Cookie Policy
1. Cookies and Similar Technologies
Cookies are small text files stored on your device (computer, tablet, or mobile) when you visit a website. They help websites remember information about your visit, such as your authentication status, which makes your next visit easier and the site more useful to you.
Cookies may be "session cookies" (deleted when you close your browser) or "persistent cookies" (they remain on your device for a set period or until you delete them).
This policy also covers similar technologies that store or read data on your device — principally your browser's localStorage and sessionStorage. European law (the ePrivacy Directive, Article 5(3)) treats these the same way it treats cookies, so we ask for consent on the same basis. Where this policy says "cookies", read it as "cookies and similar technologies".
2. Your Consent Choices
The first time you visit EngageDM, a consent banner asks you to choose. Nothing optional is stored on your device before you make that choice, and simply continuing to browse is not treated as consent.
2.1 The three choices
- Accept all — allows the strictly necessary cookies plus the optional Preferences, Analytics and Marketing categories.
- Reject non-essential — allows only the strictly necessary cookies. The platform works normally; settings such as your theme simply are not remembered between visits.
- Reject all cookies, including essential — we honour this in full: your session is ended, the cookies already stored are cleared, and the platform is disabled for you until you allow essential cookies again. This is offered because a genuine refusal must be possible, and because EngageDM cannot securely operate without a session cookie and a CSRF token. Your refusal is remembered in a single session-scoped cookie so that we can keep honouring it — it disappears when you close your browser.
2.2 How your choice is recorded
Your decision is stored in one cookie, edm_cookie_consent, containing the categories you allowed, a version number, a timestamp, and a randomly generated consent reference. An acceptance is kept for 6 months, after which we ask again; a refusal is kept only for the browser session.
2.3 Our record of your choice
Data protection law requires us to be able to demonstrate that you consented — not merely to assert it (GDPR Article 7(1); an equivalent duty falls on us as Data Fiduciary under DPDP Section 6). A cookie alone cannot do that, because it lives on your device and vanishes when you clear your browser. So each time you make a choice we also write one row to our own consent log, recording:
- the consent reference — a random identifier with no meaning outside this log, used to keep your successive choices in order so we can show that a withdrawal was received and acted on;
- which categories you allowed, the version of this policy in force, and the date and time;
- the page you made the choice on and your browser's user-agent string;
- a salted, one-way hash of your IP address — enough to corroborate a record, but not reversible back to your IP;
- your account id and email, only if you were signed in at the time.
This log is append-only: we never edit or overwrite a row, because the ordered history is the evidence. It is used for compliance and dispute-resolution only — never for analytics, profiling, advertising, or building any picture of you. Records are kept for 3 years and then deleted. If you delete your EngageDM account, we remove your account id and email from these rows rather than deleting them, so the proof that consent was lawfully collected survives without remaining linked to you. Our legal basis for keeping it is GDPR Article 6(1)(c) — compliance with a legal obligation.
You can ask us for a copy of your consent history, or raise a query about it, using the contact details in section 10.
2.4 Preventing referral fraud
There is one further place we use the consent reference, and we would rather set it out plainly than bury it. Our Partnership Program pays a commission when someone you refer buys a plan. That creates an obvious temptation: open a second account, refer yourself, and collect a commission on your own purchase. To detect it we record, against your account, the consent reference of the browsers you sign in from and a salted, one-way hash of the IP address you sign in from. When a referral commission is about to be paid, we check whether the two accounts involved look like one person.
- We set no additional cookie for this — it reuses the consent reference already described above.
- We store no raw IP address; the hash cannot be reversed back to your IP.
- It is used only to decide whether a partner commission should be paid or checked by a person first. It is never used for analytics, advertising, profiling, or anything that affects your own account, your plan, or what you are charged.
- These records are kept for 6 months from the last time you signed in from that browser, and are deleted with your account.
Our legal basis is legitimate interests (GDPR Article 6(1)(f)) — preventing fraud, which Recital 47 recognises as a legitimate interest — and the corresponding legitimate use under the DPDP Act. You can object to this processing using the contact details in section 10.
2.4 Legal bases
- Strictly necessary cookies — no consent is required under ePrivacy Article 5(3) / UK PECR Regulation 6(4), because they are essential to provide the service you requested. Any associated personal data is processed under GDPR Article 6(1)(b) (performance of a contract) and 6(1)(f) (legitimate interest in securing the service).
- All other categories — consent only, under GDPR Article 6(1)(a) and, for users in India, Section 6 of the Digital Personal Data Protection Act, 2023. Consent is free, specific, informed, unambiguous, and as easy to withdraw as it is to give.
