Legal

Cookie Policy

Effective Date: April 16, 2026 · Last updated: April 2026

1. What Are Cookies

Cookies are small text files that are stored on your device (computer, tablet, or mobile phone) when you visit a website. They are widely used to make websites function properly, improve user experience, and provide information to site operators.

Cookies may be set by the website you are visiting ("first-party cookies") or by third-party services that the website uses for specific functionality such as analytics, payment processing, or authentication ("third-party cookies").

This Cookie Policy explains how ComplyFormAI Corp ("we," "us," or "our") uses cookies and similar tracking technologies on the ComplyFormAI platform ("Platform"), accessible at complyformai.com and its associated subdomains. This policy should be read in conjunction with our Privacy Policy.

2. How We Use Cookies

We use cookies and similar technologies for the following purposes:

  • Authentication and Security: To verify your identity when you sign in, maintain your session, and protect against cross-site request forgery (CSRF) and other security threats.
  • Essential Platform Functionality: To enable core features of the Platform including navigation, access to secure areas, and proper rendering of application state.
  • User Preferences: To remember your preferences, display settings, language selections, and other configuration choices to provide a consistent experience across sessions.
  • Performance and Analytics: To understand how users interact with the Platform, identify usage patterns, measure feature adoption rates, and improve platform performance. We do not collect personally identifiable information (PII) through analytics cookies.
  • Payment Processing: To facilitate secure payment transactions through our payment provider, Stripe, including fraud detection and compliance with payment card industry standards.
  • Load Balancing: To distribute traffic across our infrastructure to ensure consistent performance and availability.

3. Types of Cookies We Use

3.1 Strictly Necessary Cookies

These cookies are essential for the Platform to function and cannot be disabled. They are typically set in response to actions you take, such as signing in, setting preferences, or filling out forms. Without these cookies, the Platform cannot operate as intended.

Cookie NamePurposeDurationProvider
__Host-authjs.session-tokenStores encrypted session token for user authentication via Auth.js v5Session / 30 daysComplyFormAI (1st party)
__Host-authjs.csrf-tokenProvides CSRF protection for authentication forms and state-changing requestsSessionComplyFormAI (1st party)
__Host-authjs.callback-urlStores the callback URL during the OAuth authentication flowSessionComplyFormAI (1st party)
cfai_org_contextStores the active organization context for multi-tenant session managementSessionComplyFormAI (1st party)
cfai_feature_tierCaches the current subscription tier for feature flag evaluation1 hourComplyFormAI (1st party)
__cf_bmCloudflare bot management cookie for DDoS protection and traffic filtering30 minutesCloudflare (3rd party)
__vercel_live_tokenInfrastructure routing cookie for deployment managementSessionVercel (3rd party)

3.2 Functional Cookies

These cookies enable enhanced functionality and personalization. They may be set by us or by third-party providers whose services we use. If you disable these cookies, some or all of these features may not function properly.

Cookie NamePurposeDurationProvider
cfai_preferencesStores user interface preferences including sidebar state, table density, default views, and dashboard layout1 yearComplyFormAI (1st party)
cfai_localeStores language and locale preference for content rendering and date/number formatting1 yearComplyFormAI (1st party)
cfai_themeStores light/dark mode preference and any custom theme settings1 yearComplyFormAI (1st party)
cfai_recent_orgsStores recently accessed organization identifiers for quick-switch functionality90 daysComplyFormAI (1st party)
cfai_onboarding_stateTracks onboarding progress to resume where the user left off30 daysComplyFormAI (1st party)

3.3 Analytics Cookies

These cookies help us understand how users interact with the Platform by collecting and reporting information anonymously. We use this data to improve feature design, optimize workflows, and enhance overall platform performance. No personally identifiable information (PII) is collected or transmitted through analytics cookies.

Cookie NamePurposeDurationProvider
_vaVercel Analytics visitor identifier (anonymous, no PII) for measuring page views, navigation patterns, and Web Vitals performance metrics1 yearVercel Analytics (3rd party)
va_ssVercel Speed Insights session cookie for measuring Core Web Vitals (LCP, FID, CLS) and real-user performanceSessionVercel Analytics (3rd party)
cfai_feature_usageAnonymous feature adoption tracking to measure which platform capabilities are most utilized across tiersSessionComplyFormAI (1st party)

3.4 Third-Party Cookies

These cookies are set by third-party services that we integrate with to provide specific Platform functionality. Each provider has its own cookie and privacy policy.

Cookie NamePurposeDurationProvider
__stripe_midStripe merchant identification cookie used for payment processing, fraud prevention, and PCI DSS compliance1 yearStripe
__stripe_sidStripe session cookie for maintaining payment form state during checkout30 minutesStripe
ESTSAUTH / ESTSAUTHPERSISTENTMicrosoft Entra ID (Azure AD) authentication tokens used during SSO login flowSession / 90 daysMicrosoft
AADSSOMicrosoft Entra ID single sign-on state cookieSessionMicrosoft
__Host-GAPSGoogle authentication cookie used during Google OAuth login flow2 yearsGoogle
SIDCCGoogle security cookie for authentication integrity verification1 yearGoogle
NIDGoogle cookie used during the OAuth consent and authentication flow6 monthsGoogle

Cookies used on the Platform fall into two categories based on their duration:

4.1 Session Cookies

Session cookies are temporary cookies that exist only for the duration of your browser session. They are automatically deleted when you close your browser. Session cookies are primarily used for authentication, CSRF protection, and maintaining application state during your active use of the Platform. Examples include the CSRF token and payment session cookies.

