Legal
Cookie Policy
Everything QuantGrid stores on your device, named individually. It is a short list: strictly necessary storage, one appearance preference, and two analytics tools on the public website. No advertising and no cross-site tracking on either property, and no analytics at all in the dashboard.
- Last updated
- 21 August 2026
- Applies to
- quantgrid.in and the QuantGrid platform
1. What this covers
This policy explains what Tristack Technologies LLP, trading as QuantGrid, stores on your device and why. It covers two properties:
- quantgrid.in, the public website you are reading now.
- app.quantgrid.in, the dashboard you sign in to once you register.
It covers cookies and also browser local storage, because both are data kept on your own device and the practical question is the same one: what is stored, why, and how do you get rid of it. The wider picture, including what we collect on our servers and your rights under the Digital Personal Data Protection Act, 2023, is in the Privacy Policy.
2. Our position, in short
That is a smaller list than most sites publish, and it is deliberate. A copy-trading platform has no business knowing which pages you read before you signed up, so the honest position is to collect nothing rather than to collect it and promise restraint.
3. On the website
The marketing site at quantgrid.in is statically rendered and sets no cookies of its own. You can read every page, including the prices and every policy document, without anything of ours being written to your device.
Cloudflare, which proxies and protects the site, sets its own operational cookies on our domain as traffic passes through it. Those are listed in section 5. The contact form posts what you type in it and nothing more: it sets no cookie, and it does not remember you between visits.
4. In the dashboard
The dashboard at app.quantgrid.in does not use a session cookie. When you sign in, it keeps your access token in browser local storage and sends it with each call it makes to our API. The practical differences worth knowing:
- Signing out, or clearing site data for that domain, removes the token and ends the session on that device.
- The token is scoped to your own account and is the only thing that identifies you to the application.
- It is stored per browser and per device, so signing in on a laptop does not sign you in on a phone.
The dashboard also remembers the appearance you selected, in the same local storage. That is the complete list. Your broker access tokens are never stored in your browser: they are held encrypted on our servers, as described on the security page.
5. The complete inventory
Every item stored on your device by us or by our network provider, what it does and how you remove it. If you find something on our domains that is not on this list, tell us at [email protected] and we will explain it or remove it.
| What | Where it is stored | Purpose | Type | Control |
|---|---|---|---|---|
| Sign-in token | Browser local storage, on the dashboard domain | Keeps you signed in to the dashboard between page loads once you have authenticated. Not a cookie: it is held in local storage and sent by the application when it calls our API. | Strictly necessary | Sign out, or clear site data for the dashboard domain. Clearing it signs you out. |
| Appearance preference | Browser local storage, on the dashboard domain | Remembers the dashboard appearance you selected, so it is not reset on every visit. | Preference | Clear site data for the dashboard domain and it returns to the default. |
| Network and bot-protection cookies | Cookie, set by Cloudflare on our domains | Cloudflare sits in front of both sites and sets its own operational cookies (for example __cf_bm) to tell automated traffic from human traffic and to keep the service reachable. | Strictly necessary | Blocking them may cause the network layer to challenge or refuse your requests before they reach us. |
| Google Analytics (_ga, _ga_*) | Cookie, set on our domain, loaded through Google Tag Manager | Counts visits and which pages are read, so we can tell what is useful and what nobody opens. Property G-6T56MSKN21. It measures pages, not people: we do not send it your name, your email or anything about your trading. | Analytics | Block cookies for our domain, use Google's opt-out add-on, or use a browser or extension that blocks the tag. |
| Microsoft Clarity (_clck, _clsk) | Cookie, set on our domain, loaded through Google Tag Manager | Records how pages are used, including clicks, scrolling and navigation, and can replay a session as a diagram of those interactions. We use it to find layouts that confuse people. Project xyupuaiht6. Clarity masks text input by default, so what you type is not captured. | Analytics | Block cookies for our domain, or use a browser or extension that blocks the tag. Clarity also honours a Do Not Track signal. |
Nothing in that table has a marketing purpose, and none of it is shared with anyone for one.
