Cookies and browser storage
Everything Qvesti stores in your browser, what it is for, and how long it stays. The list is checked against the code that writes the cookies: a test fails the build when a name in the source is missing from this page, or a name on this page has left the source. That check reads the source rather than running all of it, so a browser test reads a real cookie jar as well, and the date at the foot of this page says when a person last went through it.
You are not asked to accept anything. Every cookie below is doing the job named beside it: keeping you signed in, keeping a conversation together, stopping a form being submitted by someone else, remembering the language you chose. None of them is here to watch you. The browser storage below is your own copy of a conversation and a note that you have finished a walkthrough; it is kept on your device, and the site still works if you block or clear it.
There is no analytics cookie, no advertising cookie and no tracking cookie. We run no tag manager and no measurement script. Nobody is paid for what you do here. The companies that run the service for us are listed further down.
Who is responsible Qvesti · info@qvesti.com
This website
| Name | Set by | What it is for | How long it lasts | Where it appears |
|---|---|---|---|---|
__Host-QvestiLocale | Qvesti | Remembers the language you chose here, and is read where nothing more specific applies. A language named in the address, a page offered in fewer languages, or a shop's own setting on the shop's own address each take precedence. | 365 days | qvesti.com; a shop's own address, when its chat runs there |
__Host-RAGSession | Qvesti | Identifies this browser, so a conversation holds together across messages. Sign-in attempts are counted against it too, and when you are signed in it is what keeps the workspace you chose, and any administrative access you hold, on this browser rather than on your account. | 30 days | qvesti.com; a shop's own address, when its chat runs there |
__Host-RAGCsrf | Qvesti | Proves a request came from a page we served, so nobody else can act as you. | 30 days | qvesti.com; a shop's own address, when its chat runs there |
Signing in and the operator console
| Name | Set by | What it is for | How long it lasts | Where it appears |
|---|---|---|---|---|
__Host-RAGAuth | Supabase, our authentication provider | Keeps you signed in. Set by our authentication provider. | 400 days | qvesti.com |
__Host-RAGAuth-code-verifier | Supabase, our authentication provider | A one-time value that proves the sign-in you finish is the sign-in you started. | 400 days | qvesti.com |
__Host-RAGApp | Qvesti | Remembers which workspace you last opened. | 30 days | qvesti.com |
__Host-RAGPwReset | Qvesti | Keeps password setup or recovery tied to the browser that verified your email, including any required two-step verification. Expires within 15 minutes. | 15 minutes | qvesti.com |
__Host-RAGEmailCode | Qvesti | Connects an email code request to this browser for up to 10 minutes. It contains a request identifier and no email address, password or email code. | 10 minutes | qvesti.com |
__Host-RAGEmailChange | Qvesti | Carries a short-lived permission to change your sign-in address, after you click the link in the email. | 30 minutes | qvesti.com |
__Host-RAGDeleteGrant | Qvesti | Carries a short-lived permission to confirm deleting your account, after you click the link in the email. | 30 minutes | qvesti.com |
__Host-RAGAdminGrant | Qvesti | Records that you re-entered your password for an administrative action. | 12 hours | qvesti.com |
A sign-in token too long for one cookie is split across numbered cookies that share its name, .0, .1 and onwards. They are one cookie to you and to us.
