Cookies and similar technologies
A cookie is a small text record stored by a browser. Evalat also uses local storage, session storage, service workers, and browser cache for closely related purposes. These technologies do not give Urjasoft access to unrelated files on your device.
Evalat uses four categories:
- Essential: required for authentication, security, consent, assessment continuity, fraud prevention, and requested transactions. These cannot be disabled through the Evalat preference panel.
- Functional preferences: remember choices you make, such as theme, layout, saved filters, and push-subscription state. They do not advertise to you.
- Analytics: optional measurement of public-page visits, performance, and interaction patterns to improve the service.
- Marketing: optional campaign measurement or advertising attribution. This category is separate from analytics and is not required to use Evalat.
Current first-party cookies and storage
| Name or storage | Category | Purpose | Typical duration |
|---|---|---|---|
evalat_session | Essential | Keeps authentication, CSRF protection, flash messages, account recovery state, and assessment continuity in one protected session. It is HttpOnly, SameSite protected, and Secure on production HTTPS. | Configured session period; invalidated by logout, idle or absolute timeout, or server expiry |
evalat_cookie_consent | Essential preference | Stores the consent version, selected optional categories, and update time so the banner does not ask on every visit. | 12 months, then consent is requested again |
evalat-theme in local storage | Functional | Remembers light, dark, or system theme on this browser. | Until changed or browser storage is cleared |
evalat:* workspace keys in local storage | Functional | Remember saved filter views, command favorites and recents, panel state, workspace history, and a saved layout on the device. These records contain interface choices and route references, not passwords. | Until removed by the user, the feature, or browser cleanup |
evalat.push.endpoint in local storage | Functional | Remembers the endpoint of a push subscription you explicitly enable so it can be managed or revoked. | Until push is revoked or storage is cleared |
| Session storage | Essential / functional | Temporarily carries same-tab navigation feedback and transient interface state. | Current browser tab session |
| Service worker and Cache Storage | Essential / functional | Caches versioned static assets for performance, installation, and limited offline behavior. It does not cache private assessment responses as a substitute for server storage. | Rotated on app updates or removed by browser/site-data controls |
The CSRF token is held inside the protected server session and is not a separate readable cookie. Evalat does not store passwords, Aadhaar numbers, Aadhaar OTPs, card PINs, or UPI PINs in cookies or browser storage.
Optional and later-stage services
The following integrations are supported for possible production use. They load only on public pages, only when Urjasoft configures the relevant identifier, and only after the matching browser consent. Registration, login, and signed-in workspaces do not load these optional public-page tags.
| Service | Category | Possible cookies or data | Use |
|---|---|---|---|
| Google Analytics 4 | Analytics | May set _ga and a property-specific _ga_* identifier; duration is controlled by Google and Urjasoft's configuration. | Aggregated public-page traffic, performance, and navigation measurement. IP anonymization is requested by Evalat's tag configuration. |
| Google Tag Manager | Analytics or marketing, depending on the tag | The container itself is a tag loader; tags deployed through it may set their own cookies. | Loads only tags covered by the consent category granted. Urjasoft must not use it to bypass this preference mechanism. |
| Microsoft Clarity | Analytics | May set _clck, _clsk, and Microsoft-domain identifiers described by Microsoft. | Public-page interaction and performance analysis, which may include pseudonymous click, scroll, and session-replay data. |
| Meta Pixel | Marketing | May set _fbp and receive browser, page, event, and campaign-attribution information. Meta describes _fbp as lasting up to 90 days. | Campaign attribution and measurement. It is never required for an Evalat account or assessment. |
Urjasoft will update this Policy and, where necessary, request a new choice before adding a materially different optional purpose. Optional tags are not intended for targeted advertising to children.
Payment, identity, OAuth, and linked providers
When you choose Google sign-in, open Cashfree Secure ID or DigiLocker, complete a payment, view an embedded provider feature, or follow a third-party link, that provider may set cookies on its own domain under its own policy. Those cookies are not created by the Evalat domain and Urjasoft cannot directly delete them from your browser.
Rejecting Evalat analytics or marketing cookies does not prevent an essential provider cookie that is necessary to complete a payment, security check, or identity flow you requested. Review the provider notice before continuing its hosted flow.
Manage this browser's preferences
Changing a choice stops the related tags from loading on later requests. A provider cookie already stored may remain until it expires or you remove it through browser controls. Your choice applies to this browser and device; repeat it on other browsers or devices.
Browser and device controls
Most browsers let you inspect, block, or delete cookies and site data. Blocking all cookies can prevent login, account recovery, assessment autosave, payment return, or other essential workflows. You can usually remove Evalat data from the browser's privacy or site-settings panel and revoke push notifications in browser notification settings.
Browser "Do Not Track" signals are not interpreted as a substitute for the explicit choices above because there is no uniform standard. Global privacy signals will be honored where applicable law requires and the signal can be reliably applied.
Policy changes
Urjasoft may update this Policy when storage, providers, purposes, or legal requirements change. The effective date will be updated. A materially new optional use will not be treated as accepted merely because an older category was enabled.
Contact
B-8, Basement Floor, Sector-2, Noida 201301, India
Email: contact@urjasoft.com
Phone: +91 767 864 9274
For a privacy or cookie request, use the subject "Evalat Cookie / Privacy Request" or submit the contact form.