Cookie Policy
How OyeChats uses cookies and similar technologies.
Introduction
This Cookie Policy explains how OyeChats uses cookies and similar technologies on our marketing site at oyechats.com, the customer dashboard at app.oyechats.com, and the embeddable chat widget our customers deploy on their own websites.
If you are a customer deciding how to describe the OyeChats widget in your own cookie notice, the section on the widget below is the part you need.
The embeddable chat widget
The OyeChats widget stores a single anonymous session identifier so a conversation stays continuous for the same Visitor. That identifier is not tied to a name, an email address, or an account unless the Visitor submits one through a lead-capture form.
Primary storage is localStorage, under the key chat_session_id_[bot key]. Because localStorage is partitioned per origin, the widget also writes first-party cookies so a conversation survives a move between subdomains of the site it is embedded on:
- oyechats_sid_[bot key]: Mirrors the anonymous session identifier, scoped to the parent domain of the site the widget is embedded on, so a Visitor moving from example.com to help.example.com keeps the same conversation. First-party, SameSite=Lax, Secure on HTTPS. (30 days)
- __oye_apex_probe: A throwaway cookie written and immediately deleted the first time the widget loads on a hostname, to work out which parent domain the browser will accept a cookie for. It holds no data about the Visitor and does not persist. (Deleted immediately)
These are first-party cookies on the customer's own domain, not OyeChats cookies, and they are strictly necessary for the chat function the Visitor initiated. Cross-subdomain continuity is enabled by default, using an automatically detected parent domain; customers can restrict the scope by setting an explicit share domain in the dashboard under Channels. If the browser refuses cookies, the widget falls back to localStorage alone and the chat still works, without continuity across subdomains.
The widget sets no advertising, analytics, or cross-site tracking cookies, and does not track Visitors across websites belonging to different customers. Session storage is namespaced per bot, so a Visitor who chats on two OyeChats-powered sites is not linked between them.
Your choices and controls
You can control cookies in several ways:
- Browser settings: most browsers let you block, delete, or be warned about cookies on a per-site basis.
- Marketing site banner: if a consent banner is shown on oyechats.com in your region, you can accept or decline non-essential categories there.
- In the widget: starting a new chat clears the stored session identifier and expires the continuity cookie.
- Widget scope, for customers: if you operate a site that embeds the OyeChats widget, you can narrow cross-subdomain continuity to a specific domain from your dashboard under Channels.
Blocking strictly-necessary cookies will break sign-in and other core flows on the dashboard.
Do Not Track and Global Privacy Control
Browsers can transmit a Do Not Track (DNT) header or a Global Privacy Control (GPC) signal. We honor GPC where transmitted: when GPC is detected, we treat it as an opt-out of any sale or sharing of personal information for the purposes covered by the CCPA / CPRA. We do not respond to DNT, which has no agreed meaning across browsers.
Changes to this policy
We may update this Cookie Policy from time to time to reflect changes in technology, applicable law, or our practices.
Questions
Have a question about how we use cookies? Write to support@oyechats.com and we will respond within 14 days.