Cookie Policy
GCC ERA PRIVATE LIMITED
Effective 10 September 2026 · Last updated 10 September 2026
Applies to gccera.com, gccera.com/products, and the GCC ERA mobile app (com.gccera.app)
This Cookie Policy explains, cookie by cookie, what is stored on your device when you use gccera.com. It supplements Section 3 of our Privacy Policy (which describes the categories and the legal basis) and should be read alongside our Terms and Conditions. Where this policy and the Privacy Policy differ on a point of detail about cookies, this policy is the more specific and more current statement.
1. What Cookies Are
Cookies are small text files a website stores on your device. Related technologies — localStorage, sessionStorage and tracking pixels — do the same job in a different way. Throughout this policy "cookies" means all of them, because the DPDP Act cares about the processing of your personal data, not the storage mechanism used.
A first-party cookie is set by gccera.com. A third-party cookie is set by another company whose code runs on our pages. Both are listed below.
2. Our Consent Model
Nothing non-essential loads before you choose. Analytics and advertising scripts are not merely held back from sending events — the scripts themselves are never fetched until you accept. This matters because merely loading a third party's script discloses your IP address, user-agent and referring page to that company, which is processing in its own right.
We show a consent banner on your first visit with two clear options — Accept all and Reject non-essential. Both are single clicks and neither is visually preferred over the other. Ignoring the banner has the same effect as rejecting: nothing non-essential loads.
Withdrawal is honoured immediately, not just recorded. If you accept and later reject, the page reloads so that already-running third-party scripts are unloaded from the tab. Recording a refusal while those scripts kept transmitting would make the withdrawal cosmetic.
3. Cookies We Set (Full List)
a. Strictly necessary — always active
These are required for sign-in, security and fraud prevention. They cannot be switched off without breaking the Platform, and they carry no advertising or profiling function.
| Name | Set by | Purpose | Retention |
|---|---|---|---|
cookie_consent | gccera.com (localStorage) | Remembers your banner choice. Without it we would have to ask on every page. | Until you clear site data |
sb-*-auth-token | gccera.com (Supabase) | Keeps you signed in. | Session / until sign-out |
gcc_anon_id, gcc_first_touch, gcc_touch_bound | gccera.com | Anonymous identifier used to attribute a later sign-up to the visit that led to it. Not shared with advertisers unless you accept advertising cookies. | Until you clear site data |
rzp_unified_session_id | Razorpay | Payment session integrity and fraud prevention during checkout. | Session |
b. Analytics — only after you accept
None of the following exist on your device unless you clicked Accept all.
| Name | Set by | Purpose | Retention |
|---|---|---|---|
_ga, _ga_3D5SHRSJJJ | Google Analytics 4 (via Google Tag Manager) | Distinguishes visitors and sessions to measure traffic and page performance. | Up to 2 years |
_clck, _clsk | Microsoft Clarity (gccera.com) | Links a session to its heatmap and replay record. | _clck up to 1 year; _clsk 1 day |
CLID, ANONCHK, MR, SM, MUID, SRM_B | Microsoft (clarity.ms, bing.com) | Clarity's own session identifiers, set on Microsoft domains. | Up to 1 year |
AMP_* (e.g. AMP_296625ff1b) | Amplitude | Product analytics — which features are used and where users get stuck. | Up to 1 year |
ph_* | PostHog | Product analytics. Only present where PostHog is enabled. | Up to 1 year |
c. Advertising — only after you accept
| Name | Set by | Purpose | Retention |
|---|---|---|---|
_fbp | Meta Pixel (gccera.com) | Measures whether advertising we pay for led to a sign-up, and supports remarketing. | Up to 3 months |
Server-side measurement. Where you have accepted advertising cookies, we may also send conversion events to Meta and Google Ads from our servers. Any email address or phone number in those events is irreversibly hashed (SHA-256) first — the recipient cannot read the underlying contact details. This is measurement, not a sale of your data, and it does not happen if you decline.
4. Cookies Set by Our Hosting Provider
We must disclose something we do not fully control. Our web host inserts its own traffic-monitoring script into pages as they are served — after our own code has been built and deployed. Because this insertion happens at the server, our consent banner cannot gate it the way it gates every vendor in Section 3.
| Name | Set by | Purpose | Retention |
|---|---|---|---|
_tccl_visitor, _tccl_visit | Hosting provider (secureserver.net) | Host-level traffic and performance monitoring. | Up to 1 year |
_scc_session | Hosting provider | Host-level session measurement. | Session |
These are analytics cookies of our hosting provider, not advertising cookies, and they are not used by us to profile you or to target advertising. We are working to disable this monitoring at the hosting account level. Until that is complete we disclose it here rather than leave it undocumented, and we will remove this section once the cookies stop being set.
5. Third-Party Cookies We Do Not Control
Some cookies are set by providers whose services you choose to use on our pages. These are governed by that provider's own policy:
- Razorpay — payment processing and fraud checks, loaded only when you begin a payment.
- Google OAuth — only if you sign in with Google.
- Cloudflare — security and bot protection for the site.
We also load fonts, images and libraries from content delivery networks (Google Fonts, jsDelivr, Cloudflare CDN, Unsplash). These deliver files and do not set advertising cookies, though the CDN necessarily receives your IP address in order to send you the file.
6. How to Change or Withdraw Your Choice
Select Cookie Preferences in the footer of any page. The banner reopens and your new choice takes effect immediately. Withdrawing consent is exactly one click — the same effort it took to give it, as DPDP §6(4) requires.
You can also block or delete cookies in your browser settings. Blocking strictly necessary cookies will prevent sign-in from working.
7. Session Replay & Masking
Where you have accepted analytics cookies, Microsoft Clarity and Amplitude may record an anonymised playback of your interaction with a page — pointer movement, clicks and scrolling.
Masking is set to strict. Text you type is masked before it leaves your browser, so CV contents, salary figures, phone numbers and email addresses are not transmitted into a recording. We consider this essential rather than optional, because these recordings would otherwise hold the most sensitive data on the Platform in the least protected place.
8. Mobile App
The GCC ERA mobile app (com.gccera.app) presents the same banner and honours the same choice. Notification and microphone permissions are controlled separately by your operating system and can be revoked at any time in device settings without losing access to the rest of the Platform.
9. Policy Updates & Contact
We update this policy when we add, remove or change a cookie. The "Last updated" date at the top reflects the most recent change. Material changes to what we collect will be surfaced through the consent banner rather than only by editing this page.
Questions about this policy, or about cookies set on your device:
- Grievance Officer: [email protected]
- Registered office: 11, Niribili Path, R G Baruah Road, Zoo Road, Kamrup Metropolitan, Guwahati, Assam – 781024, India
- Customer care: +91 75007 09210 · [email protected]
For unresolved concerns, write to the Data Protection Board of India at the address on their official website.
GCC ERA Private Limited · CIN U62011AS2025PTC028987 · GSTIN 18AAMCG3895Q1ZH
