Cookie Policy
Last Updated: 24/08/2026
MASTER COOKIE & TRACKING POLICY
This Comprehensive Cookie & Tracking Policy details the data governance, user consent protocols, and tracking technologies deployed by OLDFUL HEALTH CARE PLATFORMS LLP (operating under the brand name AYUXA). This applies across the AYUXA website (www.ayuxacare.com), the AYUXA mobile application, and all underlying server infrastructures.
Because we handle highly sensitive personal data—including diagnostic test reports, prescriptions, and real-time physical locations for elder care and SOS routing—transparency and strict compliance are our highest priorities.
1. Regulatory Compliance (DPDP Act)
AYUXA operates in strict compliance with the Digital Personal Data Protection Act, 2023 (DPDPA) of India. As a Data Fiduciary, we mandate the following protocols:
- Opt-In Model: We do not deploy any non-essential cookies, mobile SDK trackers, or analytical beacons on your device without your explicit, unambiguous, and informed consent.
- No Coercion: Access to the public areas of our website is not restricted if you choose to decline non-essential cookies.
- Granular Control: You maintain the absolute legal right to view active trackers, withdraw consent instantly, and request the deletion of non-essential tracking histories.
2. Mechanisms of Tracking
To provide a seamless healthcare platform, we utilize a combination of web, mobile, and telecommunication tracking technologies:
- Cookies & Local Storage: Small text files placed on your browser, and Secure Local Storage utilized within our mobile application framework to cache user preferences and authentication states locally on your device.
- Web Beacons & Pixels: Invisible image files embedded in our web pages and emails to verify if transactional emails (like clinical reports) were successfully delivered and accessed.
- Mobile SDKs: Third-party Software Development Kits embedded in our app architecture. These facilitate routing (Google Maps), emergency push notifications, and payment tokenization (Razorpay).
- Voice Metadata Tracking: For safety and quality assurance, communications facilitated between you and our caregivers via our telecommunications partner (Exotel) utilize call-masking. We log metadata including timestamps, durations, and connection stability.
3. Categories of Tracking Technologies
- Strictly Necessary (Essential): Core trackers required for AYUXA to function safely. These process payments, keep health records behind secure login walls, and mitigate DDoS attacks at our server edge (via Cloudflare). They cannot be disabled.
- Functional & Preference: Trackers that remember UI choices, language settings, and recently used delivery addresses to streamline the booking of elder care visits.
- Performance and Analytical: Trackers that monitor page load speeds, Nginx server response times, and app crash diagnostics to help our backend team optimize platform stability.
- Third-Party Integrations: API handshakes executing specific operational functions, including Redcliffe Labs (diagnostic syncing), fast2sms (OTP generation), and Razorpay (secure checkout).
4. Comprehensive Cookie & SDK Inventory
| Cookie / Tracker | Provider | Purpose & Description | Duration | Category |
|---|---|---|---|---|
__cf_bm / __cfduid |
Cloudflare (Edge) | Bot mitigation, DDoS protection, and secure web traffic routing before reaching our Hostinger VPS. | 30 Mins | Strictly Necessary |
ayuxa_auth_session |
AYUXA (Backend) | Maintains secure user login states to access patient records and care plans. | Session | Strictly Necessary |
rzp_checkout_track |
Razorpay | Facilitates secure payment gateway handshakes, tokenization, and financial fraud prevention. | 15 Mins | Strictly Necessary |
gmaps_geo_cache |
Google Maps API | Temporarily stores latitude/longitude to accurately route caregivers and map local pharmacies. | 24 Hours | Functional |
sms_delivery_token |
fast2sms | Confirms successful delivery of critical SOS alerts and transactional OTPs via WhatsApp/SMS. | Session | Strictly Necessary |
bloodtest_sync_id |
Redcliffe Labs | Syncs the user's home-collection booking from the AYUXA dashboard to the laboratory backend. | 7 Days | Strictly Necessary |
cookie_consent_status |
AYUXA | Remembers whether the user accepted or rejected non-essential tracking under DPDP Act rules. | 1 Year | Strictly Necessary |
5. Legal Loophole Protections
- Network Edge & Hosting: Security cookies placed by our Content Delivery Network (Cloudflare) or server host operate independently at the network edge to prevent cyber-attacks. They are legally exempt from consent banner blocking as they are strictly necessary for platform survival.
- Do Not Track (DNT) Signals: Because there is no universally accepted legal or technological standard for recognizing "Do Not Track" signals transmitted by web browsers, AYUXA does not currently alter its site behavior or tracking practices upon receiving a DNT signal.
- Mobile Framework Autonomy: The third-party SDKs embedded in our mobile framework may independently cache operational data on your device. AYUXA disclaims liability for tracking behavior silently altered by a third-party package update beyond our immediate control.
6. Mobile App Device Permissions
On the AYUXA Mobile App, traditional cookies are superseded by device permissions. The app requires explicit OS-level permission for:
- Precise Location (GPS): Strictly necessary for dispatching SOS ambulances, routing Phlebotomists, and locating the nearest local pharmacy.
- Background App Refresh: Required for the SOS Emergency Panic feature to successfully broadcast your location even if the application is minimized.
- Push Notifications: Utilized to send critical updates (e.g., "Your caregiver has arrived" or "Your diagnostic report is ready").
7. Managing & Withdrawing Consent
You possess total control over your digital footprint. Note: Disabling Strictly Necessary trackers or OS permissions (like GPS and Background Data) will permanently cripple critical features like the SOS Panic Button, payment processing, and location routing.
- Via the AYUXA App: Navigate to Profile > Settings > Privacy & Data Permissions to revoke consent.
- Mobile OS Controls: Revoke app-level permissions directly through your smartphone settings (Settings > Apps > AYUXA > Permissions).
- Browser Controls: Instruct your browser (Chrome, Safari, Firefox) to refuse cookies via the internal Privacy & Security settings tab.
8. Grievance & Compliance Contacts
If you have questions or wish to exercise your data rights regarding tracking technologies, please contact our Compliance Officer:
No. 39-7-1, 3rd Floor, 7th Main,
Appareddy palya, Indiranagar,
Bangalore 560038
Grievance Officer: SK Murgan