Legal

Cookie Policy

Effective date: 1 August 2026 | Last updated: 1 August 2026

1. What this Policy covers

This Cookie Policy explains how Headshot Marketing Pvt. Ltd. ("Kadaikodi", "we", "us") uses cookies, local storage, session storage, IndexedDB, pixels, web beacons and similar technologies ("cookies") on the Kadaikodi website at kadaikodi.com, the product frontend at app.kadaikodi.com, and the Kadaikodi mobile apps (where they store local state / SDK identifiers). It supplements our Privacy Policy.

2. What cookies are, and how we categorise them

A cookie is a small text file stored on your device by your browser. We use four categories:

  • Strictly necessary — required to operate the site or product (authentication, security, load balancing, CSRF, payment/checkout integrity, cookie-consent state). You cannot opt out of these and still use the Service.
  • Functional — remember your preferences (theme, language, last city / location, recently viewed carts, cart contents) so the product behaves the way you set it up.
  • Analytics / performance — measure how the site and product are used via our self-hosted analytics instance so we can fix bugs and prioritise improvements. We export this data for our own analysis and do not sell it.
  • Marketing — measure the effectiveness of our own marketing campaigns. We do not use cookies to share data with third-party advertising networks for cross-context behavioural advertising.

3. The cookies we set

Cookie / storage keySet byCategoryPurposeDuration
kk_session, kk_csrfBurdenoff (first-party)Strictly necessaryAuthenticated session and CSRF protectionSession / 14 days
kk_consentBurdenoff (first-party)Strictly necessaryRecords your cookie-consent choices12 months
kk_city, kk_locale, kk_themeBurdenoff (first-party)FunctionalLast city / location, language, theme12 months
LocalStorage: kk_cart, kk_ui_stateBurdenoff (first-party)FunctionalPersists cart contents and UI stateUntil cleared
Payment-partner checkout cookiesRazorpay / StripeStrictly necessarySecure checkout and fraud prevention during paymentPer provider
__cf_bm, cf_clearanceCloudflareStrictly necessaryBot management, WAF challenge stateUp to 30 days
Maps provider tiles/session[Provider being finalised]FunctionalMap rendering, geocoding and live trackingPer provider
Analytics identifiersSelf-hosted analytics (operated by Burdenoff)AnalyticsAggregate, de-identified product and website analyticsUp to 13 months

The exact names above may evolve as the product develops; the categories and providers will not change without notice. We do not load third-party advertising cookies, retargeting pixels, social-network "share" pixels that load without consent, or fingerprinting beyond what Cloudflare and our fraud-prevention require for security.

4. Our product and website analytics

We use a self-hosted, managed-cloud analytics instance that we operate ourselves; our analytics tool is not given commercial access to your data.

  • Events recorded include page views, searches, feature usage, error counts, click-stream within the product, and aggregate funnel data — keyed by an internal account / device identifier.
  • We may export analytics data for our own analysis and dashboarding. We do not sell analytics data or user-level behavioural profiles to any third party, and we do not share user-level analytics with advertising networks.
  • Where analytics processing involves cookies or similar storage on EEA / UK / Swiss visitors' devices, it requires consent — see Section 5.

5. How we ask for consent

  • EEA, UK and Switzerland. On your first visit we show a banner that lets you Accept all, Reject non-essential, or open preferences to consent category-by-category. Non-essential cookies are not set until you consent.
  • India. We rely on a layered notice — this Cookie Policy plus the banner — consistent with the Digital Personal Data Protection Act, 2023 and the IT Act, 2000 SPDI Rules.
  • California and other US states. We honour Global Privacy Control (GPC) signals as opt-out signals for "sale" or "sharing" to the extent state laws require. We do not sell personal information.
  • Rest of world. We apply the broader of any local requirement and the EEA standard above where lawful.

6. Controlling cookies

You can:

  • Adjust your choices in our cookie preferences centre;
  • Delete or block cookies through your browser settings (strictly necessary cookies cannot be disabled without breaking the Service);
  • Control mobile SDK / advertising identifiers and location permissions through your device settings;
  • Transmit a Global Privacy Control signal — we honour it as a US opt-out signal.

7. Do Not Track

There is no industry consensus on "Do Not Track" (DNT). We do not currently respond to DNT signals, but we honour Global Privacy Control as set out in Section 5.

8. Changes to this Policy

We may update this Cookie Policy from time to time. For material changes that introduce new tracking categories or providers, we will re-prompt EEA / UK / Swiss visitors for consent and notify account holders by email or in-product banner. The current version is always at kadaikodi.com/cookies.

9. Contact

Questions about cookies and tracking: [email protected].