3. How We Use Cookies
EngageDM uses cookies for the following purposes:
- Authentication: To keep you signed in to your account across pages and browser sessions.
- Security: To help protect your account against cross-site request forgery (CSRF) attacks and to secure the OAuth and two-factor authentication flows.
- Session state: To remember which Instagram account (workspace) you last had active.
- Consent: To record and honour your cookie choices.
- Dismissals you asked for: To remember that you finished or skipped a guided product tour, or hid the getting-started checklist, so neither reopens on your next page.
- Preferences (optional): To remember your light/dark theme.
- Product analytics (optional): To understand which features are used and where people get stuck, so we can fix and improve them — for example, how many people finish setting up an automation. See section 4.3.
- Referral discounts (optional, Marketing): If you arrived through a partner's referral link, to remember that referral code so your discount is applied at checkout and the partner is credited.
4. Categories We Use
4.1 Strictly necessary Always active
These are required for EngageDM to work and cannot be switched off in our systems. They are set in response to actions you take — signing in, switching workspace, submitting a form, closing a prompt, or recording a cookie choice.
| Name | Purpose | Duration |
|---|---|---|
token |
Stores your authenticated session JWT. Required to keep you logged in across pages and browser sessions. | 7 days |
active_workspace |
Remembers which Instagram account (workspace) you last had active so you don't have to re-select it on each visit. | Persistent (until you switch workspace or log out) |
csrf-token |
A double-submit CSRF token that protects your account against cross-site request forgery attacks. Set automatically on each page load and validated on all form submissions and API mutations. | Session |
ig_oauth_state |
A short-lived cookie set only during the Instagram account connection flow. Contains a signed, tamper-proof state value used to verify that the OAuth callback comes from a legitimate request (prevents CSRF during OAuth). Deleted immediately after the Instagram connection completes or fails. | 10 minutes |
post_login_redirect |
A short-lived cookie set when you click a call-to-action link on the landing page before you are signed in. After you complete Google sign-in, we use this cookie to redirect you to the page you originally intended to visit. Deleted immediately after use. | Short-lived (cleared on use) |
recovery_link_state, update_primary_state, totp_action_state |
Short-lived, signed cookies set only when you start the recovery-account linking, primary-account update, or two-factor-authorisation flows from Settings. Each carries a tamper-proof, single-use token across the Google OAuth round-trip. Deleted immediately after the flow completes or fails. | 3–10 minutes (cleared on use) |
human_check |
Set on the sign-in page after you pass the Cloudflare Turnstile check, which confirms that a real browser — rather than an automated script — is asking to start Google sign-in. It is a signed record that the check was passed and contains no personal data and no identifier. Deleted the moment you continue to Google, so each check covers one sign-in attempt. Turnstile is used only for this check; it does not track you across sites, and we send Cloudflare nothing but the challenge response and your IP address so it can be validated. See Cloudflare's privacy policy. | 10 minutes (cleared on use) |
support_unlock |
Set only for EngageDM staff, and only after they enter a code from their authenticator app to open the internal customer-support inbox. It is a signed record that the check was passed, so they are not asked for a code on every action; it contains no personal data. Cleared automatically after 30 minutes of inactivity, when they sign out, and if they turn two-factor authentication off. | 30 minutes of inactivity |
recovery_login_notice |
Set when you sign in using your recovery Google account, so we can prompt you to update your primary account. Cleared once you update it or dismiss the prompt. | 7 days (cleared on use) |
edm_cookie_consent |
Records the cookie categories you allowed, a version number, a timestamp, and a random consent reference. Necessary because it is the only way we can keep honouring your choice on later requests. The reference keeps your consent history in order in our compliance log (see section 2.3) and lets us detect referral-commission fraud (see section 2.4) — it is not used for analytics, advertising or profiling. | 6 months if you accept; browser session only if you refuse |
engagedm_tour_v1_* (browser localStorage, not a cookie) |
Records that you finished or skipped a guided product tour, so that tour does not reopen every time you load a page. It is written only when you close the tour, holds nothing but the fact that you closed it, and is never read for analytics or advertising. It is strictly necessary for the same reason the consent record above is: dismissing a prompt is an action you asked for, and without somewhere to note it we could not carry it out. | Until you clear your browser storage or replay the tour |
engagedm_checklist_v1 (browser localStorage, not a cookie) |
Records that you hid the getting-started checklist on your dashboard, so it stays hidden. Written only when you dismiss it, holds nothing but that fact, and is never read for analytics or advertising. Strictly necessary on the same basis as the tour flag above. | Until you clear your browser storage |
You can block these in your browser, but EngageDM will not work: without token you cannot stay signed in, and without csrf-token no form or API mutation will be accepted.
