Legal document

Cookie & Local Storage Notice

Last updated: 2026-07-15

This summary is provided for transparency and is not specific legal or tax advice. Questions? Contact support@billsos.com.

BillsOS uses only essential first-party cookies required to operate the Service. We do not use third-party advertising, cross-site tracking, or analytics cookies.

1. Cookies We Use

Cookie name Purpose Lifetime Type
__Host-bos_session Login session — authenticates you while logged in Session / 30 days Essential
__Host-bos_lang Language preference — remembers whether you prefer Thai or English 1 year Essential
__Host-bos_ref Signup attribution — remembers which channel you clicked through before signing up (e.g. a referral link or guide page) 1 hour Essential

Details on these cookies

  • The session cookie (__Host-bos_session) uses the __Host- prefix for maximum security — preventing subdomain override. It is set as HttpOnly, Secure, SameSite=Lax to guard against XSS and CSRF.
  • The language cookie (__Host-bos_lang) stores only the value "th" or "en". No personal data is held in this cookie.
  • The attribution cookie (__Host-bos_ref) is set only when you land on the signup page via a link carrying a channel parameter. It stores only a short channel code (e.g. a campaign name or referral code) — no name, email, or other identifying data — and expires automatically within 1 hour whether or not you complete signup.

2. What We Do Not Use

  • No third-party tracking pixels or beacons
  • No advertising or retargeting cookies
  • No analytics cookies (e.g. Google Analytics)
  • No social-media cookies

Because we use only essential cookies that do not require consent under PDPA and related law, we do not show an accept/reject cookie consent banner. We do show a short informational notice for transparency, which you can dismiss. Your dismissal is remembered in your browser's local storage, not a cookie.

3. Cloudflare and Rate-Limiting

Cloudflare (our hosting provider) may set security, DDoS-protection, and rate-limiting cookies or tokens at the infrastructure level. These are considered essential for the secure operation of the Service.

4. Third-Party Widgets (Stripe, Cloudflare Turnstile)

Some pages embed third-party widgets required for the Service to function: subscription checkout uses Stripe Checkout/Customer Portal, and certain forms (e.g. Contact) may use Cloudflare Turnstile to verify you are not a bot. These widgets may set their own cookies on the provider's own domain (not billsos.com), governed by Stripe's and Cloudflare's respective privacy policies, not this Notice.

5. Local Storage

The Service may use browser local storage for transient UI state (e.g. form state). This data is never transmitted to our servers and is cleared when you clear your browser's local storage.

6. How to Clear or Disable Cookies

You can delete or disable cookies via your browser settings:

  • Chrome: Settings → Privacy and security → Clear browsing data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data → Clear Data
  • Safari: Settings → Privacy → Manage Website Data
  • Edge: Settings → Privacy, search, and services → Clear browsing data

Note: deleting the session cookie will log you out automatically.

7. Contact

For questions about our use of cookies, please contact support@billsos.com.

© 2026 BillsOS · a product of Cavastir  ·  support@billsos.com