Cookie Policy

Last updated: April 20, 2026

This Cookie Policy explains how ZDottedLine Inc. ("Zdottedline," "we," "us," or "our") uses cookies and similar technologies on the zdottedline.com website and e-signature platform. This policy should be read alongside our Privacy Policy.

What Are Cookies

Cookies are small text files stored on your device when you visit a website. They help the site remember your preferences, maintain your session, and improve your experience.

Cookies We Use

Essential Cookies (Strictly Necessary)

These cookies are required for the platform to function. They cannot be disabled without breaking core functionality. Under the ePrivacy Directive, these cookies do not require consent as they are strictly necessary for the service you requested.

CookiePurposeDuration
Authentication tokenSecure HttpOnly cookie that maintains your login session (SameSite=Strict)7 days
CSRF tokenPrevents cross-site request forgery attacks on form submissionsSession
Session identifierMaintains your session state across page loads30 minutes (inactivity timeout)

Preference Cookies (Optional)

These cookies remember your choices to provide a personalized experience.

CookiePurposeDuration
Theme preferenceRemembers your light/dark mode choice1 year
Language preferenceRemembers your language selection1 year

Cookies We Do NOT Use

Zdottedline is committed to minimal data collection. We do not use:

  • Third-party advertising or retargeting cookies
  • Social media tracking pixels (Facebook Pixel, LinkedIn Insight, etc.)
  • Cross-site tracking cookies
  • Analytics cookies that identify individual users
  • Fingerprinting or device-identification technologies beyond what is necessary for signature evidence collection

Managing Cookies

You can control cookies through your browser settings. Most browsers allow you to block or delete cookies. However, disabling essential cookies will prevent you from using the platform's authenticated features (login, document signing, account management).

Instructions for managing cookies in common browsers:

  • Chrome: Settings → Privacy and Security → Cookies
  • Firefox: Settings → Privacy & Security → Cookies
  • Safari: Preferences → Privacy → Manage Website Data
  • Edge: Settings → Cookies and Site Permissions

Data Retention for Cookie Data

Session data associated with cookies is retained only for the duration specified in the tables above. Authentication sessions expire after 30 minutes of inactivity. Refresh tokens expire after 7 days. Upon expiration or logout, session data is invalidated and removed from our servers. Our data retention practices are governed by our internal Data Retention Policy.

Security of Cookie Data

All authentication cookies are configured with security best practices:

  • HttpOnly: Prevents JavaScript access (mitigates XSS attacks)
  • Secure: Only transmitted over HTTPS connections
  • SameSite=Strict: Prevents cross-site request forgery

In the event of a security incident affecting session data, our Incident Response Plan governs notification, containment, and remediation procedures. See our GDPR Compliance page for details on our incident response commitments.

Changes to This Policy

We may update this Cookie Policy from time to time. Material changes will be communicated through a notice on the platform.

Contact

Questions about our cookie practices? Contact us at privacy@zdottedline.com.