4.2 Preferences Optional
These remember how you like the interface set up. They are stored only if you allow the Preferences category. Turning the category off deletes what it stored and stops new writes — nothing else about the platform changes.
| Name | Storage | Purpose | Duration |
|---|---|---|---|
EngageDM-theme |
localStorage |
Remembers whether you chose the light or dark theme. | Until you clear it or withdraw consent |
Every item in this category is browser storage, not a cookie. The platform also recognises an optional currency cookie that overrides the currency prices are displayed in; we do not currently set it anywhere, and if that changes it will fall under this same Preferences category.
4.3 Analytics Optional
We use PostHog for product analytics: which pages and features are used, which steps people abandon, and which errors they hit. It exists so we can fix what is broken and build what is used. It is off unless you switch this category on, and nothing is downloaded or stored until you do.
Analytics requests are sent to engagedm.in/si — our own domain — and we pass them on to PostHog. We do this so the measurement is not skewed by content blockers, which would otherwise silently drop data from exactly the people most careful about privacy. It is a routing choice, not a way of hiding anything from you, and it does not change what is collected or what your consent controls: withdrawing consent stops it completely.
| Cookie Name | Purpose | Duration |
|---|---|---|
ph_edm_si_posthog |
Set by PostHog only if you have allowed this category. It stores a randomly generated identifier for your browser, plus the current session id, so a sequence of pages can be recognised as one visit rather than a series of unrelated ones. It contains no name, email, or account details, is readable only by EngageDM, and is never used for advertising or shared with any ad network. | 12 months (or until you withdraw this category) |
What is collected: the pages you view on EngageDM, clicks and form interactions within them, your browser, device type, operating system, referring page, and an approximate location (country/region) derived from your IP address. If you are signed in, this is linked to your account's random internal identifier so we can tell one person's session from another's — never to your name or email address, neither of which is sent.
What is deliberately not collected: we do not record your screen or your keystrokes (session replay is switched off entirely), we do not track you across other websites, and we do not build advertising profiles. Message content, Instagram access tokens, payment details, PAN and UPI details, and one-time codes are filtered out before anything leaves our server.
PostHog Inc. acts as our processor under a data processing agreement. Depending on the region configured for our project, data is stored in the United States or the European Union; where it leaves the UK/EEA, the transfer relies on Standard Contractual Clauses. See PostHog's Privacy Policy.
If you leave this category off, or turn it off later, nothing is measured, the cookie above is deleted, and the identifier stored in your browser is discarded. EngageDM works exactly the same either way.
4.4 Marketing Optional
EngageDM sets no advertising, retargeting, or cross-site tracking cookies, and does not participate in any advertising network. This category covers exactly one thing: crediting the partner whose referral link brought you here, and giving you the discount that link promised. It is stored only if you allow this category.
| Cookie Name | Purpose | Duration |
|---|---|---|
edm_ref |
Set only if you arrive through a partner's referral link (for example engagedm.in/?ref=abc123) and you have allowed this category. It stores that referral code — nothing else — so your discount is applied automatically at checkout, including after you sign in, and the partner is credited for the sale. It contains no identifier, is never read by any other site, and is not used for advertising, profiling, or measuring your browsing. Opening a different referral link replaces the stored code. You can remove the discount at any time from the checkout page, which deletes this cookie. |
90 days (or until you remove the code at checkout, or withdraw this category) |
If you leave this category off, referral links still work as ordinary links — you simply arrive with no code stored, no discount applied, and no attribution recorded. Turning the category off later deletes the stored code immediately, and we stop reading it even if the cookie somehow survives.
5. Third-Party Cookies
EngageDM sets no third-party advertising or cross-site tracking cookies. Our product analytics provider is listed below and only operates if you allow the Analytics category. Separately, when you interact with third-party services integrated into the platform, those services may set their own cookies under their own policies:
- PostHog — product analytics, and only with your consent (section 4.3). Requests are routed through our own domain, and PostHog acts as our processor. See PostHog's Privacy Policy.
- Razorpay — payment processing for customers billed in INR. Razorpay may set cookies on its hosted checkout, including for fraud prevention. Necessary to take a payment. See Razorpay's Privacy Policy.
