Cookie Policy
Effective Date: April 16, 2026 · Last updated: April 2026
1. What Are Cookies
Cookies are small text files that are stored on your device (computer, tablet, or mobile phone) when you visit a website. They are widely used to make websites function properly, improve user experience, and provide information to site operators.
Cookies may be set by the website you are visiting ("first-party cookies") or by third-party services that the website uses for specific functionality such as analytics, payment processing, or authentication ("third-party cookies").
This Cookie Policy explains how ComplyFormAI Corp ("we," "us," or "our") uses cookies and similar tracking technologies on the ComplyFormAI platform ("Platform"), accessible at complyformai.com and its associated subdomains. This policy should be read in conjunction with our Privacy Policy.
2. How We Use Cookies
We use cookies and similar technologies for the following purposes:
- Authentication and Security: To verify your identity when you sign in, maintain your session, and protect against cross-site request forgery (CSRF) and other security threats.
- Essential Platform Functionality: To enable core features of the Platform including navigation, access to secure areas, and proper rendering of application state.
- User Preferences: To remember your preferences, display settings, language selections, and other configuration choices to provide a consistent experience across sessions.
- Performance and Analytics: To understand how users interact with the Platform, identify usage patterns, measure feature adoption rates, and improve platform performance. We do not collect personally identifiable information (PII) through analytics cookies.
- Payment Processing: To facilitate secure payment transactions through our payment provider, Stripe, including fraud detection and compliance with payment card industry standards.
- Load Balancing: To distribute traffic across our infrastructure to ensure consistent performance and availability.
3. Types of Cookies We Use
3.1 Strictly Necessary Cookies
These cookies are essential for the Platform to function and cannot be disabled. They are typically set in response to actions you take, such as signing in, setting preferences, or filling out forms. Without these cookies, the Platform cannot operate as intended.
| Cookie Name | Purpose | Duration | Provider |
|---|---|---|---|
| __Host-authjs.session-token | Stores encrypted session token for user authentication via Auth.js v5 | Session / 30 days | ComplyFormAI (1st party) |
| __Host-authjs.csrf-token | Provides CSRF protection for authentication forms and state-changing requests | Session | ComplyFormAI (1st party) |
| __Host-authjs.callback-url | Stores the callback URL during the OAuth authentication flow | Session | ComplyFormAI (1st party) |
| cfai_org_context | Stores the active organization context for multi-tenant session management | Session | ComplyFormAI (1st party) |
| cfai_feature_tier | Caches the current subscription tier for feature flag evaluation | 1 hour | ComplyFormAI (1st party) |
| __cf_bm | Cloudflare bot management cookie for DDoS protection and traffic filtering | 30 minutes | Cloudflare (3rd party) |
| __vercel_live_token | Infrastructure routing cookie for deployment management | Session | Vercel (3rd party) |
3.2 Functional Cookies
These cookies enable enhanced functionality and personalization. They may be set by us or by third-party providers whose services we use. If you disable these cookies, some or all of these features may not function properly.
| Cookie Name | Purpose | Duration | Provider |
|---|---|---|---|
| cfai_preferences | Stores user interface preferences including sidebar state, table density, default views, and dashboard layout | 1 year | ComplyFormAI (1st party) |
| cfai_locale | Stores language and locale preference for content rendering and date/number formatting | 1 year | ComplyFormAI (1st party) |
| cfai_theme | Stores light/dark mode preference and any custom theme settings | 1 year | ComplyFormAI (1st party) |
| cfai_recent_orgs | Stores recently accessed organization identifiers for quick-switch functionality | 90 days | ComplyFormAI (1st party) |
| cfai_onboarding_state | Tracks onboarding progress to resume where the user left off | 30 days | ComplyFormAI (1st party) |
3.3 Analytics Cookies
These cookies help us understand how users interact with the Platform by collecting and reporting information anonymously. We use this data to improve feature design, optimize workflows, and enhance overall platform performance. No personally identifiable information (PII) is collected or transmitted through analytics cookies.
