Cookie Policy

How Kafei utilizes cookies, local storage JWTs, and session tokens to deliver secure restaurant operations.

Effective
September 4, 2026
Entity
Antigravity
Jurisdiction
India
Applies to
kafei.in

1. What Are Cookies and Local Storage?

This Cookie Policy explains how Kafei uses cookies, web beacons, local storage objects (localStorage and sessionStorage), and similar browser technologies to ensure our restaurant POS, kitchen display screens, waiter interfaces, and guest ordering portals function reliably and securely.

2. Categories of Cookies & Storage Technologies We Use

2.1 Strictly Necessary Storage (Essential for Service Operation)

These tokens and cookies are strictly required to authenticate users, maintain secure active sessions, and prevent fraudulent requests:

  • kafei_access_token (Local Storage): Encrypted JSON Web Token (JWT) used to authenticate API requests between the web client and NestJS backend.
  • kafei_auth_user (Local Storage): Basic user session metadata (ID, role, assigned branch) used for client-side route guard authorization.
  • CSRF & Security Tokens: Anti-tampering tokens that protect forms and API endpoints from Cross-Site Request Forgery attacks.

2.2 Functional & Preference Cookies

  • kafei-theme: Remembers whether you prefer Dark Mode (Kafei Charcoal & Red theme) or Light Mode across POS and KDS screens.
  • active_branch_id: Remembers your currently selected restaurant branch to prevent repeated branch selection prompts.
  • kds_audio_alert_enabled: Stores kitchen chime audio preferences for incoming order tickets.

2.3 Performance & Telemetry

  • API Latency & Health Heartbeats: Anonymous telemetry measuring network round-trip times and WebSocket connection stability for live kitchen displays.
  • Error Diagnostics: Client-side crash logs and rendering error captures to assist our engineering team in resolving software defects.

2.4 Third-Party Integrations

  • Google OAuth: When logging in via Google Sign-In, Google may set session cookies on its domains to verify your Google identity securely.
  • Payment Gateways (Razorpay / Stripe): Secure PCI-compliant iframe cookies utilized to authenticate cardholder verification.

3. No Third-Party Behavioral Ad Tracking

Kafei does NOT deploy third-party behavioral advertising cookies, retargeting pixels, or ad exchange tracking scripts on our platform.

4. Managing and Disabling Cookies

You can customize your cookie preferences directly in Kafei at any time or configure your web browser (Chrome, Firefox, Safari, Edge) to reject or delete cookies. However, because authentication tokens in localStorage are essential to verify your identity, disabling local storage will prevent you from logging into your Kafei workspace and operating the POS or KDS.

Interactive Cookie Controller

Adjust telemetry and UI preferences without affecting essential authentication.

Questions about this policy?

Write to us for data subject requests, deletion requests, security reports, or compliance reviews. We respond within 5 business days.

Antigravity, Kolkata, West Bengal, India