Cookie Policy

Effective date: September 5, 2026

This Cookie Policy explains how BttrLabs Private Limited (“Watari”) uses cookies and similar technologies when you visit our marketing site or use the Watari application. It supplements our Privacy Policy.

1. What are cookies?

Cookies are small text files stored on your device when you visit a website. They allow the site to recognise your device across pages and across visits, and to store small pieces of state, such as whether you are signed in.

We also use related technologies such as localStorage, sessionStorage, and pixel tags. References to “cookies” in this Policy include those technologies.

2. Categories we use

  • Strictly necessary cookies are required for the Service to function (e.g. authentication, session continuity). These cannot be turned off without breaking core functionality. They do not require consent under EU ePrivacy / DPDP frameworks.
  • Functional cookies remember preferences such as theme and side-bar state to make the Service more usable. They do not track behaviour across sites.
  • Analytics cookies help us understand aggregate usage patterns so we can improve the Service. What happens before you answer the banner depends on where you are reading from, and section 3b sets out exactly what runs in each case. In the EU, EEA, UK and Switzerland, and for any visitor whose location we cannot determine, nothing analytics-related is stored on your device until you accept. Everywhere else, analytics runs by default and the banner gives you a control that turns it off.

We do not currently use any cookies for cross-context behavioural advertising, retargeting, or sale of personal information.

3. Cookies in detail

NameSourceCategoryPurposeDurationParty
sb-*-auth-tokenSupabase AuthStrictly necessaryKeeps you signed in. Used to authenticate your session.Session + 7-day refreshfirst-party
sidebar_stateWatari appFunctionalRemembers whether the dashboard side-bar is collapsed or expanded.7 daysfirst-party
watari_consentWatari app (cookie banner)Strictly necessaryRecords your cookie-consent decision so the banner does not re-prompt on every visit. Set only after you click Accept or Reject on the banner.1 yearfirst-party
bs_consent_regimeWatari app (middleware)Strictly necessaryRecords which consent rules apply to you, derived from the country your request arrives from. Holds one of two values, opt_in or opt_out, and no location beyond that. Used to decide whether analytics may run before you answer the banner.30 daysfirst-party
bs_regionWatari app (middleware)FunctionalRemembers whether to quote prices in INR or USD. Derived from the country your request arrives from, and overridable with a query parameter.1 yearfirst-party
__vercel_live_tokenVercelStrictly necessaryPreview-deployment authentication. Set on preview URLs only, not present on the production site.Sessionthird-party
_gaGoogle Analytics 4AnalyticsDistinguishes one visitor from another so we can count visits and see which pages and referrers bring people to the site. Set only after you grant analytics consent, and never on the signed-in product.2 yearsthird-party
_ga_*Google Analytics 4AnalyticsHolds the session state for the specific Analytics property. Set alongside _ga, under the same consent.2 yearsthird-party

3a. localStorage entries

A few preferences are stored in your browser's localStorage rather than in cookies. These are read by client-side JavaScript only and are not transmitted to our servers on every request.

  • theme: Remembers your dark- or light-mode preference. Stored in browser localStorage by next-themes, not in a cookie.
  • watari_consent: Mirror of the cookie above. Both carry the same decision; the localStorage copy is what the consent helper reads to gate analytics.
  • ph_*: PostHog product analytics identifier and session state, inside the signed-in product only. Written to localStorage rather than a cookie. Created only after you grant analytics consent, and never when Global Privacy Control is set.

3b. Analytics, and what your location changes

We use two analytics tools, for two different questions.

  • Google Analytics 4 measures how people arrive: which page, which referrer or search, and whether they reached signup. It runs only on our public marketing pages and the signup and login pages, never inside the signed-in product. When it is permitted to store data it sets the _ga and _ga_* cookies listed above. Google acts as a processor for this data.
  • PostHog measures what happens inside the product once you are signed in, so we can see which features are used and where people get stuck. It stores its identifier in browser localStorage rather than a cookie, which is why it does not appear in the cookie table.

Which rules apply to you is decided by the country your request arrives from, recorded in the bs_consent_regime cookie. If we cannot determine your location, we apply the stricter set.

In the EU, EEA, United Kingdom and Switzerland, and for any visitor we cannot place: nothing analytics-related is stored on your device until you accept, and the Analytics toggle in the banner starts switched off. PostHog is not downloaded at all. Google Analytics is present on the page but starts in a denied state, in which it sets no cookie, reads no cookie, creates no identifier for you, and sends only a request carrying the page address and no device identifier. Accepting switches it on; rejecting leaves it in that state permanently.

In the United States, India and the rest of the world: analytics runs by default, which is what the local rules permit. The banner says so, the Analytics toggle starts switched on, and Reject all turns it off in one click. Turning it off stops PostHog and puts Google Analytics into the denied state described above.

The banner itself is the same in both cases: the same wording, the same three choices, and the same categories. Only the starting position of the toggles changes.

Two things are true in every location. A Global Privacy Control signal from your browser overrides all of the above and denies analytics outright. And we never load analytics of any kind on preview or development deployments, only on the live site.

India's Digital Personal Data Protection Act 2023 brings its consent provisions into force on 13 May 2027. Indian visitors move to the prior-consent behaviour described above on that date, and this page will be updated to match.

4. Consent & controls

The banner offers three choices on its first layer: Reject all, Manage and Accept all. Reject all is the same size, the same styling and the same single click as Accept all, and it is never hidden behind Manage. It does not block the page and there is no way to dismiss it without answering, because a dismissal is not consent.

Manage opens the three categories described in section 2 with a switch on each. Strictly necessary is shown, switched on and locked, because the Service cannot run without it. Functional and Analytics are yours to set, and whether they start on or off is the only thing your location changes (section 3b). Turning Functional off means the site stops remembering preferences such as whether the product sidebar is collapsed.

Your answer is stored on this device and respected on future visits.

You can change your answer at any time, in either direction, by clicking “Cookie settings” in the site footer.

We honour the Global Privacy Control (GPC) signal, if your browser sends GPC, we treat that as an opt-out of analytics cookies (and, where applicable, of any “sale” or “share” for cross-context behavioural advertising).

You can also block or delete cookies directly via your browser settings. Note that blocking strictly necessary cookies may break the Service.

5. Third-party cookies

Third parties listed in the table above process cookie data under their own privacy policies, summarised at watari.ai/legal/subprocessors.

6. Changes

We may update this Cookie Policy from time to time. The “Effective date” at the top of this page indicates the last revision. Material changes are notified by email to the registered owner of each Organisation at least 30 days before they take effect.

7. Contact

Questions about cookies? Email privacy@watari.ai.