4.2 Persistent Cookies

Persistent cookies remain on your device for a specified period or until you manually delete them. They are used for purposes that require data retention across browser sessions, such as remembering your login status, user preferences, and anonymous analytics identifiers. Persistent cookie durations on the Platform range from 30 minutes to 2 years, depending on the cookie's purpose.

The following table summarizes the duration ranges by cookie category:

Cookie CategoryTypical DurationPurpose of Retention
Strictly NecessarySession to 30 daysMaintain authentication state and security protections
Functional30 days to 1 yearPreserve user preferences and interface customization
AnalyticsSession to 1 yearMeasure aggregate usage patterns over meaningful time periods
Third-Party30 minutes to 2 yearsSupport authentication provider and payment processing requirements

You have several options for managing cookies on the Platform:

When you first visit the Platform, a cookie consent banner allows you to accept or customize your cookie preferences. You can modify these preferences at any time by navigating to Settings > Privacy > Cookie Preferences within your account dashboard. Note that strictly necessary cookies cannot be disabled as they are required for the Platform to function.

5.2 Browser Settings

Most modern web browsers allow you to control cookies through their settings. You can typically configure your browser to:

  • Block all cookies (note: this will prevent the Platform from functioning)
  • Block only third-party cookies
  • Delete all cookies when you close the browser
  • Receive a notification before a cookie is set

Instructions for managing cookies in common browsers:

  • Google Chrome: Settings > Privacy and Security > Cookies and other site data
  • Mozilla Firefox: Settings > Privacy & Security > Cookies and Site Data
  • Microsoft Edge: Settings > Privacy, search, and services > Cookies and site permissions
  • Safari: Preferences > Privacy > Manage Website Data

5.3 Impact of Disabling Cookies

If you choose to disable or restrict cookies, please be aware of the following impacts:

  • Disabling strictly necessary cookies will prevent you from signing in and using the Platform entirely.
  • Disabling functional cookies will reset your preferences each session, requiring manual reconfiguration of display settings, language, and layout.
  • Disabling analytics cookies will not affect Platform functionality but will limit our ability to improve the user experience based on usage data.
  • Disabling third-party cookies may prevent authentication via Microsoft Entra ID or Google SSO and may interfere with Stripe payment processing.

6. Third-Party Services and Their Cookies

The Platform integrates with the following third-party services, each of which may set cookies on your device. We do not control the cookies set by these providers and recommend reviewing their respective privacy policies.

6.1 Stripe (Payment Processing)

We use Stripe to process subscription payments securely. Stripe sets cookies to enable payment form functionality, detect and prevent fraudulent transactions, and comply with Payment Card Industry Data Security Standard (PCI DSS) requirements. Stripe's cookies are essential for any payment-related functionality on the Platform.

Stripe Privacy Policy: https://stripe.com/privacy

6.2 Microsoft Entra ID (Authentication)

Customers who authenticate via Microsoft Entra ID (formerly Azure Active Directory) will encounter Microsoft authentication cookies during the sign-in process. These cookies manage the OAuth 2.0 / OpenID Connect authentication flow and maintain SSO state. Microsoft cookies are set on Microsoft domains and are subject to Microsoft's privacy practices.

Microsoft Privacy Statement: https://privacy.microsoft.com

6.3 Google (Authentication)

Customers who authenticate via Google will encounter Google authentication cookies during the sign-in process. These cookies manage the OAuth 2.0 authentication flow and verify the integrity of the authentication session. Google cookies are set on Google domains.

Google Privacy Policy: https://policies.google.com/privacy

6.4 Vercel (Hosting and Analytics)

The Platform is hosted on Vercel's infrastructure. Vercel may set cookies for infrastructure routing, deployment management, and anonymous performance analytics. Vercel Analytics collects Web Vitals metrics and page-level performance data without collecting PII.

Vercel Privacy Policy: https://vercel.com/legal/privacy-policy

6.5 Cloudflare (Security and Performance)

We use Cloudflare for DDoS protection, web application firewall (WAF), and content delivery. Cloudflare may set cookies for bot detection and traffic management purposes. These cookies are classified as strictly necessary for security.

Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/

7. Do Not Track Signals

Some web browsers transmit "Do Not Track" (DNT) signals to websites. As there is currently no universally accepted standard for how companies should respond to DNT signals, the Platform does not currently alter its data collection and use practices in response to DNT signals.

However, we are committed to respecting user privacy. Our analytics implementation collects only anonymous, aggregate data and does not track individual users across third-party websites. We do not engage in behavioral advertising or sell user data to third parties. We will continue to monitor developments in privacy standards and adjust our practices as appropriate.

Users who wish to limit tracking may use the cookie preference controls described in Section 5 or install browser extensions such as Privacy Badger or uBlock Origin.

8. Updates to This Policy

We may update this Cookie Policy from time to time to reflect changes in our use of cookies, the addition or removal of third-party services, changes in applicable law, or improvements to our privacy practices.

When we make material changes to this Cookie Policy, we will:

  • Update the "Last Updated" date at the top of this document.
  • Post the revised Cookie Policy on the Platform.
  • For significant changes (such as the introduction of new cookie categories or third-party tracking services), notify users via an in-app notification or email to the account administrator.
  • Where required by applicable law, obtain renewed consent for any new non-essential cookies.

We encourage you to review this Cookie Policy periodically to stay informed about our use of cookies and related technologies.

9. Contact Information

If you have questions, concerns, or requests regarding this Cookie Policy or our use of cookies and tracking technologies, please contact us:

ComplyFormAI Corp
Email: privacy@complyformai.com
Website: complyformai.com
Support Portal: support.complyformai.com

For data protection inquiries specific to European users, you may also contact our designated privacy team at dpo@complyformai.com.

We aim to respond to all privacy-related inquiries within ten (10) business days.