevention and transaction verification cookies strictly to detect fraudulent payment attempts and securely complete checkouts.
Third-party payment gateways operate under their respective privacy and security policies. We do not store raw cardholder details or CVV numbers on our servers.
6. Managing & Disabling Cookies
Most modern web browsers allow you to control cookie permissions through browser settings. You can configure your browser to reject all cookies, accept only first-party cookies, or alert you whenever a cookie is set.
To manage cookies in your browser:
- Google Chrome: Settings > Privacy and Security > Third-party cookies
- Mozilla Firefox: Settings > Privacy & Security > Cookies and Site Data
- Apple Safari: Preferences > Privacy > Cookies and website data
- Microsoft Edge: Settings > Cookies and site permissions
Please note: If you block strictly necessary cookies (such as laybuild_token), you will be unable to log in to your LayBuild AI account or access authenticated dashboard features.
7. Do Not Track & Global Privacy Control Signals
Certain web browsers support Do Not Track (DNT) or Global Privacy Control (GPC) signals designed to communicate privacy choices to websites. Because LayBuild AI does not track users across third-party websites or engage in behavioral ad targeting, our default data collection already adheres to the protections intended by DNT and GPC protocols.
8. Storage Duration & Expiration
Cookies deployed by our platform are classified by duration:
Session Cookies: Temporary cookies that exist only while your browser is open and are purged automatically when you close your browser window.
Persistent Cookies: Cookies that remain on your device for a defined retention period (ranging from 24 hours to 1 year) or until manually cleared, allowing the platform to recognize returning users and restore authenticated sessions.
9. Changes to This Cookie Policy
We may periodically update this Cookie Policy to reflect new technical capabilities, updated security standards, or regulatory guidance. Material revisions will be reflected with an updated "Last updated" date at the top of this document, and notifications will be issued through workspace dashboards or email where appropriate.
10. Contact Information
If you have questions regarding our use of cookies or related browser storage mechanisms, please reach out to our privacy and security team:
Email: [email protected]
Security Desk: [email protected]
Postal: LayBuild AI Platform, Privacy & Compliance Office