Cookie policy
EvoPay LLP · BIN 240440034473
Effective date: 1 January 2026
Last updated: 18 July 2026
1. Introduction
This Policy describes the cookies and similar browser storage used by the EvoPay service on the VirtuOZ platform when you use the site in a browser. For personal data in general, see the Privacy policy.
2. Cookies we set
We use first-party cookies:
- vtoz_access_token — short-lived access token after sign-in.
- vtoz_refresh_token — refresh token so you need not sign in on every visit.
- vtoz_csrf_token — CSRF protection for forms that change data.
- vtoz_locale — selected UI language.
- vtoz_wallet_country — wallet country / region for the session.
- vtoz_trusted_device_id and vtoz_trusted_device_token — pair for optional “remember this device” MFA; limited lifetime.
Where appropriate for tokens, we set Secure and HttpOnly, plus a SameSite policy.
Lifetimes follow server configuration (refresh up to 30 days; trusted-device tokens match the “remember device” period).
3. Theme preference (not a cookie)
Light / dark theme may be stored in localStorage under vtoz_theme. It is not sent to the server automatically.
4. What we do not use
This web shell does not use advertising cookies or third-party analytics cookies. If payment or identity flows later need extra cookies, we will update this Policy and, where required, ask for consent before setting non-essential cookies.
5. Managing cookies
You can block or delete cookies in browser settings. Without essential session cookies you cannot stay signed in or submit forms securely.
6. Changes
We may update this Policy when cookie use changes. The “Last updated” date changes accordingly.