| Cookie Name | Purpose | Duration | Provider |
|---|---|---|---|
| _va | Vercel Analytics visitor identifier (anonymous, no PII) for measuring page views, navigation patterns, and Web Vitals performance metrics | 1 year | Vercel Analytics (3rd party) |
| va_ss | Vercel Speed Insights session cookie for measuring Core Web Vitals (LCP, FID, CLS) and real-user performance | Session | Vercel Analytics (3rd party) |
| cfai_feature_usage | Anonymous feature adoption tracking to measure which platform capabilities are most utilized across tiers | Session | ComplyFormAI (1st party) |
3.4 Third-Party Cookies
These cookies are set by third-party services that we integrate with to provide specific Platform functionality. Each provider has its own cookie and privacy policy.
| Cookie Name | Purpose | Duration | Provider |
|---|---|---|---|
| __stripe_mid | Stripe merchant identification cookie used for payment processing, fraud prevention, and PCI DSS compliance | 1 year | Stripe |
| __stripe_sid | Stripe session cookie for maintaining payment form state during checkout | 30 minutes | Stripe |
| ESTSAUTH / ESTSAUTHPERSISTENT | Microsoft Entra ID (Azure AD) authentication tokens used during SSO login flow | Session / 90 days | Microsoft |
| AADSSO | Microsoft Entra ID single sign-on state cookie | Session | Microsoft |
| __Host-GAPS | Google authentication cookie used during Google OAuth login flow | 2 years | |
| SIDCC | Google security cookie for authentication integrity verification | 1 year | |
| NID | Google cookie used during the OAuth consent and authentication flow | 6 months |
4. Cookie Duration
Cookies used on the Platform fall into two categories based on their duration:
4.1 Session Cookies
Session cookies are temporary cookies that exist only for the duration of your browser session. They are automatically deleted when you close your browser. Session cookies are primarily used for authentication, CSRF protection, and maintaining application state during your active use of the Platform. Examples include the CSRF token and payment session cookies.
4.2 Persistent Cookies
Persistent cookies remain on your device for a specified period or until you manually delete them. They are used for purposes that require data retention across browser sessions, such as remembering your login status, user preferences, and anonymous analytics identifiers. Persistent cookie durations on the Platform range from 30 minutes to 2 years, depending on the cookie's purpose.
The following table summarizes the duration ranges by cookie category:
| Cookie Category | Typical Duration | Purpose of Retention |
|---|---|---|
| Strictly Necessary | Session to 30 days | Maintain authentication state and security protections |
| Functional | 30 days to 1 year | Preserve user preferences and interface customization |
| Analytics | Session to 1 year | Measure aggregate usage patterns over meaningful time periods |
| Third-Party | 30 minutes to 2 years | Support authentication provider and payment processing requirements |
5. Managing Your Cookie Preferences
You have several options for managing cookies on the Platform:
5.1 In-Platform Cookie Settings
When you first visit the Platform, a cookie consent banner allows you to accept or customize your cookie preferences. You can modify these preferences at any time by navigating to Settings > Privacy > Cookie Preferences within your account dashboard. Note that strictly necessary cookies cannot be disabled as they are required for the Platform to function.
5.2 Browser Settings
Most modern web browsers allow you to control cookies through their settings. You can typically configure your browser to:
- Block all cookies (note: this will prevent the Platform from functioning)
- Block only third-party cookies
- Delete all cookies when you close the browser
- Receive a notification before a cookie is set
Instructions for managing cookies in common browsers:
- Google Chrome: Settings > Privacy and Security > Cookies and other site data
- Mozilla Firefox: Settings > Privacy & Security > Cookies and Site Data
- Microsoft Edge: Settings > Privacy, search, and services > Cookies and site permissions
- Safari: Preferences > Privacy > Manage Website Data
5.3 Impact of Disabling Cookies
If you choose to disable or restrict cookies, please be aware of the following impacts:
- Disabling strictly necessary cookies will prevent you from signing in and using the Platform entirely.