- Dodo Payments — Merchant of Record for customers billed in USD. Dodo may set cookies on its hosted checkout page. Necessary to take a payment. See Dodo Payments' Privacy Policy.
- Google OAuth — authentication. Google may set cookies as part of the sign-in flow. Necessary to log you in. See Google's Privacy Policy.
- Google Fonts — our typeface is loaded from Google's CDN. Google does not set cookies for font delivery but does receive your IP address as part of the request. See Google's Privacy Policy.
- Cloudflare — sits in front of our servers for TLS, caching, and abuse protection, and may set a strictly necessary security cookie. See Cloudflare's Privacy Policy.
These are triggered by actions you take (paying, signing in, loading a page) rather than by the consent banner, and we do not control them. Please refer to each provider's policy for details and their own opt-out mechanisms.
6. Managing and Withdrawing Consent
6.1 Change your choice at any time
Open the panel with the link in the footer of every page. You can switch individual categories on or off, accept everything, reject everything non-essential, or reject all cookies including the essential ones. Withdrawing consent is exactly as easy as giving it — the same panel, the same number of clicks, as required by GDPR Article 7(3).
Withdrawing the Preferences category deletes the data that category had stored on your device; withdrawing Marketing deletes any stored referral code. Withdrawal does not affect the lawfulness of processing carried out before you withdrew.
6.2 Rejecting essential cookies
If you choose "Reject all cookies, including essential", we end your session, clear the cookies we had stored, and stop the platform from loading for you. You will see a page explaining this with a one-click way to allow essential cookies again. Your refusal is stored in a session-only cookie so we can keep honouring it; closing your browser clears it. You can also reach engagedm.in/site-prefs/reset directly to clear your recorded choice and be asked again.
6.3 Browser settings
Independently of our banner, most browsers let you refuse or delete cookies, or notify you when one is set. Note that blocking token will sign you out, blocking csrf-token will make form submissions fail, and blocking ig_oauth_state will prevent you from connecting an Instagram account.
To clear EngageDM cookies, use your browser's "Clear browsing data" option. This signs you out of your session; your account data is not affected.
6.4 If you have no JavaScript
The consent banner works without JavaScript: it falls back to plain form buttons offering the same three choices. We never store anything optional before you press one.
7. Do Not Track and Global Privacy Control
Some browsers transmit a "Do Not Track" (DNT) signal or a Global Privacy Control (GPC) signal. We honour them. If your browser sends either, our product analytics does not run at all — even if you have switched the Analytics category on. Nothing else changes, because there is nothing else to switch off: EngageDM runs no advertising or cross-site tracking cookies, and never sells or shares personal information as those terms are defined by the CCPA/CPRA.
8. Your Rights
Depending on where you live, you have rights over the personal data processed through cookies. In each case we aim to respond within the statutory deadline, and you will never be discriminated against for exercising them.
8.1 European Economic Area and United Kingdom (GDPR / UK GDPR, ePrivacy, PECR)
You have the right to be informed, to access, rectify, erase, restrict, and object to processing, to data portability, and to withdraw consent at any time. You may also lodge a complaint with your national supervisory authority — in the UK, the Information Commissioner's Office.
8.2 India (Digital Personal Data Protection Act, 2023)
As a Data Principal you have the right to access a summary of your personal data and its processing, to correction and erasure, to nominate another person to exercise your rights, and to grievance redressal. Consent obtained here is free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and may be withdrawn at any time with the same ease. Grievances can be raised at the contact address below and, if unresolved, escalated to the Data Protection Board of India.
8.3 California (CCPA / CPRA)
EngageDM does not sell or share personal information as those terms are defined by the CCPA/CPRA, and does no cross-context behavioural advertising — so there is no "Do Not Sell or Share My Personal Information" mechanism to offer. You retain the rights to know, delete, correct, and to limit the use of sensitive personal information.
8.4 Brazil (LGPD) and other jurisdictions
Data subjects under the LGPD have rights of confirmation, access, correction, anonymisation, portability, deletion, and revocation of consent. If your local law grants you cookie rights not listed here, contact us and we will honour them.
9. Updates to This Policy
We may update this Cookie Policy from time to time. Any changes will be posted on this page with an updated effective date. If we add a new cookie category or materially change how we use cookies, we will raise the consent version and ask you to choose again — your previous choice will not be carried over to a purpose you did not agree to. We also re-ask everyone at least every 6 months.
10. Contact Us
If you have any questions about this Cookie Policy, please contact us:
- Email: [email protected]
- Website: engagedm.in/contact