1. What Are Cookies?
Cookies are small text files that are stored on your device (computer, tablet, or mobile phone) when you visit our website. They contain information about your browsing behavior and preferences. Cookies serve various purposes, such as remembering login information, storing preferences, and tracking website usage.
This Cookie Policy explains how Z-Score Data Systems uses cookies and similar tracking technologies. By continuing to use our website, you consent to our use of cookies as described in this policy.
2. Types of Cookies We Use
2.1 Essential/Necessary Cookies
Purpose: These cookies are necessary for the website to function properly. They enable core functionality such as security, authentication, and navigation.
Examples:
- Firebase Authentication tokens for admin login
- Session cookies to maintain user login status
- CSRF protection tokens
- Security and rate-limiting tokens
- Form submission tracking
Duration: Session-based (deleted when you close your browser) or up to 1 year for persistent authentication.
Consent Required: No, these cookies are necessary for website functionality and are exempt from consent requirements.
2.2 Analytical/Performance Cookies
Purpose: These cookies help us understand how users interact with our website. They collect anonymized data about page visits, user behavior, and website performance.
Services Used:
- Google Analytics 4 (GA4): Tracks website usage, page views, user journeys, and conversions. Data is anonymized and aggregated.
- Firebase Analytics: Tracks app-level events and user engagement metrics.
Data Collected: Page URL, referrer, session duration, bounce rate, user device type, browser type, operating system, approximate location (country/city level only).
Duration: Typically 1-2 years from last activity.
Consent Required: Yes, in most jurisdictions. We obtain consent via banner or opt-in.
2.3 Functional Cookies
Purpose: These cookies remember your preferences and settings to enhance user experience without collection of personally identifiable information.
Examples:
- Dark/Light mode preference
- Language preference
- Form input history (auto-fill suggestions)
- UI state (expanded menus, collapsed sections)
Duration: 1 year or until manually cleared.
Consent Required: Recommended, as these enhance user experience.
2.4 Security & Bot Prevention Cookies
Purpose: These cookies protect our website from malicious activity, fraud, and automated attacks.
Services Used:
- Google reCAPTCHA v3: Detects and prevents bot submissions without user interaction. Tracks interaction patterns to assess legitimacy.
- Firebase Security: Detects suspicious activity and enforces rate limiting.
- Custom Rate Limiting: Tracks submission patterns to prevent abuse (3 submissions per IP per 24 hours).
Data Collected: IP address, user-agent, interaction patterns, form submission behavior.
Duration: 24 hours for rate limiting; reCAPTCHA tokens expire in 2 minutes.
Consent Required: No, these are necessary for website security.
2.5 Advertising Cookies (Not Used)
Status: We do not currently use advertising or marketing cookies. We do not track you across websites for advertising purposes. We do not use retargeting pixels or third-party ad networks.
3. Third-Party Cookies
Some cookies are placed by third-party services that we use:
| Service | Purpose | Cookie Type |
|---|---|---|
| Google Analytics | Website analytics and usage tracking | Analytical |
| Google reCAPTCHA v3 | Bot detection and security | Security |
| Firebase | Authentication, hosting, analytics | Essential, Analytical |
| Google Fonts | Font delivery and caching | Functional |
Each third-party service has its own privacy policy. We recommend reviewing Google's Privacy Policy for more details.
4. How We Use Cookie Information
Cookie data is used for the following purposes:
- Authentication: Keeping you logged in to secure areas of the website
- Security: Preventing fraud, abuse, and unauthorized access
- User Experience: Remembering preferences and improving website usability
- Analytics: Understanding how users interact with our content to improve it
- Rate Limiting: Preventing excessive form submissions and API abuse
- Compliance: Meeting legal and regulatory requirements
5. Cookie Consent & Your Choices
Consent Mechanism: We implement a cookie consent banner that appears on first visit (if required by your jurisdiction). You can:
- Accept all cookies (proceed without restrictions)
- Reject non-essential cookies (functional, analytical, advertising)
- Customize your preferences (select specific cookie categories)
- Update preferences anytime via settings or by clearing cookies
Managing Cookies in Your Browser: You can manage cookies through your browser settings:
- Chrome: Settings → Privacy and Security → Cookies and other site data
- Firefox: Preferences → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy → Cookies and website data
- Edge: Settings → Privacy, search, and services → Clear browsing data
Note: Disabling essential cookies may prevent you from accessing certain features of our website, such as login functionality.
6. Cookie Duration & Retention
Cookie retention varies by type:
- Session Cookies: Deleted when you close your browser
- Persistent Cookies: Remain for a specified duration (1 day to 2 years) or until manually deleted
- Analytics Cookies: Typically retained for 12-24 months for historical analysis
You can clear cookies at any time through your browser settings. This will log you out of authenticated sessions and reset your preferences.
7. Do Not Track (DNT) Signals
Some browsers include a "Do Not Track" (DNT) feature that sends a signal to websites you visit. Currently, there is no universal standard for recognizing DNT signals. We respect user privacy preferences but may not explicitly honor DNT headers at this time.
However, you can always disable cookies through your browser settings regardless of DNT status.
8. GDPR & CCPA Compliance
GDPR Compliance (EU Users): If you are located in the European Union, we:
- Obtain explicit consent before placing non-essential cookies
- Provide clear information about cookie purposes and duration
- Allow you to withdraw consent at any time
- Honor your rights to access, correction, deletion, and data portability
CCPA Compliance (California Users): If you are a California resident, you have the right to:
- Know what personal information is collected, used, and shared
- Request deletion of your personal information
- Opt-out of the sale or sharing of your personal information
- Access your personal information in a portable format
9. Cookies & Security
Security Measures: We implement security best practices for cookie handling:
- Secure Flag: Authentication cookies are transmitted only over HTTPS
- HttpOnly Flag: Sensitive cookies are inaccessible to JavaScript, preventing XSS attacks
- SameSite Attribute: Cookies include SameSite=Strict or SameSite=Lax to prevent CSRF attacks
- Encryption: Session data is encrypted in transit and at rest
- Token Expiration: Authentication tokens have short expiration times (1 hour to 7 days)
10. Data Sharing with Third Parties
We do not share cookie data with third parties for their own marketing purposes. Cookie data is shared only with:
- Service providers we use (Google Analytics, Firebase, reCAPTCHA) for the stated purposes
- Law enforcement if legally required
- Third parties to protect our legal rights or prevent fraud
All third-party services are bound by confidentiality agreements and data processing agreements (Data Processing Addendums for GDPR compliance).
11. Children & Cookies
Our website is not intended for children under 13. We do not knowingly set cookies for users under 13. If we learn that a child under 13 has received a cookie, we will take steps to remove it. Parents concerned about their child's cookie use should contact us immediately.
12. International Data Transfers
Cookie data may be processed in the United States through our service providers (Google, Firebase). We ensure that any international transfers comply with GDPR Standard Contractual Clauses and adequacy determinations.
13. Cookie Policy Changes
We may update this Cookie Policy at any time to reflect changes in cookie practices, technology, or legal requirements. Changes become effective upon posting with an updated "Effective Date."
Material changes will be notified via email or a prominent notice on our website. Your continued use constitutes acceptance of updated policies.
14. Contact & Complaints
For questions or concerns about our cookie use:
Email: privacy@zsds.io
Address: Z-Score Data Systems, 5755 North Point Pkwy STE 253, Alpharetta, GA 30022, USA
Response Time: We respond within 30 days of receiving requests.
GDPR Users: If you believe we have violated your privacy rights, you have the right to lodge a complaint with your local Data Protection Authority (DPA).
15. Cookie Consent Withdrawal
You can withdraw your cookie consent at any time by:
- Clearing your browser cookies
- Using your browser's "Do Not Track" feature
- Disabling cookies in your browser settings
- Contacting us at privacy@zsds.io to request cookie deletion
Quick Reference: Cookie Summary
| Category | Required | Duration |
|---|---|---|
| Essential | ✓ Yes | Session to 1 year |
| Analytical | Consent | 1-2 years |
| Functional | Recommended | 1 year |
| Security | ✓ Yes | 24 hours to 2 min |
Last Updated: April 17, 2026 | Version 1.0
© 2026 Z-Score Data Systems. All Rights Reserved.
Related Policies: Privacy Policy | Terms of Service
