Last Updated: August 24, 2026
This Cookie Policy describes the cookies and browser-storage technologies currently used by Valtriox on its website and Portal. Read it with our Privacy Policy.
A cookie is a small value a website asks a browser to store and return with later requests. Browser local storage and cache storage remain on the device but are not cookies and are not automatically attached to requests. This policy identifies each type separately because the Portal currently uses all three for different purposes.
Successful Portal login sets the following first-party vt-* cookies. The server uses them to identify the signed-in account, apply role and organization scope, and verify the authentication values.
| Cookie | Current purpose | Current lifetime |
|---|---|---|
| vt-user-id | Signed-in user identifier | Up to 7 days |
| vt-user-email | Signed-in account email | Up to 7 days |
| vt-user-role | Role used for authorization checks | Up to 7 days |
| vt-org-id | Organization scope, when an organization is assigned | Up to 7 days |
| vt-auth-sig | Integrity signature for the authentication values | Up to 7 days |
These cookies currently use HttpOnly, SameSite=Lax, and path /; production cookies also use Secure. Logging out asks the server to expire them immediately. Blocking or deleting them can prevent signed-in Portal use. There is no separate in-product switch for authentication cookies.
The Portal uses browser local storage under valtriox-* keys. Unlike the authentication cookies above, these values can be read by application scripts on the same origin and have no server-set expiry date.
| Keys | Current purpose | Retention on device |
|---|---|---|
| valtriox-theme, valtriox-language, valtriox-appTheme | Display theme and language preferences | Until the app replaces/removes it or browser site data is cleared |
| valtriox-session-active | Boolean UI hint that a session was active; it is not an authentication credential | Removed on logout or error recovery |
| valtriox-brandname, valtriox-logo, valtriox-tagline, valtriox-configured | Locally displayed brand setup values | Removed on logout/error recovery or when browser site data is cleared |
| valtriox-timezone-detected, valtriox-timezone-value | Timezone setup state and selected/detected timezone | Until replaced or browser site data is cleared |
| valtriox-social-posts, valtriox-chat-{organization}-{channel} | Browser-local social-post state and up to the latest 200 chat messages per organization/channel | Until the feature replaces/removes it or browser site data is cleared |
The exact set of keys can change as beta features change. Clearing browser site data removes these local values and may reset preferences or locally stored feature content.
If a Google Analytics measurement ID is configured for a deployment, the site loads Google's analytics script after the page becomes interactive and configures it for that ID. Google may then receive usage/device information and use its own identifiers or cookies under Google's terms.
If a Meta Pixel ID is configured, the site loads the Meta Pixel after the page becomes interactive, records a page-view event, and may record lead events. A page-view request can also occur through the pixel's non-JavaScript image fallback.
Current consent behavior: As of the date above, the site does not provide a cookie-consent banner or category-preference control. When the relevant deployment ID is configured, Google Analytics or Meta Pixel loads without waiting for a prior in-product consent choice. You can use browser controls, content blockers, or the provider controls below.
Browser settings can block or delete cookies and clear local/cache storage. Private browsing, tracking protection, or extensions may also limit third-party requests. Because there is no current Valtriox consent panel, browser and provider controls are the available controls for analytics and advertising technologies.
Blocking first-party cookies may prevent login. Clearing local storage may reset theme, language, timezone, branding, and browser-local chat or social-post state. Logging out expires the vt-* cookies and removes the session hint and core local brand keys, but it does not currently remove every preference or feature-content key.
The site does not currently implement a separate response to browser Do Not Track signals. Browser-level blocking or deletion controls may still affect cookies, local storage, and third-party requests.
A service worker may use browser Cache Storage for selected public static assets and navigation support. This cache is not a cookie and does not represent that signed-in application data is available offline. The browser or a later application version may update or remove cached files, and you can clear them through browser site-data controls.
We may revise this policy as the beta, its configuration, or applicable requirements change. The revised page will show an updated date. Where practicable and appropriate, we may also use available account or email channels for material changes.
For questions about this policy or the technologies described here, contact us: