Cookies & local storage
This policy explains the cookies and browser storage that SQARME CMD uses, why we use them, and how you can manage them. We use only strictly-necessary and functional first-party cookies — no analytics, advertising or cross-site tracking of any kind.
01What cookies & local storage are
A cookie is a small text file that a website asks your browser to store and send back on later visits. Cookies let a site recognise your session — for example, to keep you logged in as you move between pages. Local storage is a related browser feature that lets a site save small pieces of data on your device; unlike a cookie, local storage is not automatically sent to the server with each request, and it stays on your device until you or the site clear it.
This policy covers both the cookies set by SQARME CMD across sqarme.com, cmd.sqarme.com and trial.sqarme.com, and the UI-preference keys we store in your browser's local storage. It forms part of, and should be read with, our Privacy Policy.
02Our approach
We keep our use of browser storage deliberately minimal. Every cookie we set is first-party (set by SQARME on our own domains) and falls into one of two categories:
- Strictly necessary — required for the service to work at all, such as keeping you signed in and routing you securely to your isolated engine. The service cannot function without these.
- Functional — used to remember choices and flow state, such as where you are in the signup flow or a short-lived self-heal flag, so the experience behaves correctly.
We do not use any analytics, advertising, profiling or cross-site tracking cookies. There is no Google Analytics, Meta Pixel, Segment, or any similar tracker on our domains. We do not sell or share browsing data, and we do not build advertising profiles.
No tracking cookies. Everything we store is either strictly necessary to run your session and engine routing, or a functional preference. None of it is used for advertising, analytics or cross-site tracking.
03Strictly-necessary & functional cookies
The table below lists the first-party cookies we may set. Lifetimes are approximate. Cookies marked Secure in production are sent only over HTTPS on our live sites. HttpOnly cookies cannot be read by page scripts, which reduces the risk of theft.
| Name | Purpose | Duration | Type |
|---|---|---|---|
| cp_session | Control-plane login session. HttpOnly; SameSite=Strict; Secure in production. |
~12 hours | Strictly necessary |
| sqarme_rt | Signed routing token that forwards you to your own isolated engine. Carries only your username and grants no access by itself — your master-password and TOTP login is the gate. HttpOnly; SameSite=Lax; Secure in production. |
~30 days | Strictly necessary / functional |
| sqarme_flow | Tracks your progress through the signup flow. HttpOnly; SameSite=Lax. |
~1 hour | Functional |
| sqarme_heal | Short-lived portal self-heal flag used to recover a broken routing state. HttpOnly. |
~30 seconds | Functional |
| Engine dashboard session | Your trading-dashboard login session (Flask). The CSRF token is held server-side in this session, not as its own cookie. HttpOnly; SameSite=Strict; Secure in production. |
Until browser closes | Strictly necessary |
| Trial session | Your trial-demo session on trial.sqarme.com. HttpOnly; SameSite=Lax. |
~24 hours | Strictly necessary |
04Local storage (UI preferences)
The following keys are stored in your browser's local storage to remember your interface preferences. They live on your device, are never sent to our servers, and you can clear them at any time from your browser settings (clearing them simply resets the matching preference to its default).
| Key | Purpose |
|---|---|
| c2cx_theme | Your light or dark theme choice. |
| c2cx_themes_custom | Any custom colour palettes you have saved. |
| c2cx_perf_lite | Performance-lite mode preference (reduces visual effects). |
| c2cx_privacy | Privacy mode — blurs sensitive numbers on screen. |
| c2cx_ticker_hidden | Whether the live ticker is hidden. |
| c2cx_pinned_settings | Settings you have pinned to the top bar. |
| qr_widget_pos | The remembered position of the QR widget. |
| p2p_notif_prefs | Your notification preferences. |
| home_pay_mru | Most-recently-used entries on the home pay box. |
| home_market_amt | Last amount used in the home market widget. |
| home_market_methods | Last payment methods selected in the home market widget. |
| home_sug_resolved | Which home suggestions you have dismissed or resolved. |
These preferences are convenience features only. Because they stay on your device and are never transmitted to us, they are not used to identify or track you.
05Third-party resources
Our pages load a small number of resources from third-party content-delivery networks. These providers do not set cookies on our domain, but because your browser connects to them directly they may log your IP address and user-agent under their own policies:
- Google Fonts — serves the web fonts used across the site. Google may log connection metadata (IP, user-agent) when your browser fetches a font.
- Cloudflare cdnjs — serves the Socket.IO realtime library used by the dashboard. Cloudflare may log connection metadata when the file is fetched.
Within the dashboard, your browser may also connect directly to IP-lookup and currency-rate endpoints to power security and market features; like the resources above, these set no cookie on our domain but may log your IP and user-agent under their own policies.
These are infrastructure resources, not trackers. We do not embed advertising, analytics or social-media tracking scripts. For the full list of third parties involved in running the service, see the Privacy Policy.
06Managing cookies
You can view, block and delete cookies through your browser's settings. Most browsers also let you clear local storage for a specific site. The exact steps vary by browser — look for the “Cookies and site data” or “Privacy and security” section of your browser's settings, or its help pages.
Blocking strictly-necessary cookies will break the service. The session and routing cookies listed in section 3 are required to log in, stay signed in and reach your isolated engine. If you block or delete them, you will not be able to use SQARME CMD until they are allowed again.
Clearing the functional cookies or the local-storage keys is safe — at most you will be returned to the start of a flow or have a preference reset to its default.
07Consent
We rely only on strictly-necessary and functional first-party storage, and we set no analytics, advertising or cross-site tracking cookies. Strictly-necessary cookies are exempt from prior consent because the service you have asked for cannot work without them. Functional cookies and the UI-preference keys are set in the course of providing the features you use, and you remain in control through your browser settings and the in-app preference toggles.
Because we do not set non-essential tracking cookies, we do not currently present a cookie-consent banner. If we ever introduce a cookie that is not strictly necessary or functional, we will update this policy and seek your consent where the law requires it.
08Changes & contact
We may update this Cookie Policy from time to time to reflect changes to our service or to legal requirements. When we do, we will revise the “Last updated” date shown at the top of this page. Material changes will be communicated through the service where appropriate.
For more on how we handle your personal data, please read our Privacy Policy. If you have any questions about this Cookie Policy or our use of browser storage, contact us:
- care@sqarme.com
- Grievance Officer
- The Grievance Officer, SQARME PRIVATE LIMITED, reachable at grievance@sqarme.com.
- Registered office
- 44 Backary Portion, 2nd Floor, Regal Building, Connaught Place, New Delhi – 110001, India.
- Phone & WhatsApp
- +91 99903 22528 · Mon–Fri, 10 AM – 6 PM IST.
Still need a hand?
Our team replies Mon–Fri, 10 AM – 6 PM IST.