Legal
Cookie Policy
Effective date: 1 August 2026 | Last updated: 1 August 2026
1. What this Policy covers
This Cookie Policy explains how Headshot Marketing Pvt. Ltd. ("Kadaikodi", "we", "us") uses cookies, local storage, session storage, IndexedDB, pixels, web beacons and similar technologies ("cookies") on the Kadaikodi website at kadaikodi.com, the product frontend at app.kadaikodi.com, and the Kadaikodi mobile apps (where they store local state / SDK identifiers). It supplements our Privacy Policy.
2. What cookies are, and how we categorise them
A cookie is a small text file stored on your device by your browser. We use four categories:
- Strictly necessary — required to operate the site or product (authentication, security, load balancing, CSRF, payment/checkout integrity, cookie-consent state). You cannot opt out of these and still use the Service.
- Functional — remember your preferences (theme, language, last city / location, recently viewed carts, cart contents) so the product behaves the way you set it up.
- Analytics / performance — measure how the site and product are used via our self-hosted analytics instance so we can fix bugs and prioritise improvements. We export this data for our own analysis and do not sell it.
- Marketing — measure the effectiveness of our own marketing campaigns. We do not use cookies to share data with third-party advertising networks for cross-context behavioural advertising.
3. The cookies we set
| Cookie / storage key | Set by | Category | Purpose | Duration |
|---|---|---|---|---|
| kk_session, kk_csrf | Burdenoff (first-party) | Strictly necessary | Authenticated session and CSRF protection | Session / 14 days |
| kk_consent | Burdenoff (first-party) | Strictly necessary | Records your cookie-consent choices | 12 months |
| kk_city, kk_locale, kk_theme | Burdenoff (first-party) | Functional | Last city / location, language, theme | 12 months |
| LocalStorage: kk_cart, kk_ui_state | Burdenoff (first-party) | Functional | Persists cart contents and UI state | Until cleared |
| Payment-partner checkout cookies | Razorpay / Stripe | Strictly necessary | Secure checkout and fraud prevention during payment | Per provider |
| __cf_bm, cf_clearance | Cloudflare | Strictly necessary | Bot management, WAF challenge state | Up to 30 days |
| Maps provider tiles/session | [Provider being finalised] | Functional | Map rendering, geocoding and live tracking | Per provider |
| Analytics identifiers | Self-hosted analytics (operated by Burdenoff) | Analytics | Aggregate, de-identified product and website analytics | Up to 13 months |
The exact names above may evolve as the product develops; the categories and providers will not change without notice. We do not load third-party advertising cookies, retargeting pixels, social-network "share" pixels that load without consent, or fingerprinting beyond what Cloudflare and our fraud-prevention require for security.
4. Our product and website analytics
We use a self-hosted, managed-cloud analytics instance that we operate ourselves; our analytics tool is not given commercial access to your data.
- Events recorded include page views, searches, feature usage, error counts, click-stream within the product, and aggregate funnel data — keyed by an internal account / device identifier.
- We may export analytics data for our own analysis and dashboarding. We do not sell analytics data or user-level behavioural profiles to any third party, and we do not share user-level analytics with advertising networks.
- Where analytics processing involves cookies or similar storage on EEA / UK / Swiss visitors' devices, it requires consent — see Section 5.
5. How we ask for consent
- EEA, UK and Switzerland. On your first visit we show a banner that lets you Accept all, Reject non-essential, or open preferences to consent category-by-category. Non-essential cookies are not set until you consent.
- India. We rely on a layered notice — this Cookie Policy plus the banner — consistent with the Digital Personal Data Protection Act, 2023 and the IT Act, 2000 SPDI Rules.
- California and other US states. We honour Global Privacy Control (GPC) signals as opt-out signals for "sale" or "sharing" to the extent state laws require. We do not sell personal information.
- Rest of world. We apply the broader of any local requirement and the EEA standard above where lawful.
6. Controlling cookies
You can:
- Adjust your choices in our cookie preferences centre;
- Delete or block cookies through your browser settings (strictly necessary cookies cannot be disabled without breaking the Service);
- Control mobile SDK / advertising identifiers and location permissions through your device settings;
- Transmit a Global Privacy Control signal — we honour it as a US opt-out signal.
7. Do Not Track
There is no industry consensus on "Do Not Track" (DNT). We do not currently respond to DNT signals, but we honour Global Privacy Control as set out in Section 5.
8. Changes to this Policy
We may update this Cookie Policy from time to time. For material changes that introduce new tracking categories or providers, we will re-prompt EEA / UK / Swiss visitors for consent and notify account holders by email or in-product banner. The current version is always at kadaikodi.com/cookies.
9. Contact
Questions about cookies and tracking: [email protected].