- Disabling functional cookies will reset your preferences each session, requiring manual reconfiguration of display settings, language, and layout.
- Disabling analytics cookies will not affect Platform functionality but will limit our ability to improve the user experience based on usage data.
- Disabling third-party cookies may prevent authentication via Microsoft Entra ID or Google SSO and may interfere with Stripe payment processing.
6. Third-Party Services and Their Cookies
The Platform integrates with the following third-party services, each of which may set cookies on your device. We do not control the cookies set by these providers and recommend reviewing their respective privacy policies.
6.1 Stripe (Payment Processing)
We use Stripe to process subscription payments securely. Stripe sets cookies to enable payment form functionality, detect and prevent fraudulent transactions, and comply with Payment Card Industry Data Security Standard (PCI DSS) requirements. Stripe's cookies are essential for any payment-related functionality on the Platform.
Stripe Privacy Policy: https://stripe.com/privacy
6.2 Microsoft Entra ID (Authentication)
Customers who authenticate via Microsoft Entra ID (formerly Azure Active Directory) will encounter Microsoft authentication cookies during the sign-in process. These cookies manage the OAuth 2.0 / OpenID Connect authentication flow and maintain SSO state. Microsoft cookies are set on Microsoft domains and are subject to Microsoft's privacy practices.
Microsoft Privacy Statement: https://privacy.microsoft.com
6.3 Google (Authentication)
Customers who authenticate via Google will encounter Google authentication cookies during the sign-in process. These cookies manage the OAuth 2.0 authentication flow and verify the integrity of the authentication session. Google cookies are set on Google domains.
Google Privacy Policy: https://policies.google.com/privacy
6.4 Vercel (Hosting and Analytics)
The Platform is hosted on Vercel's infrastructure. Vercel may set cookies for infrastructure routing, deployment management, and anonymous performance analytics. Vercel Analytics collects Web Vitals metrics and page-level performance data without collecting PII.
Vercel Privacy Policy: https://vercel.com/legal/privacy-policy
6.5 Cloudflare (Security and Performance)
We use Cloudflare for DDoS protection, web application firewall (WAF), and content delivery. Cloudflare may set cookies for bot detection and traffic management purposes. These cookies are classified as strictly necessary for security.
Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/
7. Do Not Track Signals
Some web browsers transmit "Do Not Track" (DNT) signals to websites. As there is currently no universally accepted standard for how companies should respond to DNT signals, the Platform does not currently alter its data collection and use practices in response to DNT signals.
However, we are committed to respecting user privacy. Our analytics implementation collects only anonymous, aggregate data and does not track individual users across third-party websites. We do not engage in behavioral advertising or sell user data to third parties. We will continue to monitor developments in privacy standards and adjust our practices as appropriate.
Users who wish to limit tracking may use the cookie preference controls described in Section 5 or install browser extensions such as Privacy Badger or uBlock Origin.
8. Updates to This Policy
We may update this Cookie Policy from time to time to reflect changes in our use of cookies, the addition or removal of third-party services, changes in applicable law, or improvements to our privacy practices.
When we make material changes to this Cookie Policy, we will:
- Update the "Last Updated" date at the top of this document.
- Post the revised Cookie Policy on the Platform.
- For significant changes (such as the introduction of new cookie categories or third-party tracking services), notify users via an in-app notification or email to the account administrator.
- Where required by applicable law, obtain renewed consent for any new non-essential cookies.
We encourage you to review this Cookie Policy periodically to stay informed about our use of cookies and related technologies.
9. Contact Information
If you have questions, concerns, or requests regarding this Cookie Policy or our use of cookies and tracking technologies, please contact us:
ComplyFormAI Corp
Email: privacy@complyformai.com
Website: complyformai.com
Support Portal: support.complyformai.com
For data protection inquiries specific to European users, you may also contact our designated privacy team at dpo@complyformai.com.
We aim to respond to all privacy-related inquiries within ten (10) business days.