The hosted chat page
| Name | Set by | What it is for | How long it lasts | Where it appears |
|---|---|---|---|---|
__Host-RAGChatClearance | Qvesti | Records that you passed the bot challenge, so you are not asked again on every message. | 1 day | qvesti.com; a shop's own address, when its chat runs there |
__Host-RAGChatOutagePass | Qvesti | A short pass issued when the bot challenge itself is unavailable, so chat keeps working. | 5 minutes | qvesti.com; a shop's own address, when its chat runs there |
Confirming a contact request
| Name | Set by | What it is for | How long it lasts | Where it appears |
|---|---|---|---|---|
__Host-QvestiContactSession-<flow> | Qvesti | Holds the one confirmation you are in the middle of, and nothing else. | 10 minutes | contact.widget.qvesti.com |
__Host-QvestiContactCsrf-<flow> | Qvesti | Proves the confirmation you submit is the one we opened for you. | 10 minutes | contact.widget.qvesti.com |
The older support runtime
| Name | Set by | What it is for | How long it lasts | Where it appears |
|---|---|---|---|---|
__Host-QvestiSupportSession | Qvesti | Identifies your session in the older support runtime, on the shop's own address. | 8 hours | a shop's own support address |
__Host-QvestiSupportCsrf | Qvesti | The same protection against another site acting as you, there. | 8 hours | a shop's own support address |
Browser storage
| Name | What it is for | Where it appears |
|---|---|---|
qvesti-widget-setup-v1:<app>:<installation> | Remembers which widget snippet version and language you copied, per app and installation, so setup guidance can stop highlighting it. No automatic expiry; clearing this site's data removes it. | Signing in and the operator console |
qvesti:chat-history:v1:hosted%3A<app> | Your own copy of the conversation, so it is still there if you come back. | The hosted chat page |
qvesti:widget-history:v1:<installation> | Your own copy of the conversation with a shop's widget, kept per installation. | The chat widget on other people's sites |
ragainfra.test-lab-workflow.<workspace>.v1 | Remembers that you have already seen a short walkthrough. | Signing in and the operator console |
Two of these keep your own copy of a conversation, in your browser and nowhere else, in a separate list for each app or installation. When you open a chat again, a conversation whose last message is more than thirty days old is no longer listed, and its text goes when that list is next written — in the widget as soon as you send another message, in the chat on this site when a different conversation is saved. Nothing runs on a timer, so a list you never come back to keeps its bytes until you clear them. A list holds twenty conversations: once it is full, saving a new one drops the oldest of the rest, and the oldest give way as well whenever the list would grow past the size limit we set for it. The Clear history control in a chat empties the one list it belongs to, the app or installation you are chatting with, and leaves the others; to remove all of them, clear the browser's site data for qvesti.com and for the shop's site where you used the widget. The walkthrough and widget-setup preferences remember completed guidance and copied snippets. Neither expires automatically; both stay until you clear this site's data.
Cookies we only delete
Older sign-in cookies from a previous version of our authentication provider are still recognised, and the only thing done with them is to expire them. Nothing writes them any more.
sb-<project>-auth-token, sb-<project>-auth-token.0, sb-<project>-auth-token.1, sb-<project>-auth-token-code-verifier, sb-<project>-auth-token-code-verifier.0, sb-<project>-auth-token-code-verifier.1
Other people's code
Cloudflare Turnstile is the only third-party code that runs on our pages, on the sign-in and chat surfaces, to tell a person from a script. It sets its own cookies on its own address, challenges.cloudflare.com, which we never read. Cloudflare can also place a cf_clearance cookie on the site you are visiting; we neither set it nor read it.
challenges.cloudflare.com · cf_clearance
Who else can see this
- Supabase, which provides our authentication and database
- Vercel, which hosts this website
- Cloudflare, which provides the bot challenge and delivers our email
- Google Cloud, which runs our background services
Why we are allowed to store these
Every cookie here is strictly necessary to provide the service you asked for, so no consent is required to store it. For the cookies that deliver a signed-in account, processing is necessary to perform our agreement with you. For the ones that protect a request from being forged, and for the bot challenge, we rely on our legitimate interest in keeping the service safe to use. For the ones that identify an anonymous conversation, or hold a contact confirmation while you complete it, we rely on our legitimate interest in providing what you asked for.
How long any of this is kept
For cookies, the lifetime in the table is the retention period: the browser removes each one when it expires. For the browser storage above, the criterion is use rather than a timer: a conversation is no longer listed once its last message is thirty days old, and its text goes when that list is next written — in the widget at your next message, here when a different conversation is saved. A list holds at most twenty and sheds the oldest when it would grow too large, you can clear a list yourself at any time, and the walkthrough flag has no expiry at all: it stays until you clear this site's data.
Your rights
You can ask what we hold about you, correct it, have it deleted, limit what we do with it, object to it, or receive it in a portable form. Write to info@qvesti.com and we will answer.
If you are not satisfied
You can complain to a data protection supervisory authority in the country you live or work in, or where you think something went wrong.
Removing all of it
Clearing the browser's site data for qvesti.com removes every cookie we set there and every conversation stored for it; where you met Qvesti on a shop's own address — its widget, or a chat served under the shop's domain — clear that site's data as well. Signing out removes the cookie that keeps you signed in, the one that remembers your workspace and the one that records an administrative re-entry of your password; a permission you opened from an email — a password reset, an address change, a deletion — stays in your browser until it expires. The chat widget has its own Clear history control, and it empties only that installation's list.
What this page covers
This page covers what Qvesti stores in your browser and who can see it. It is not a full privacy policy, and it does not describe what a shop using Qvesti does with the conversations on its own site.
Last checked against the code: