Legal · Cookies
Cookie policy
How SynFi uses browser storage.
SynFi runs on the VirtuOZ platform alongside EvoPay payment and escrow services. This page describes first-party HTTP cookies and similar browser storage when you visit SynFi pages or an authenticated cabinet. Read it with the privacy policy. It does not cover third-party sites linked from deal documents.
Scope
Where this policy applies
This policy covers SynFi on operator-hosted VirtuOZ deployments (for example paths /synfi/*). It applies when you browse public pages, register, or use authenticated project-owner and partner cabinets.
- Shared platform identity. Session and security cookies may be shared across VirtuOZ brands (SynFi, EvoPay) under one account — see the platform disclosures on operator boundaries.
- Deal tools. A cabinet may link to external verification, banking, or document portals with their own cookies. Those are governed by their policies.
- Not legal advice. Cookie rules differ by country. Write to synfi@virtuoz.io for platform clarifications.
Essential cookies
Required for security and sign-in
These first-party cookies are needed for sign-in, form protection, and basic preferences. We do not use them for advertising.
- vtoz_access_token — short-lived access token for authenticated API requests and pages after sign-in.
- vtoz_refresh_token — refresh token to obtain new access tokens without signing in on every visit.
- vtoz_csrf_token — CSRF protection; required to submit forms that change data.
- vtoz_locale — chosen interface language across pages.
Tokens are set with Secure and HttpOnly where applicable, and with SameSite policies suited to a web session. Exact lifetimes follow server configuration (for example a refresh token may last up to 30 days).
Context and optional cookies
Wallet context and trusted devices
- vtoz_wallet_country — wallet country or region for the session in EvoPay-related payment flows.
- vtoz_trusted_device_id and vtoz_trusted_device_token — optional pair when you choose “remember this device” for MFA; identifies a trusted browser for a limited time.
You can avoid trusted-device cookies by not choosing remember-at sign-in. Wallet-context cookies apply only in payment scenarios with regional routing.
Local storage
Theme preference (not a cookie)
The light/dark theme toggle may store your choice in browser localStorage under vtoz_theme. The value is not sent to the server automatically as a cookie and is not used for tracking.
Analytics and advertising
What SynFi pages do not use
- No advertising cookies. Public SynFi pages do not set third-party advertising or retargeting cookies.
- No analytics cookies. Aggregate marketing metrics (views, referrers, button clicks) are processed on the server without analytics cookies in the browser and without cross-site identifiers.
- Future changes. If embedded payment or identity-check flows add cookies, we will update this policy and request consent where required for non-essential cookies.
Managing cookies
Browser settings
You can block or delete cookies in browser settings. Blocking essential session cookies will prevent staying signed in or submitting forms safely. Deleting cookies may sign you out of SynFi and EvoPay under a shared platform session.
We may update this cookie policy when usage changes. Material changes will be reflected on this page.
Questions
Privacy or cookie questions?
For the platform: synfi@virtuoz.io. For broader data processing, see the SynFi privacy policy and platform disclosures.