What are cookies
Small text files placed on your device when you visit CVJinny.
Cookies are small text files placed on your device when you visit our website. They help us provide you with a better experience by remembering your preferences, keeping you signed in, and understanding how you use our platform.
Strictly necessary
Essential for the platform to function. Set under the GDPR "legitimate interest / contract performance" lawful basis — no consent required, cannot be disabled.
- Authentication cookies: Managed by Supabase Auth to keep you signed in securely across sessions (httpOnly, sameSite=lax, secure in production).
- CSRF / security cookies: Used to protect against cross-site request forgery and validate OAuth state parameters returned by every connected platform.
- PKCE verifier (per OAuth provider): Short-lived (10 minutes) cookie set during the OAuth authorization-code exchange for X / Twitter, TikTok, Reddit, LINE, KakaoTalk, Zalo, ShareChat, Moj, Kwai, and any other PKCE-required platform. Discarded the moment the exchange completes.
- OAuth state parameter: One-time random nonce echoed back by every platform's callback to prevent CSRF in the OAuth flow itself.
- Locale + locale_source + country + country_ip_hash: Set by middleware to remember your interface language, whether you picked it explicitly (sticks 1 year) or it was auto-derived (re-derives if your country changes), and to detect VPN switches without re-running the IP geolocation API on every request. Non-tracking — purely operational.
- TOTP step-up token: Set after a successful TOTP / 2FA challenge so admin pages can enforce step-up authentication. HMAC-signed, user-bound, 8-hour TTL, cleared on sign-out.
- Cookie consent: Stores your preference choice (
velo_cookie_consent_v2).
Functional
Remember your choices to provide a personalized experience.
- Theme preference: Remembers your light/dark mode selection.
- Language preference: Stores your chosen interface language.
- Sidebar state: Remembers whether the dashboard sidebar is collapsed or expanded.
Analytics
Only loaded after you consent. You can opt out at any time.
We use analytics cookies only after you consent. These help us understand how visitors interact with our platform.
- Google Analytics 4 (GA4): Only loaded if you explicitly consent via our cookie banner. You may opt out at any time.
Third-party
Some embedded services may set their own cookies during interactions you initiate (checkout, OAuth login, etc).
The cookies below are set by third parties only when you initiate a flow that requires them — they are not loaded on the marketing site by default. Each third party has its own cookie / privacy policy linked alongside.
- Razorpay (primary payment processor): Set during the Razorpay Checkout / NetBanking / UPI flow for fraud prevention, session management, and 3DS authentication. Razorpay Privacy Policy.
- Stripe (fallback payment processor, currently disabled): If the owner re-enables Stripe as a fallback, Stripe may set cookies during checkout for fraud prevention and session management. Stripe Privacy Policy.
- OAuth providers (Meta, Google, X, LinkedIn, TikTok, Snapchat, Pinterest, Reddit, etc.): When you click "Connect" for any of the 23 supported platforms, the platform's own auth domain (facebook.com, accounts.google.com, x.com, linkedin.com, www.tiktok.com, accounts.snapchat.com, www.pinterest.com, www.reddit.com, etc.) sets its own cookies during the authorization step. GenZHook never reads those cookies — they belong to that platform's domain. Each platform's privacy policy applies; full list at /sub-processors.
- Cloudflare (CDN / DDoS / WAF): Cloudflare may set a non-tracking
__cf_bmcookie (30-minute TTL) as part of its bot-management product. It does not contain personal information and is not used for advertising. Cloudflare Privacy Policy.
How to control cookies
Manage preferences from the banner or your browser settings.
When you first visit CVJinny, a cookie consent banner allows you to accept or decline non-essential cookies. You can change your preference at any time from the footer of any page.
You can also control cookies through your browser settings. Most browsers allow you to:
- View what cookies are stored and delete them individually.
- Block third-party cookies.
- Block cookies from specific sites.
- Block all cookies.
- Delete all cookies when you close your browser.
Note: Blocking strictly necessary cookies will prevent you from signing in and using the platform.
Data retention
How long cookies stick around.
Authentication cookies expire when your session ends or after 7 days of inactivity. Consent cookies persist for 365 days. Analytics cookies follow the retention periods set by their respective providers.
Updates to this policy
Changes are effective when posted.
We may update this Cookie Policy periodically. Changes are effective when posted. We recommend reviewing this page occasionally.
Owner's Reservation of Rights
Absolute, exclusive discretion — no prior notice required.
The Owner reserves the absolute, exclusive, and unfettered discretion, with or without prior notice and without liability, to add, change, restructure, or remove any cookie, localStorage key, fingerprint, telemetry signal, or similar technology; to add or change analytics, advertising, attribution, or third-party measurement tools; to introduce new categories of data collection consistent with the Privacy Policy and Terms of Service; and to modify or replace this Cookie Policy with effect upon posting.
The Owner's Universal Reservation of Rights set out in Terms of Service section 1.1, the Authorized-Use License in section 1.2, the Benefits Reservation in section 1.3, the Dynamic Pricing & FX clause in section 1.4, and the Comprehensive Owner Protections in section 18 are incorporated into this Cookie Policy in full. Without limiting those sections, the Owner may at any time add, change, modify, restrict, suspend, or discontinue any feature, plan, integration, price, fee, FX rate, credit weight, quota, discount, coupon, reward, or facility, partially or fully, with or without prior notice. You waive any claim — including any claim to refund, credit-back, pro-rated rebate, alternative reward, replacement Benefit, or compensation of any kind — arising from the exercise of these rights, except only where applicable mandatory law preserves an unwaivable right and only to the absolute minimum the law requires. The No-Refund Policy applies in full and is incorporated by reference.
Authorized data use
Aggregated insights may be shared, licensed, or sold for our benefit.
By using the Service you authorize GenZHook to collect, derive, aggregate, anonymize, model, share, license, sell (in de-identified or pseudonymized form), and otherwise commercially exploit non-content data and aggregated insights for financial, analytical, advertising, marketing, business-intelligence, third-party-data-licensing, and operational purposes that benefit CVJinny, its affiliates, partners, sub-processors, advertisers, data licensees, and assigns.
Full details are in Privacy Policy section 4a and Terms of Service section 1.2. CVJinny is the sole and exclusive beneficiary of any revenue derived from this license.