Skip to content
← Home

Cookie Policy

Last updated 27 April 2026

We keep cookies to a minimum. The only ones Nyxo sets today are the ones we need to keep you signed in and to protect your account. We do not run ad networks, third-party trackers, or fingerprinting scripts. This page explains exactly what gets stored and how to control it.

1. What is a cookie

A cookie is a small text file your browser stores on your device when you visit a website. The browser sends it back to the same website on subsequent visits so the site can recognise you, remember your preferences, or keep you signed in. The same mechanism is used by similar technologies — local storage, session storage, IndexedDB. We treat all of those the same way this policy treats cookies.

2. Cookies we set

Every cookie below is a strictly necessary cookie under the DPDPA 2023 and the EU ePrivacy Directive — without them the site cannot deliver the service you asked for, so we do not ask for opt-in consent. We also don't set anything else.

  • better-auth.session_token — keeps you signed in across pages. HttpOnly, Secure, SameSite=Lax. Lifetime: 30 days, refreshed on each visit. Removed on sign-out.
  • __Host-better-auth.csrf — CSRF token bound to the session, used to verify form posts come from the page we served. HttpOnly, Secure, SameSite=Strict. Lifetime: session.
  • nyxo-locale — remembers your language choice (English / हिन्दी) so the next page loads in the right language without an account lookup. SameSite=Lax. Lifetime: 1 year. Set only if you actively change the language.
  • nyxo-mobile-nav — UI-only state, remembers whether you had the dashboard sidebar open or collapsed. SameSite=Lax. Lifetime: session. No personal data.

3. Cookies we do NOT set

  • No advertising or retargeting cookies.
  • No third-party analytics (Google Analytics, Facebook Pixel, etc.) by default.
  • No social-media share-button cookies.
  • No fingerprinting scripts.

If we ever add privacy-friendly analytics (e.g. Plausible, which is cookieless), we'll update this page first and tell signed-in users. We will never silently turn on a third-party tracker.

4. Cookies on creator storefronts

When a buyer visits a creator's public storefront (e.g. nyxo.store/{creator}), only the cookies above can be set. Individual creators cannot inject their own trackers into pages we host on their behalf — that's a platform-wide restriction we enforce in our content security policy.

5. Payment-gateway cookies

During checkout, Razorpay and Stripe load their secure payment widgets in an iframe. Those iframes set their own cookies under the gateway's domains (razorpay.com, stripe.com) for fraud detection. Those cookies are governed by the gateway's privacy policy — see Razorpay's and Stripe's. Neither is loaded until you click Pay.

6. How to disable or delete cookies

You can clear cookies any time from your browser's settings. Our session cookie cannot be set without your explicit sign-in action, so the simplest way to opt out completely is to sign out.

  • Chrome — Settings → Privacy and security → Cookies and other site data → See all site data → search "nyxo".
  • Firefox — Settings → Privacy & Security → Cookies and Site Data → Manage Data.
  • Safari — Preferences → Privacy → Manage Website Data.
  • iOS / Android — your phone's browser settings include the same controls.

Clearing the session cookie will sign you out — that's expected.

7. Changes

If we ever change which cookies we set we'll update the "Last updated" date above and, for material changes (e.g. introducing analytics), notify signed-in users by email at least 7 days before the change takes effect.

8. Contact

Questions about cookies or any other privacy concern, write to privacy@nyxo.store. Per DPDPA §11 we'll respond within 30 days.

See also: Privacy Policy · Terms of Service