Cookie & Tracking Policy
Policy 13 of 19 | Version 1.0 | Operator: Bani Global Industries LLP | Effective Date: 05/10/2026
Important Notice
This Cookie & Tracking Policy explains how BANI GLOBAL INDUSTRIES LLP ("BANI GLOBAL INDUSTRIES LLP", "StampMitra", "we", "us", or "our") uses Cookies and similar technologies in connection with the StampMitra websites, Developer Platform, Partner Platform, documentation interfaces, authentication interfaces, customer-facing web applications, and other digital interfaces where this Policy is presented.
This Policy is intended to be read together with the StampMitra Developer Privacy Policy, Developer Terms of Service, API Security Policy, API Acceptable Use Policy, and other applicable policies and agreements.
This Policy does not create any right to use a particular Cookie, tracking technology, analytics provider, advertising technology, or third-party technology.
The technologies actually deployed may change from time to time depending on the functionality, security requirements, infrastructure, regulatory requirements, and business configuration of the relevant StampMitra service.
Where a technology is described as potentially available "where deployed", this means that the relevant technology may be introduced, removed, substituted, or disabled without requiring this Policy to enumerate every technical implementation detail.
1. Purpose
1.1 This Policy explains the purposes for which StampMitra may use Cookies and similar technologies.
1.2 The purpose of this Policy is to provide transparency regarding authentication, session management, security, preferences, functionality, analytics, performance measurement, fraud prevention, service operation, and other permitted uses.
1.3 This Policy also explains the choices available to users regarding non-essential Cookies and similar technologies, subject to applicable law.
2. Scope
2.1 This Policy applies to relevant web-based interfaces operated or made available by StampMitra where Cookies or similar technologies are deployed.
2.2 Such interfaces may include, without limitation:
- (a) stampmitra.in;
- (b) developer.stampmitra.in;
- (c) partner.stampmitra.in;
- (d) relevant documentation or support interfaces;
- (e) authentication and account-management interfaces; and
- (f) other StampMitra web properties that expressly reference this Policy.
2.3 The API itself is primarily a server-to-server service. API requests may generate technical logs, identifiers, security telemetry, request metadata, and other operational records even where browser Cookies are not involved.
2.4 This Policy therefore applies to browser-based tracking technologies and similar technologies, but does not imply that every API request uses Cookies.
3. Contractual and Legal Status
3.1 This Policy forms part of the StampMitra privacy and platform governance framework.
3.2 Where incorporated into an agreement, this Policy shall be interpreted together with the applicable Developer Terms, Privacy Policy, DPA, Security Policy, Acceptable Use Policy, and other applicable contractual documents.
3.3 Nothing in this Policy limits any mandatory right or obligation arising under applicable law.
3.4 Where applicable law requires consent for a particular technology or purpose, StampMitra will seek and manage such consent in accordance with the requirements applicable to the relevant processing activity.
3.5 References to consent, legal basis, Data Principal rights, or similar concepts shall be interpreted to the extent applicable and in force under Indian law and any other law applicable to the relevant processing activity.
4. Definitions
4.1 “Cookie” means a small data file or similar browser mechanism stored on a user's device by a website or web application.
4.2 “First-Party Cookie” means a Cookie placed or controlled by the website or service being visited.
4.3 “Third-Party Cookie” means a Cookie or similar technology controlled by a third party in connection with content, functionality, analytics, security, or another permitted service.
4.4 “Essential Cookie” means a Cookie necessary for core functionality, authentication, session management, security, fraud prevention, load management, or other functionality that cannot reasonably be provided without the relevant technology.
4.5 “Functional Cookie” means a Cookie used to remember preferences or settings that improve functionality or user experience.
4.6 “Analytics Technology” means technology used to understand service usage, performance, traffic patterns, errors, or interaction with a digital interface.
4.7 “Security Technology” means technology used to detect, prevent, investigate, or mitigate fraud, abuse, unauthorized access, attacks, or other security risks.
4.8 “Preference Technology” means technology used to remember user-selected settings or choices.
4.9 “Marketing Technology” means technology used for advertising, campaign measurement, audience measurement, or marketing-related purposes, where such technology is deployed.
4.10 “Tracking Technology” means Cookies, pixels, tags, scripts, SDKs, local storage, device identifiers, browser identifiers, and similar technologies capable of storing, accessing, transmitting, or recognizing information associated with a browser, device, session, or interaction.
4.11 “Pixel” or “Tracking Pixel” means a small technical element capable of communicating information when a webpage, email, or other digital content is loaded or interacted with.
4.12 “Local Storage” means browser-based storage mechanisms capable of retaining information on a device.
4.13 “Session” means a period during which a user or system interacts with a StampMitra application or service.
5. Types of Technologies Used
5.1 StampMitra may use one or more of the following categories:
- (a) Essential and strictly necessary technologies;
- (b) Authentication and session technologies;
- (c) Security and fraud-prevention technologies;
- (d) Preference and functional technologies;
- (e) Analytics and performance technologies;
- (f) Error monitoring and diagnostic technologies;
- (g) Marketing or advertising technologies, where deployed;
- (h) Local Storage and comparable browser technologies;
- (i) device or browser identifiers; and
- (j) similar technologies necessary for service operation.
5.2 Not every category will necessarily be active on every StampMitra website, application, environment, or geographic location.
5.3 The actual technologies deployed may depend on the specific service, account type, environment, browser, device, consent configuration, and applicable law.
6. Essential Technologies
6.1 Essential technologies may be required to:
- (a) authenticate users;
- (b) maintain secure sessions;
- (c) maintain login state;
- (d) protect account access;
- (e) maintain application functionality;
- (f) prevent fraudulent activity;
- (g) protect APIs and web applications;
- (h) maintain security controls;
- (i) manage traffic;
- (j) preserve selected security settings;
- (k) detect abuse; and
- (l) provide requested services.
6.2 Essential technologies may operate without a separate opt-in where permitted by applicable law because disabling them may prevent the requested service from functioning correctly.
6.3 StampMitra does not use the classification "essential" merely to avoid consent obligations where applicable law requires consent.
7. Authentication and Login
7.1 Authentication technologies may be used to identify an authenticated session.
7.2 Such technologies may support:
- (a) Developer Portal login;
- (b) Partner Portal login;
- (c) Customer account access;
- (d) session continuity;
- (e) account recovery;
- (f) authorization state;
- (g) access-control enforcement; and
- (h) prevention of unauthorized session reuse.
7.3 Authentication technologies may be associated with session identifiers, account identifiers, security information, or other technical information.
7.4 Authentication information shall not be treated as authorization to disclose passwords, API keys, OTPs, access tokens, or other confidential credentials.
8. Session Management
8.1 StampMitra may use session technologies to maintain continuity during a user's interaction with a web application.
8.2 Session technologies may expire when a session ends or after an appropriate period of inactivity or security-relevant events.
8.3 StampMitra may invalidate session identifiers following security events, credential changes, account recovery, logout, administrative action, or other security circumstances.
8.4 Users must not attempt to manipulate, reuse, forge, or bypass session identifiers.
9. Security and Fraud Prevention
9.1 StampMitra may use Cookies and similar technologies to identify abnormal activity, suspicious sessions, automated abuse, credential attacks, fraudulent activity, account takeover attempts, or other security threats.
9.2 Security technologies may collect technical information such as:
- (a) IP address;
- (b) browser characteristics;
- (c) device characteristics;
- (d) session information;
- (e) timestamps;
- (f) request patterns;
- (g) authentication events;
- (h) security events; and
- (i) other information reasonably necessary for security.
9.3 Security technologies may remain active even where a user declines optional analytics or marketing technologies.
9.4 Security controls may not be disabled merely because a user has declined non-essential Cookies.
10. Preference and Functional Technologies
10.1 Where deployed, functional technologies may remember settings selected by a user.
10.2 Such settings may include:
- (a) language preference;
- (b) interface preference;
- (c) documentation preference;
- (d) region or jurisdiction preference;
- (e) consent preference; and
- (f) other user-selected settings.
10.3 Disabling functional technologies may require users to re-enter preferences.
11. Analytics and Performance
11.1 StampMitra may use analytics technologies to understand how users interact with its digital interfaces.
11.2 Analytics may help StampMitra understand:
- (a) page performance;
- (b) application performance;
- (c) feature usage;
- (d) navigation patterns;
- (e) errors;
- (f) service reliability;
- (g) traffic patterns;
- (h) documentation usage;
- (i) onboarding completion; and
- (j) general product performance.
11.3 Analytics information may be aggregated, pseudonymized, or otherwise processed in a manner intended to reduce unnecessary identification where reasonably practicable.
11.4 StampMitra will not represent analytics information as anonymous merely because direct identifiers are absent where the information may reasonably be linked with other information.
12. Error Monitoring and Diagnostics
12.1 StampMitra may use technical identifiers and similar technologies to diagnose application failures, errors, latency, broken functionality, and security events.
12.2 Diagnostic information may include browser, device, session, request, timestamp, error, and technical environment information.
12.3 Diagnostic information may be retained for a reasonable period consistent with security, troubleshooting, service improvement, and legal requirements.
13. Marketing and Advertising Technologies
13.1 StampMitra may deploy marketing or advertising technologies on selected interfaces or campaigns where such technologies are used.
13.2 Marketing technologies may support:
- (a) campaign measurement;
- (b) conversion measurement;
- (c) advertising performance;
- (d) audience measurement; or
- (e) other lawful marketing functions.
13.3 StampMitra will not treat the mere possibility of future deployment as confirmation that a particular advertising technology is currently active.
13.4 Where applicable law requires consent before deploying a particular marketing technology, StampMitra will obtain the required consent before the relevant processing occurs.
13.5 StampMitra may disable, modify, or discontinue marketing technologies without creating any entitlement to compensation.
14. Email and Communication Technologies
14.1 Certain communications may contain technical mechanisms capable of recording whether a communication was delivered, opened, interacted with, or otherwise processed.
14.2 Such mechanisms may be used where lawful for:
- (a) service communication;
- (b) security communication;
- (c) transactional communication;
- (d) campaign measurement;
- (e) operational analysis; or
- (f) abuse prevention.
14.3 Not every email or communication will contain such technology.
14.4 Transactional and security communications may continue irrespective of marketing preferences where necessary to operate the account or service.
15. Local Storage and Similar Technologies
15.1 StampMitra may use Local Storage or similar browser storage where reasonably required for application functionality.
15.2 Such technologies may store information relating to:
- (a) application settings;
- (b) temporary state;
- (c) user preferences;
- (d) security state;
- (e) documentation state; or
- (f) other application functionality.
15.3 Local Storage may remain on a device after a browser session ends, depending on the technology and browser configuration.
15.4 Users may clear Local Storage through their browser or device settings, subject to the consequences described in this Policy.
16. Device and Browser Identifiers
16.1 StampMitra may process technical identifiers associated with a browser, device, application, session, or network connection.
16.2 Such identifiers may be used for security, fraud prevention, service operation, analytics, debugging, or other lawful purposes.
16.3 StampMitra will seek to avoid unnecessary collection of device-level information unrelated to the relevant service purpose.
17. IP Addresses and Network Information
17.1 IP addresses and network information may be processed as technical information.
17.2 Such information may be used for:
- (a) security;
- (b) fraud prevention;
- (c) rate limiting;
- (d) geographic or jurisdictional controls where required;
- (e) troubleshooting;
- (f) access control;
- (g) abuse detection;
- (h) audit logs; and
- (i) legal or regulatory compliance.
17.3 An IP address may constitute personal information under applicable law depending on the circumstances and shall be handled accordingly.
18. First-Party Technologies
18.1 StampMitra may deploy first-party Cookies and similar technologies directly through its own web applications.
18.2 First-party technologies may support authentication, session management, preferences, security, analytics, and other legitimate functions.
18.3 First-party technologies remain subject to applicable privacy and security requirements.
19. Third-Party Technologies
19.1 StampMitra may use third-party technologies where reasonably necessary for functionality, analytics, security, communications, payments, support, fraud prevention, or other legitimate purposes.
19.2 Third-party technologies may be subject to the privacy and cookie policies of the relevant third party.
19.3 StampMitra does not represent that every third-party technology will remain unchanged.
19.4 StampMitra may replace a third-party technology with another provider or technical implementation without changing the fundamental purpose of the relevant processing.
19.5 No particular third-party provider is guaranteed under this Policy.
20. Third-Party Content and Embedded Components
20.1 Web interfaces may contain embedded components, documentation resources, security controls, payment interfaces, communication tools, or other third-party functionality.
20.2 Such components may independently use technical identifiers or similar technologies.
20.3 Where legally required, StampMitra may provide or facilitate appropriate notice or consent mechanisms.
21. Consent Management
21.1 Where required, StampMitra may provide a Cookie or privacy preference interface.
21.2 The consent mechanism may allow users to:
- (a) accept optional technologies;
- (b) reject optional technologies;
- (c) manage categories;
- (d) change preferences; or
- (e) withdraw previously provided consent.
21.3 Consent choices may themselves require storage of a preference identifier.
21.4 A consent-management mechanism may not necessarily control technologies that are strictly necessary for security or core service functionality.
22. Withdrawal of Consent
22.1 Where consent is the applicable legal basis, a user may withdraw consent through the available consent-management mechanism or other appropriate method.
22.2 Withdrawal of consent does not affect processing lawfully carried out before withdrawal.
22.3 Withdrawal may not be available for technologies that are strictly necessary for the operation or security of the requested service.
22.4 Withdrawal may affect functionality where optional technologies support features selected by the user.
23. Browser Controls
23.1 Most modern browsers allow users to control Cookies.
23.2 Users may generally configure browsers to:
- (a) block Cookies;
- (b) delete Cookies;
- (c) restrict third-party Cookies;
- (d) receive warnings before storage; or
- (e) clear site data.
23.3 Browser controls may differ by browser, operating system, and device.
23.4 Blocking all Cookies may cause certain StampMitra services to function incorrectly or become unavailable.
23.5 Security and authentication functions may be materially affected when essential storage is disabled.
24. Cookie Duration
24.1 Cookies may be either session-based or persistent.
24.2 Session Cookies may ordinarily expire when the relevant session ends or when the browser removes the associated session state.
24.3 Persistent technologies may remain for a period determined by the relevant function, security requirement, legal requirement, or configuration.
24.4 StampMitra may modify the duration of a technology where reasonably necessary for security, functionality, performance, or compliance.
24.5 This Policy does not establish a universal retention period for every Cookie or identifier.
25. Data Associated with Cookies
25.1 Depending on the technology, associated information may include:
- (a) unique identifiers;
- (b) session identifiers;
- (c) account identifiers;
- (d) browser information;
- (e) device information;
- (f) timestamps;
- (g) preferences;
- (h) interaction information;
- (i) security signals;
- (j) technical request information; and
- (k) other information reasonably necessary for the stated purpose.
25.2 StampMitra seeks to limit the information associated with a Cookie to what is reasonably necessary for its intended purpose.
26. API Traffic and Cookies
26.1 Server-to-server API requests generally do not require browser Cookies.
26.2 API authentication ordinarily relies on API credentials, authorization mechanisms, request signing, tokens, or other mechanisms specified in the applicable API documentation.
26.3 API requests may nevertheless generate operational records, including technical identifiers, timestamps, IP addresses, request metadata, response metadata, security events, and audit information.
26.4 API logs are governed by the applicable Privacy Policy, Security Policy, DPA, Terms, and retention requirements rather than being treated as browser Cookie data merely because they contain technical identifiers.
27. Developer Portal Tracking
27.1 The Developer Portal may use technologies necessary to provide:
- (a) account authentication;
- (b) workspace access;
- (c) project management;
- (d) API credential management;
- (e) security controls;
- (f) consent preferences;
- (g) documentation functionality;
- (h) performance monitoring; and
- (i) other Developer Platform functionality.
27.2 Developer Portal technologies may be associated with account and workspace information where necessary to provide the requested functionality.
28. Partner and Customer Interfaces
28.1 Similar technologies may be deployed on StampMitra customer and partner interfaces.
28.2 The categories and purposes may vary according to the specific service.
28.3 A Cookie configuration applicable to the Developer Portal should not be assumed to apply identically to customer or partner applications.
29. Sandbox Environment
29.1 Sandbox interfaces may use Cookies and similar technologies for authentication, session management, security, testing, diagnostics, and functionality.
29.2 Sandbox environments may use different technical configurations from Production environments.
29.3 Developers must not use Sandbox to circumvent Production security, monitoring, rate limits, or other controls.
30. Production Environment
30.1 Production interfaces may use additional security and monitoring technologies based on risk and operational requirements.
30.2 Production security technologies may process technical information necessary to protect accounts, APIs, transactions, and services.
30.3 Production processing remains subject to applicable privacy and data protection obligations.
31. Tracking and Security Monitoring
31.1 Security monitoring is not equivalent to behavioral advertising.
31.2 StampMitra may monitor technical activity to protect its infrastructure, developers, users, transactions, documents, APIs, and connected systems.
31.3 Security monitoring may include automated detection, anomaly detection, rate-limit monitoring, abuse detection, fraud signals, and related technologies.
31.4 Security monitoring may continue even if optional analytics or marketing technologies are rejected.
32. Fraud and Abuse Prevention
32.1 Tracking technologies may be used to detect:
- (a) credential abuse;
- (b) automated attacks;
- (c) account takeover attempts;
- (d) fraudulent transactions;
- (e) excessive automation;
- (f) suspicious sessions;
- (g) API abuse;
- (h) identity fraud;
- (i) document fraud; and
- (j) other prohibited or unlawful activity.
32.2 StampMitra may combine technical signals with other security information where legally permitted and reasonably necessary.
33. Data Minimization
33.1 StampMitra seeks to collect and process only information reasonably necessary for the relevant purpose.
33.2 StampMitra does not intend to use Cookies as a general-purpose mechanism for collecting unrelated personal information.
33.3 Where a technology is no longer required, StampMitra may disable, delete, replace, or modify it.
34. Personal Data
34.1 Cookie identifiers and related information may constitute personal data depending on applicable law and the ability to associate such information with an identifiable person.
34.2 Where applicable, such information shall be handled in accordance with the StampMitra Privacy Policy and applicable data protection law.
34.3 Users should not assume that information is anonymous merely because it is stored in a Cookie or technical identifier.
35. Children and Minors
35.1 StampMitra services are not intentionally designed to encourage children to create Developer accounts or access restricted developer functionality.
35.2 Where applicable law imposes additional requirements concerning children's personal data, StampMitra will apply those requirements to the extent applicable and in force.
35.3 Developers must not knowingly use StampMitra APIs to unlawfully track, profile, identify, or monitor children.
36. International Processing
36.1 Certain Cookie-related information or technical data may be processed through infrastructure or service providers located outside the user's jurisdiction.
36.2 Where cross-border processing is subject to legal requirements, StampMitra will undertake such processing only to the extent permitted by applicable law.
36.3 Developers remain responsible for informing their End Users where their own applications implement additional tracking technologies.
37. Developer Responsibility
37.1 A Developer integrating StampMitra APIs into its own application is responsible for its own Cookies and Tracking Technologies.
37.2 Developers must independently determine whether their applications require:
- (a) Cookie notices;
- (b) consent mechanisms;
- (c) privacy notices;
- (d) opt-out mechanisms;
- (e) data protection disclosures; or
- (f) other regulatory controls.
37.3 StampMitra's Cookie Policy does not automatically satisfy a Developer's own legal obligations.
37.4 Developers must not represent StampMitra's Cookie Policy as their own privacy or cookie notice.
38. SDKs, Client Applications and Mobile Applications
38.1 StampMitra SDKs, APIs, libraries, mobile applications, or client-side components may use technical identifiers or local storage where required.
38.2 Such technologies may be governed by additional documentation or privacy notices where applicable.
38.3 Developers are responsible for technologies independently introduced into their own applications.
39. No Unauthorized Tracking
39.1 Developers must not use StampMitra APIs or services to create unauthorized tracking systems.
39.2 Developers must not use StampMitra services to secretly identify, profile, monitor, or track individuals without an appropriate lawful basis or required authorization.
39.3 The API Acceptable Use Policy applies to any tracking-related use of StampMitra services.
40. Data Sharing
40.1 StampMitra may share or permit access to technical information with service providers where reasonably necessary to provide:
- (a) hosting;
- (b) security;
- (c) analytics;
- (d) communications;
- (e) payment functionality;
- (f) support;
- (g) fraud prevention;
- (h) infrastructure;
- (i) monitoring; or
- (j) other legitimate services.
40.2 Such service providers may process information on StampMitra's behalf or independently depending on the nature of the service and applicable arrangement.
40.3 Confidential technical architecture and provider relationships may not be publicly disclosed merely because a technology is involved in a Cookie or Tracking Technology.
41. Third-Party Provider Changes
41.1 StampMitra may replace, suspend, remove, or introduce technical providers where reasonably necessary.
41.2 A provider change does not necessarily require prior individual notice unless applicable law requires otherwise.
41.3 Where a material change affects a consent-controlled processing activity, StampMitra may update its consent mechanism or Policy as appropriate.
42. Security of Cookie Information
42.1 StampMitra applies reasonable technical and organizational measures appropriate to the nature of the information and associated risks.
42.2 Authentication and security identifiers may be protected using appropriate application and infrastructure controls.
42.3 Users must protect their own devices, browsers, passwords, API credentials, sessions, and authentication mechanisms.
42.4 StampMitra cannot guarantee the security of a device or browser controlled by a user.
43. Secure Cookie Configuration
43.1 Where technically appropriate, StampMitra may apply browser security attributes and other controls designed to reduce unauthorized access to Cookies or session information.
43.2 The exact technical configuration may vary by application, browser, security requirement, and deployment environment.
43.3 This Policy does not constitute a guarantee of any particular browser security attribute or implementation.
44. Cookie Deletion
44.1 StampMitra may delete or invalidate Cookies where they are no longer required.
44.2 Cookies may also become invalid following logout, password reset, credential rotation, account recovery, security action, or application changes.
44.3 Browser deletion of Cookies does not necessarily delete server-side records associated with previous sessions or transactions.
45. Retention
45.1 Cookie-related information may be retained for different periods depending on its purpose.
45.2 Security and audit records may require longer retention than ordinary session information.
45.3 Retention shall be governed by the applicable StampMitra retention framework, legal obligations, security requirements, and legitimate business requirements.
45.4 This Policy does not establish a single universal retention period.
46. Legal and Regulatory Compliance
46.1 StampMitra may process Cookie and Tracking Technology information where reasonably necessary to comply with applicable:
- (a) laws;
- (b) regulations;
- (c) court orders;
- (d) governmental directions;
- (e) regulatory requirements;
- (f) security obligations; or
- (g) legal process.
46.2 Processing for legal compliance may continue notwithstanding an optional analytics or marketing preference where permitted by law.
47. Government and Law Enforcement Requests
47.1 StampMitra may disclose relevant technical information where required or permitted by applicable law.
47.2 StampMitra may preserve relevant technical information where reasonably necessary to comply with a lawful request or protect its rights, users, or systems.
48. Changes to Tracking Technologies
48.1 StampMitra may change its Cookie and Tracking Technology configuration from time to time.
48.2 Changes may result from:
- (a) new functionality;
- (b) security improvements;
- (c) infrastructure changes;
- (d) analytics requirements;
- (e) regulatory requirements;
- (f) provider changes;
- (g) performance optimization; or
- (h) business requirements.
48.3 Material changes will be addressed through appropriate updates to this Policy or applicable consent mechanisms where required.
49. No Guarantee of Particular Technology
49.1 StampMitra does not guarantee that a specific Cookie, SDK, pixel, analytics system, security technology, or tracking mechanism will remain available.
49.2 Technical implementation may change while maintaining substantially the same service purpose.
50. No Sale of Personal Data
50.1 StampMitra does not intend to sell personal data merely through its use of Cookies or Tracking Technologies.
50.2 Nothing in this clause limits lawful disclosures, processing by service providers, security processing, regulatory disclosures, or other processing permitted under applicable law.
50.3 The legal meaning of "sale", "sharing", "processing", or equivalent terms shall be determined under the law applicable to the relevant processing activity.
51. Advertising Preferences
51.1 Where advertising technologies are deployed, users may be provided with applicable controls through the relevant consent mechanism or browser controls.
51.2 Disabling advertising technologies does not necessarily stop all service communications.
51.3 Transactional, security, legal, and operational communications may continue irrespective of marketing preferences where necessary.
52. Do-Not-Track and Similar Signals
52.1 Browser or device privacy signals may vary in technical meaning and legal status.
52.2 StampMitra may recognize or respond to applicable privacy signals where required or technically supported.
52.3 The absence of support for a particular browser signal does not remove any statutory privacy right that otherwise applies.
53. User Responsibility for Devices
53.1 Users are responsible for maintaining reasonable security of their devices and browsers.
53.2 Users should:
- (a) maintain updated browsers;
- (b) use appropriate device security;
- (c) protect account credentials;
- (d) avoid untrusted extensions;
- (e) log out from shared devices where appropriate; and
- (f) review browser storage and privacy settings periodically.
54. Shared and Public Devices
54.1 Users accessing StampMitra from shared or public devices should take appropriate precautions.
54.2 Users should not save authentication information or persistent sessions on devices they do not control.
54.3 StampMitra is not responsible for unauthorized access resulting from a user's failure to secure a shared device.
55. Account Security
55.1 Cookie and session security does not replace the user's responsibility to protect credentials.
55.2 Users must immediately report suspected account compromise in accordance with the applicable StampMitra security procedures.
55.3 StampMitra may invalidate sessions or security identifiers where compromise is suspected.
56. Relationship with Privacy Policy
56.1 This Policy explains the technology-specific aspects of Cookies and Tracking Technologies.
56.2 The StampMitra Privacy Policy governs the broader processing of personal information and personal data.
56.3 Where the Privacy Policy imposes a broader protection than this Policy, the broader protection shall apply to the extent legally and technically applicable.
57. Relationship with DPA
57.1 Where StampMitra processes Developer Data as a processor or equivalent role, the applicable Data Processing Addendum governs the relevant processing relationship.
57.2 This Cookie Policy does not independently alter the role allocation established under the applicable DPA.
58. Relationship with Developer Terms
58.1 Developers remain bound by the Developer Terms of Service.
58.2 Nothing in this Policy grants permission to use StampMitra technology for tracking, surveillance, profiling, or data collection prohibited by the Developer Terms or Acceptable Use Policy.
59. Security Incidents
59.1 If StampMitra identifies a security incident involving Cookie, authentication, session, or tracking information, it may take immediate protective measures.
59.2 Such measures may include:
- (a) invalidating sessions;
- (b) rotating identifiers;
- (c) disabling functionality;
- (d) restricting access;
- (e) increasing monitoring;
- (f) requiring re-authentication; or
- (g) other reasonable security measures.
59.3 Incident handling is governed by the applicable StampMitra security and incident-response framework.
60. Abuse of Tracking Technologies
60.1 Users must not exploit StampMitra Cookies, sessions, identifiers, tracking mechanisms, APIs, or application behavior to bypass security or privacy controls.
60.2 Prohibited conduct includes:
- (a) session hijacking;
- (b) identifier manipulation;
- (c) credential theft;
- (d) unauthorized tracking;
- (e) security-control bypass;
- (f) token extraction;
- (g) session replay;
- (h) unauthorized enumeration; and
- (i) other abusive conduct.
61. Security Research
61.1 Security testing involving Cookies, sessions, authentication, or Tracking Technologies must comply with the StampMitra Security Vulnerability Disclosure Policy.
61.2 Researchers must not access or extract personal information belonging to other users.
61.3 Researchers must not perform destructive testing, denial-of-service testing, credential attacks, or unauthorized production exploitation.
62. Automated Systems and AI
62.1 Automated agents, bots, AI systems, crawlers, scripts, or other automated systems must not use StampMitra interfaces to circumvent Cookie, session, authentication, consent, rate-limit, security, or access controls.
62.2 Developers remain responsible for automated applications that interact with StampMitra services.
63. Documents and Sensitive Services
63.1 StampMitra may operate services involving legal documents, identity information, e-Stamp services, e-Sign services, verification information, transaction information, or other potentially sensitive data.
63.2 Cookie or Tracking Technology shall not be interpreted as authorization to collect sensitive information unnecessarily.
63.3 Developers must implement additional safeguards where their applications process sensitive or regulated information.
64. No Professional or Legal Advice
64.1 This Policy is an operational and privacy transparency document.
64.2 It does not constitute legal advice to a Developer or End User.
64.3 Developers remain responsible for obtaining independent legal advice where required.
65. Availability of Policy
65.1 StampMitra intends to maintain the current version of this Policy on an appropriate public-facing interface.
65.2 The effective date and last updated date identify the version applicable to the relevant period, subject to applicable law.
66. Policy Updates
66.1 StampMitra may update this Policy from time to time.
66.2 Updates may reflect:
- (a) legal changes;
- (b) regulatory changes;
- (c) technical changes;
- (d) new functionality;
- (e) security improvements;
- (f) changes to Tracking Technologies; or
- (g) operational requirements.
66.3 The updated version shall identify its effective or last updated date.
66.4 Where applicable law requires specific notice or consent for a material change, StampMitra will provide the legally required mechanism.
67. Interpretation
67.1 Headings are provided for convenience and do not limit interpretation.
67.2 “Including” means including without limitation.
67.3 References to applicable law include amendments, replacements, rules, regulations, notifications, directions, and legally applicable subordinate instruments.
67.4 If a provision is invalid or unenforceable under applicable law, the remaining provisions shall continue to operate to the extent legally permitted.
68. No Waiver
68.1 Failure to enforce a provision of this Policy does not constitute a waiver of that provision.
68.2 Any waiver must be legally valid and appropriately authorized.
69. Governing Framework
69.1 This Policy shall be interpreted consistently with the applicable StampMitra contractual framework and applicable laws of India.
69.2 Nothing in this Policy excludes mandatory statutory rights or remedies.
70. Contact and Grievance
70.1 Questions, concerns, privacy-related requests, or grievances concerning this Policy may be directed to:
Legal Team
BANI GLOBAL INDUSTRIES LLP
Email: [email protected]
70.2 Communications should include sufficient information to allow StampMitra to understand and appropriately address the issue.
70.3 Where a request concerns a Developer account, the requester may be required to complete reasonable verification before account-specific information is disclosed.
71. Relationship with Other Policies
71.1 This Policy forms part of the StampMitra Developer Platform policy framework.
71.2 In the event of an inconsistency:
- (a) mandatory applicable law shall prevail;
- (b) the applicable signed commercial agreement shall prevail over a general platform policy to the extent of an express conflict;
- (c) the DPA shall govern the specific processor-processing relationship where applicable; and
- (d) this Policy shall govern Cookie and Tracking Technology matters to the extent not otherwise expressly governed.
72. Confidentiality of Technical Architecture
72.1 Nothing in this Policy requires StampMitra to disclose confidential security architecture, internal infrastructure, security controls, commercial arrangements, or confidential third-party relationships.
72.2 StampMitra may provide sufficient transparency to satisfy applicable privacy and legal requirements without publishing sensitive security information.
73. Limitation of Technical Disclosure
73.1 Cookie names, identifiers, technical attributes, domains, internal service mappings, retention values, security configurations, and provider details may change.
73.2 StampMitra may avoid publishing technical details that could materially increase security risk or facilitate circumvention.
73.3 Nothing in this clause limits any disclosure required by applicable law.
74. Business Continuity
74.1 StampMitra may modify or temporarily disable Tracking Technologies during security events, maintenance, infrastructure migrations, incidents, or business-continuity activities.
74.2 Such changes may affect certain optional functionality without creating an entitlement to compensation.
75. Service Availability
75.1 Cookie functionality may depend on browser configuration, network connectivity, device configuration, third-party services, security controls, and other external factors.
75.2 StampMitra does not guarantee that every Cookie or Tracking Technology will operate on every device, browser, network, or configuration.
75.3 Service availability is governed separately by the applicable API SLA & Service Availability Policy and contractual terms.
76. Policy Record
- Policy Name: StampMitra Cookie & Tracking Policy
- Policy Number: 13 of 19
- Version: 1.0
- Status: FINAL — PUBLISHED POLICY
- Effective Date: 05 October 2026
- Last Updated: 05 October 2026
- Operator: BANI GLOBAL INDUSTRIES LLP
- Prepared by: Legal Team, BANI GLOBAL INDUSTRIES LLP
- Legal Contact: [email protected]
77. Final Acknowledgement
77.1 This Cookie & Tracking Policy constitutes the official Cookie and Tracking Technology policy of the StampMitra Developer Platform as of its effective date.
77.2 The Policy is intended to provide transparent, technically accurate, and legally responsible information concerning the use of Cookies and similar technologies.
77.3 Nothing in this Policy shall be interpreted as a representation that every technology described herein is simultaneously deployed on every StampMitra property.
77.4 StampMitra reserves the right to modify its technical implementation, subject to applicable contractual, privacy, security, and legal obligations.
77.5 By continuing to use the relevant StampMitra interface, users acknowledge that they have had an opportunity to review this Policy, subject to any consent requirements imposed by applicable law.