Cookie Policy — Corelatin
Version 2026-09 | Last Updated: September 2026 | Effective upon use of the Platform
1. What this policy covers
Cookies are small text files stored in your browser that let a website remember your session, preferences, or consent choices. This policy also covers similar browser technologies we use — localStorage (which stores data in your browser, not as a cookie) — and third-party scripts that may set cookies on their own domains when you use a feature (for example, signing in with Google or paying through PayU).
We do not use advertising networks, retargeting pixels, social-media trackers, or any marketing/advertising cookies.
2. Cookies and storage we use
The table below is the complete, current inventory. Anything not listed here is not in use.
2.1 First-party cookies (set by corelatin.in)
| Name | Category | Purpose | Duration |
|---|---|---|---|
cc_session |
Strictly Necessary | Your session: sign-in state, security tokens (CSRF), and booking-flow state. | 30 days |
remember_token |
Strictly Necessary | Keeps you signed in between visits after you log in. | 30 days |
companion_remember |
Strictly Necessary | Keeps companion accounts signed in on the companion portal. | 30 days |
cc_consent |
Strictly Necessary | Stores your cookie-consent choice, a consent reference ID, and the policy version it applies to — so we don't ask again every visit, and can show what you agreed to. | 12 months |
cc_lang |
Functional | Your language preference (English or Hindi) so the site renders in your chosen language across pages and visits. | 1 year |
2.2 Browser storage (localStorage — not cookies)
| Key | Category | Purpose | Duration |
|---|---|---|---|
cc-theme |
Functional | Your light/dark theme preference. | Until you clear it |
cc-lang |
Functional | Local copy of your language preference used by client-side widgets. | Until you clear it |
booking_form_data |
Functional | Draft autosave on the booking form so you don't lose progress. | Until cleared or the booking is submitted |
companion_form_data, companion_form_step |
Functional | Draft autosave on the companion-application form. | Until cleared |
admin_* keys |
Functional | Internal staff-console view preferences. Staff-facing only. | Until cleared |
2.3 Third-party cookies (set by the provider on its own domain)
| Name | Provider | Category | Purpose | Duration |
|---|---|---|---|---|
_ga, _ga_* |
Google Analytics 4 | Analytics | Anonymous usage statistics (pages visited, rough geography, device type). Loads only after you consent to Analytics. | Up to 2 years |
| Google cookies | Google Identity Services | Functional | Loaded only when you open a "Sign in with Google" option; enables Google sign-in. | Per Google |
| PayU cookies | PayU | Necessary (payment) | Present only during the hosted payment checkout on PayU's domain when you pay a booking advance. | Per PayU |
If you reject a category, its cookies are not set and any existing ones in that category are removed on your next visit.
3. Third-party services on the Platform
Beyond cookies, the following third parties are involved when you use the Platform:
- Google Analytics 4 — usage statistics. Consent-gated (off until you allow Analytics). Google's privacy policy
- Google Identity Services — the "Sign in with Google" button. Loads only when you open it. Google's privacy policy
- PayU — our payment gateway. The advance payment is completed on PayU's secure checkout; card and bank details are handled by PayU and never reach Corelatin servers. PayU's privacy policy
- Content delivery networks and fonts — cdnjs, jsDelivr, Google Fonts, Unsplash, and Google-hosted images serve static assets. These providers see a standard web request (your IP and browser) but do not set cookies through our site.
- WhatsApp — links to chat with us open WhatsApp (wa.me). There is no embedded WhatsApp tracker on our pages.
4. How to manage your cookie preferences
4.1 On this site. The first time you visit (or when this policy materially changes), a consent banner offers three equal choices: Accept All, Reject Non-Essential, and Customize. You can reopen it anytime via "Cookie Preferences" in the footer and change your choice — the change takes effect immediately for future page loads.
4.2 In your browser. You can also block or delete cookies through your browser settings (e.g., Chrome, Safari, Firefox, Edge privacy settings). Blocking strictly-necessary cookies may prevent sign-in and booking from working.
4.3 What consent means here. Strictly-necessary cookies run regardless because the site cannot function without them. Functional and analytics features run only after you opt in via the banner. Your choice is logged with a timestamp and policy version so we can demonstrate what was consented to.
5. Legal framework
India (primary). Cookies and similar technologies are governed by the Information Technology Act, 2000 and the IT (SPDI) Rules, 2011, which remain the operative consent and data-handling framework. The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 (notified 13 November 2025) are being phased in; their core consent and data-principal-rights provisions take effect from 13 May 2027. Our consent banner already meets that standard voluntarily — nothing on this site depends on tracking you before you say yes.
International visitors. Many of our Clients are NRIs booking for family in India. If you are visiting from the EU, UK, or another jurisdiction with its own cookie laws (e.g., GDPR, PECR), you may have additional rights under your local law; our banner applies the same opt-in standard regardless of where you visit from.
6. Retention
Cookie durations are listed in Section 2. Your consent record is kept so we can demonstrate compliance if ever required; it is not used for marketing and is not linked to your patient or booking data unless you were signed in when you consented. Data-retention rules for personal information generally are in our Privacy Policy (Section 7) and Terms of Service §22
7. Changes to this policy
If we add a new cookie or tracking technology, or change how existing ones are used, we will update this policy, bump its version, and the consent banner will re-appear for returning visitors so the new inventory is covered by fresh consent — consistent with the amendment mechanism in Terms §20.
8. Contact
Questions about cookies, consent, or your choices can go to our Grievance Officer:
Grievance Officer & Contact
For complaints, data rights requests, refund disputes, and policy grievances under the Consumer Protection (E-Commerce) Rules, 2020 and DPDPA 2023.
Response timeline: acknowledgement within 24 hours; resolution target within 15 days. General support (non-grievance): support@corelatin.in / +91-9870550407