COOKIES & LOGGING
1. This marketing site
The public marketing pages are static. They do not load a third-party analytics pixel today. The contact form posts to our own /api/contact endpoint. Hosting (Vercel) may set standard operational cookies or logs as part of delivering the site — we do not control every platform cookie.
2. The professional app
app.instaseal.co is a signed-in product. It uses session / authentication cookies (or equivalent tokens) so you stay logged in and so MFA and sealing flows can run. Those are needed to operate the account.
3. Public verification pages
When someone opens a verification page or scans a seal QR, the API may log a timestamp, IP address, and user agent so the professional can see a verification trail. That is described in the draft Privacy Policy. It is a server log, not a marketing cookie.
4. What we are not claiming
- No claim that we are “fully GDPR compliant” or “CCPA certified.”
- No claim that we never use cookies.
- No consent-banner theater until counsel says one is required for the cookies we actually set.
5. Contact
Privacy questions: info@instaarch.com or the contact form.