Cookie & Local Storage Notice
Last updated: 2026-07-15
This summary is provided for transparency and is not specific legal or tax advice. Questions? Contact support@billsos.com.
BillsOS uses only essential first-party cookies required to operate the Service. We do not use third-party advertising, cross-site tracking, or analytics cookies.
1. Cookies We Use
| Cookie name | Purpose | Lifetime | Type |
|---|---|---|---|
__Host-bos_session |
Login session — authenticates you while logged in | Session / 30 days | Essential |
__Host-bos_lang |
Language preference — remembers whether you prefer Thai or English | 1 year | Essential |
__Host-bos_ref |
Signup attribution — remembers which channel you clicked through before signing up (e.g. a referral link or guide page) | 1 hour | Essential |
Details on these cookies
- The session cookie (
__Host-bos_session) uses the__Host-prefix for maximum security — preventing subdomain override. It is set asHttpOnly,Secure,SameSite=Laxto guard against XSS and CSRF. - The language cookie (
__Host-bos_lang) stores only the value "th" or "en". No personal data is held in this cookie. - The attribution cookie (
__Host-bos_ref) is set only when you land on the signup page via a link carrying a channel parameter. It stores only a short channel code (e.g. a campaign name or referral code) — no name, email, or other identifying data — and expires automatically within 1 hour whether or not you complete signup.
2. What We Do Not Use
- No third-party tracking pixels or beacons
- No advertising or retargeting cookies
- No analytics cookies (e.g. Google Analytics)
- No social-media cookies
Because we use only essential cookies that do not require consent under PDPA and related law, we do not show an accept/reject cookie consent banner. We do show a short informational notice for transparency, which you can dismiss. Your dismissal is remembered in your browser's local storage, not a cookie.
3. Cloudflare and Rate-Limiting
Cloudflare (our hosting provider) may set security, DDoS-protection, and rate-limiting cookies or tokens at the infrastructure level. These are considered essential for the secure operation of the Service.
4. Third-Party Widgets (Stripe, Cloudflare Turnstile)
Some pages embed third-party widgets required for the Service to function: subscription checkout uses Stripe Checkout/Customer Portal, and certain forms (e.g. Contact) may use Cloudflare Turnstile to verify you are not a bot. These widgets may set their own cookies on the provider's own domain (not billsos.com), governed by Stripe's and Cloudflare's respective privacy policies, not this Notice.
5. Local Storage
The Service may use browser local storage for transient UI state (e.g. form state). This data is never transmitted to our servers and is cleared when you clear your browser's local storage.
6. How to Clear or Disable Cookies
You can delete or disable cookies via your browser settings:
- Chrome: Settings → Privacy and security → Clear browsing data
- Firefox: Settings → Privacy & Security → Cookies and Site Data → Clear Data
- Safari: Settings → Privacy → Manage Website Data
- Edge: Settings → Privacy, search, and services → Clear browsing data
Note: deleting the session cookie will log you out automatically.
7. Contact
For questions about our use of cookies, please contact support@billsos.com.
© 2026 BillsOS · a product of Cavastir · support@billsos.com