1. What cookies are
A cookie is a small text file placed on your device when you visit a website. It lets the site recognise your browser on later requests. Cookies set by the site you are visiting are called first-party cookies; those set by another domain are third-party cookies. A session cookie is deleted when you close your browser; a persistent cookie remains for a set period.
We also use technologies that work similarly — local storage, session storage, and pixels. This policy covers those too, and refers to all of them as "cookies".
2. Why we use them
- To sign you in and keep you signed in across pages and, if you choose, across visits.
- To keep the Services secure — protecting against cross-site request forgery, session hijacking, brute-force sign-in attempts, and automated abuse of booking pages.
- To make things work correctly — routing your requests to the right server, remembering your time zone so slots display accurately, and remembering your language and interface preferences.
- To understand usage in aggregate — which features are used, where errors occur, and how pages perform.
- To measure our own marketing, on our marketing website only.
3. Categories we use
| Category | Purpose | Consent required? |
| Strictly necessary |
Authentication, session management, CSRF protection, load balancing, abuse and fraud prevention, remembering your cookie choices. |
No — essential and cannot be switched off. Blocking them will break sign-in and booking. |
| Functional |
Time zone, language, interface preferences, dismissed notices, onboarding progress. |
Yes, where required by local law. |
| Analytics / performance |
Aggregate usage measurement, feature adoption, page performance, error and crash reporting. |
Yes, where required by local law. |
| Marketing |
Measuring campaign performance and attribution — on our marketing website only. |
Yes. |
4. Cookies we set
The table below lists the cookies Sloto sets directly. Names and durations may change as we update the platform; we review this list at least every [6] months.
Strictly Necessary
| Name | Purpose | Duration |
[sloto_session] | Maintains your signed-in session and links requests to your account | Session |
[sloto_remember] | Keeps you signed in across visits, if you select "Remember me" | [30] days |
[sloto_csrf] | Cross-site request forgery token — verifies form and API submissions originate from our pages | Session |
[sloto_lb] | Load balancing — keeps your session on a consistent server | Session |
[sloto_bot] | Rate limiting and automated-abuse detection on booking pages and sign-in | [24] hours |
[sloto_consent] | Records your cookie preferences so we do not ask again | [12] months |
Functional
| Name | Purpose | Duration |
[sloto_tz] | Stores your detected or selected time zone so meeting times display correctly | [12] months |
[sloto_lang] | Remembers your language preference | [12] months |
[sloto_ui] | Interface preferences — calendar view, week start day, dismissed banners | [12] months |
Analytics
| Name | Purpose | Duration |
[sloto_aid] | Pseudonymous identifier used to count unique sessions and measure feature usage in aggregate | [13] months |
[_analytics provider cookies] | Set by our analytics provider — see Section 5 | [varies] |
5. Third-party cookies
Some cookies are set by providers we use to run the Services. We do not control their cookies; their own policies govern them.
| Provider | Used for | Where set | Their policy |
| [Analytics provider] | Aggregate usage and performance measurement | Marketing site and app | [link] |
| [Error monitoring provider] | Crash and error diagnostics | App | [link] |
| [Payment gateway] | Fraud prevention and payment processing during checkout | Checkout only | [link] |
| [Support chat / helpdesk] | Live chat session continuity | Marketing site and app | [link] |
| [Marketing / ad measurement] | Campaign attribution | Marketing site only | [link] |
If you sign in using Google, Microsoft or another identity provider, or connect a calendar or conferencing account, that provider may set its own cookies during the authorisation flow. See our Privacy Policy, Section 4.
6. Cookies on booking pages
Note: We do not place advertising or cross-site tracking cookies on Sloto booking pages. Invitees visiting a booking page receive only strictly necessary cookies, plus time zone and language cookies needed to show correct slot times.
Hosts cannot add their own tracking scripts or advertising pixels to Sloto-hosted booking pages. Where a Host embeds a Sloto booking widget on their own website, that website may set its own cookies — governed by that Host's cookie policy, not ours.
7. Other similar technologies
- Local and session storage: Used to cache interface state, draft form entries, and availability data so pages load faster and you do not lose work on refresh. Cleared when you sign out or clear site data.
- Pixels in email: Our transactional and marketing emails may contain a small image that tells us whether the message was opened. We use this for deliverability troubleshooting and to stop sending marketing to inactive addresses. Blocking images in your email client prevents it.
- Server logs: Not a cookie, but we record IP address, user agent, and request metadata for security and diagnostics. See the retention table in our Privacy Policy.
8. Your consent
Where the law requires it — including in the EEA, the UK, and other jurisdictions with equivalent rules — we show a consent banner on your first visit and set non-essential cookies only after you accept them. Strictly necessary cookies are set without consent, because the Services cannot function without them.
You can accept all, reject all non-essential, or choose by category. Rejecting is as easy as accepting. Your choice is stored in the [sloto_consent] cookie and honoured for [12] months, after which we will ask again. You can change your choice at any time using the button at the top of this page and in our site footer.
9. Managing and deleting cookies
Besides our preference centre, you can control cookies in your browser — blocking all cookies, blocking third-party cookies only, or deleting existing ones. Instructions are in your browser's help pages, typically under Settings → Privacy.
Blocking strictly necessary cookies will stop you signing in, and will prevent booking pages from working. Blocking functional cookies may cause meeting times to display in the wrong time zone.
Browser-level blocking applies to that browser and device only. If you use several browsers or devices, set your preference on each. Clearing cookies also clears your saved preference, so the banner will reappear.
10. Do Not Track and Global Privacy Control
We honour Global Privacy Control (GPC) signals where legally required, treating them as an opt-out of non-essential cookies and of any sharing for cross-context behavioural advertising. We do not currently respond to browser "Do Not Track" headers, because no common industry standard for interpreting them exists.
11. Legal basis and transfers
Where the EU or UK GDPR applies, we set strictly necessary cookies on the basis of our legitimate interests in operating and securing the Services, and all other cookies on the basis of your consent. Where India's Digital Personal Data Protection Act, 2023 applies, non-essential cookies are set on the basis of your consent, with notice given through our banner.
Data collected through cookies may be processed in India and in other countries where our service providers operate. Transfer safeguards are described in Section 9 of our Privacy Policy.
12. Changes to this policy
We may update this policy as we add, remove or change the technologies we use. The "Last updated" date will change. Where a change materially affects how we use cookies, we will refresh the consent banner and ask for your choice again.
Questions about this Disclaimer:
Caresoft Systems Private Limited
Registered office address: 311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107
Email: [email protected]
Grievance Officer: Rajeev Pillai
CIN NO - U72900MH2022PTC387875