Cookie Policy

Last updated: August 1, 2026 | Effective: August 1, 2026

1. Introduction

Headshot Marketing Private Limited ("we," "our," or "us") uses cookies and similar tracking technologies on our website headshotmarketing.com and the HeadshotMarketing product frontend at app.headshotmarketing.com (together, the "Service"). This Cookie Policy explains what cookies are, how we use them, and your choices regarding their use.

This Policy supplements our Privacy Policy. The canonical version of this Policy lives in the HeadshotMarketing specs repo and at headshotmarketing.com/cookies.

2. What Are Cookies?

Cookies are small text files that are placed on your device when you visit a website or use an app. "Similar technologies" — local storage, session storage, IndexedDB, web beacons and pixels — work differently but raise the same privacy questions.

We use four categories:

  • Strictly necessary — required to operate the Service (authentication, security, load balancing, CSRF, cookie-consent state). You cannot opt out of these and still use the Service.
  • Functional — remember your preferences (theme, language, last-viewed tenant / workspace) so the product behaves the way you set it up.
  • Analytics / performance — measure how the site and product are used via our self-hosted Rybbit instance so we can fix bugs and prioritise improvements. We do not sell this data.
  • Marketing — measure the effectiveness of our own marketing and waitlist sign-ups. We do not use cookies to share data with third-party advertising networks for cross-context behavioural advertising.

3. The Cookies We Set

The exact cookie names may evolve as the product develops; the categories and providers will not change without notice. We do not load third-party advertising cookies, retargeting pixels, social-network "share" pixels that load without consent, or fingerprinting beyond what Cloudflare uses for bot mitigation.

3.1 Strictly Necessary Cookies

Cookie / keySet byPurposeDuration
Session / CSRF tokensHeadshotMarketingAuthenticated session and CSRF protectionSession / 14 days
Consent stateHeadshotMarketingRecords your cookie-consent choices12 months
`__cf_bm`, `cf_clearance`CloudflareBot management and security challenge stateUp to 30 days

3.2 Functional Cookies

Cookie / keySet byPurposeDuration
Theme, locale, tenantHeadshotMarketingTheme (light/dark), language, last-viewed workspace12 months
UI state (localStorage)HeadshotMarketingPersists UI state (tabs, sidebar, scroll position)Until cleared

3.3 Analytics Cookies

Cookie / keySet byPurposeDuration
Rybbit analytics identifiersRybbit (self-hosted by Algoshred)Aggregate, de-identified product and website analyticsUp to 13 months

3.4 Marketing Cookies

We do not use advertising or retargeting cookies from third-party networks. Any marketing cookies are limited to measuring the effectiveness of our own campaigns and waitlist sign-ups and are not used to profile your contacts, leads or customers.

4. How We Ask for Consent

  • EEA, UK and Switzerland: on your first visit we show a banner that lets you accept all, reject non-essential, or open preferences to consent category-by-category. Non-essential cookies are not set until you consent.
  • India: we rely on a layered notice — this Cookie Policy plus the banner — consistent with the Digital Personal Data Protection Act, 2023 and the IT Act, 2000 SPDI Rules.
  • California and other US states: we honour Global Privacy Control (GPC) signals as opt-out signals for "sale" or "sharing" to the extent state laws require. We do not sell personal information.

You can change your choices at any time via our Cookie Preferences page.

5. Managing Cookies

You have several options for managing cookies:

  • Adjust your choices on our Cookie Preferences page.
  • Delete or block cookies through your browser settings. Note that strictly necessary cookies cannot be disabled without breaking the Service.
  • Use browser features like Private / Incognito mode or anti-tracking extensions.
  • Transmit a Global Privacy Control signal — we honour it as a US opt-out signal.

Browser-level controls:

6. Do Not Track Signals

There is no industry consensus on "Do Not Track" (DNT). We do not currently respond to DNT signals, but we honour Global Privacy Control as set out in Section 4.

7. Children's Privacy

HeadshotMarketing is a business marketing platform intended for adults aged 18 and over acting in a business capacity and the organisations that use it. It is not directed to children and we do not knowingly create user accounts for individuals under 18.

8. Updates to This Cookie Policy

We may update this Cookie Policy from time to time. For material changes that introduce new tracking categories or providers, we will re-prompt EEA / UK / Swiss visitors for consent and notify account holders by email or in-product banner. The current version is always at headshotmarketing.com/cookies.

9. Contact Us

If you have any questions or concerns about this Cookie Policy or our use of cookies, please contact us at:

Headshot Marketing Private Limited
Registered office: "VISWAM", Plot No. 43, Veeramani Nagar, 2nd Cross Street, Nanmangalam, Chennai – 600117, Tamil Nadu, India

Email: [email protected]
Security: [email protected]