Version 2026-08-16-v2
Cookie and Local Storage Notice
Last updated: 16 August 2026
This Notice explains how AARK NETWORK PTE. LTD. uses cookies, browser storage, desktop application storage, mobile device storage, and similar technologies for HisaBooks.
1. What these technologies are
A cookie is a small value stored in a browser by a website. Browser local storage is a browser-managed store for preferences or app state. Desktop and mobile apps also use operating-system protected storage or application storage to keep sessions, saved accounts, preferences, and queued actions.
Some storage is strictly necessary. Without it, login, tenant separation, CSRF protection, checkout, device security, or app preferences may not work.
2. Web cookies and browser storage
| Storage | Purpose | Type | Typical duration |
|---|---|---|---|
Session cookie, typically PHPSESSID | Keeps a signed-in company or admin session active, separates tenants, and supports secure server-side session checks. | Strictly necessary | Session or configured login period; invalidated on logout where supported. |
| CSRF and checkout session values | Protect signup, purchase, billing, and workspace forms from forged requests and duplicate submissions. | Strictly necessary | Session or short operational period. |
Free signup anti-abuse cookie, naas_free_signup_device | Helps limit repeated automated Free workspace creation. The server stores a one-way hash of the device identifier. | Security and abuse prevention | Up to one year unless cleared earlier. |
hisabooks_pricing_region | Remembers a non-sensitive pricing-region display choice or location-detection result so the next public pricing render can show the expected currency. It is written only after functional-cookie consent. | Functional | Up to 30 days unless cleared earlier. |
Theme and UI preferences such as naas.portal.theme and sidebar preferences | Remembers light/dark/system theme and interface preferences on the same device. | Preference | Until changed or cleared. |
| Document and app preferences | May remember document panel preferences and authorised app continuity settings on the current device. | Functional | Until refreshed, synced, cleared, logout/removal, or browser storage deletion. |
3. Desktop and mobile app storage
| Platform | Storage | Purpose |
|---|---|---|
| Desktop app | Operating-system protected storage where available, plus local application data. | Stores the active session token, window state, and safe local preferences for the Electron client. |
| HisaBooks Business mobile app | Secure device storage and application storage. | Stores saved account profiles, auth tokens, biometric-unlock preference, theme choice, offline action queue, and document-viewer preference. |
| HisaBooks Team mobile app | Secure device storage and application storage. | Stores the same account, session, device preference, notification, and offline queue foundation used by the team experience. |
| Mobile push tokens | Device push token stored by HisaBooks and notification providers after permission. | Routes operational notifications to the authorised device until logout, account removal, permission removal, or token expiry. |
Offline mobile queues can contain business information entered into a pending form. Sign out, remove saved accounts, clear app storage, or uninstall the app to remove local device data, subject to operating-system behavior. Removing local app data does not delete the server workspace or cancel a subscription.
4. Third-party storage and services
When a user is redirected to Stripe Checkout or Stripe billing pages, Stripe may use its own cookies and storage to process payments, prevent fraud, and manage billing. Mobile push delivery may involve Expo and Android platform push services. App stores and operating systems may collect their own diagnostic, install, or device information under their own policies.
HisaBooks does not currently use Customer Data for third-party behavioural advertising. If non-essential analytics, advertising, chat, session replay, crash SDK, or attribution tools are introduced, this Notice and the Privacy Policy must be updated and consent controls must be added where required before those tools are enabled.
5. Your choices
- On public HisaBooks pages, use the Cookie preferences link in the footer to choose necessary-only storage or allow functional storage. Both choices are equally available, and you can change your preference later.
- You can block or delete browser cookies through browser settings, but the web application may stop working correctly.
- You can change notification, camera, photo, file, and biometric permissions through device settings.
- You can remove saved app accounts from the app and sign out of the desktop or web app.
- Company Administrators should review user access and revoke devices when a user leaves the company.
- Requests about account or workspace data can be submitted through the Data and Account Requests page.
6. Changes and contact
We may update this Notice when storage behavior, providers, app permissions, or legal requirements change. Material changes should receive a new policy version.
Contact support@hisabooks.com with cookie, local storage, or privacy questions.