6. Third parties
Five third parties can set cookies, or have cookies set on our domain on their behalf, while you use our service. Each one is there to do a specific job, and each one is governed by its own policies rather than by this one.
| Who | When they are involved | What they do |
|---|---|---|
| Cloudflare | On every visit to either site | Proxies and protects traffic to the website and the dashboard, and sets its own operational cookies to do it. We do not read them for any purpose of our own. |
| Only if you choose Sign in with Google | Sign-in happens on Google pages, which set Google cookies on Google domains under Google policies. We receive the confirmation that you signed in, your Google account identifier and your email address. Use email and password instead and nothing Google-related is involved. | |
| Razorpay | Only during a payment | Razorpay Checkout runs the payment and sets its own cookies on its own domain, for fraud prevention and to carry the transaction through. Card and bank details go to Razorpay directly and never reach our servers. |
| Google (Tag Manager and Analytics) | On every visit to the public website | Google Tag Manager loads our measurement tags, and Google Analytics 4 counts visits and page views under property G-6T56MSKN21. It receives the page you requested, a randomly generated visitor identifier and your approximate location derived from your IP address. It is not given your name, your email or anything about your trading. |
| Microsoft (Clarity) | On every visit to the public website | Microsoft Clarity records interactions with the page, including clicks, scrolling and navigation, so we can see where a layout is confusing. Project xyupuaiht6. Text you type into a field is masked by Clarity before it leaves your browser. |
None of the five is an advertising integration, none of them is given your trading data, and nothing collected is sold or shared with an ad network. Who processes what on our behalf, and where, is set out in the Privacy Policy.
7. What we do not use
Stated as a list, because a specific denial is worth more than a general assurance:
- No advertising cookies, no conversion pixels, no retargeting tags and no ad-network integrations.
- No social-media widgets, share buttons or embedded players that would set third-party cookies.
- No cross-site or cross-device tracking, no device fingerprinting and no data brokers.
- No analytics in the dashboard. The measurement described in section 5 runs on the public website only, so nothing you do with a broker account or a live order is measured.
- No trading data in any analytics tool. Google and Microsoft receive pages and interactions, never an order, a position, a balance or a broker account.
- No sale of cookie or browsing data, to anyone, ever.
This list used to open by denying any analytics at all. That stopped being true when we added Google Analytics and Microsoft Clarity to the public website, and the denial stood here longer than it should have. Both are listed in full in section 5, and this page is the record of what runs rather than of what we would like to be able to say.
8. Consent, and what we are changing
The two analytics items in section 5 are not strictly necessary. The website works identically without them, they exist so we can see which pages are useful and where a layout confuses people, and that is the kind of thing a visitor should be asked about rather than told about.
We are straightforward about where this stands. This page previously said there was no cookie banner because there was nothing to consent to. That was written when it was true and was not revised when we added measurement, so it described the site we intended rather than the site we were running. We would rather correct it plainly than quietly.
Until a consent control is in place, section 9 lists what you can do from your own browser today, and all of it works: blocking cookies for our domain stops both tools, and Clarity also honours a Do Not Track signal. Nothing about the service degrades if you block them, because nothing about the service depends on them.
9. Your controls
You are in control of all of it, from your own browser:
- Clear or block cookies for our domains in your browser settings. Every browser offers this per site.
- Clear site data for the dashboard domain to remove the sign-in token and the appearance preference. You will be signed out and the appearance returns to the default.
- Use a private window for the marketing site. Nothing of ours persists after you close it.
What blocking costs you: block the network and bot-protection cookies and our provider may challenge or refuse your requests before they reach us. Block storage on the dashboard domain and you cannot stay signed in, so the application will not work. Nothing else on the marketing site is affected: every page, price and policy stays fully readable with all storage blocked.
We set nothing that follows you between sites, so a Do Not Track or Global Privacy Control signal has nothing of ours to switch off. Cookies set by Google or Razorpay are controlled through their own settings and policies, since they are set on their domains and not on ours.
10. Changes and contact
We may revise this policy, for instance if we change network provider or add a payment method. The version in force is the one published on this page, and the date at the top is the date it took effect. This version is effective 21 August 2026.
Questions about a specific item, or a request to see what we hold about you, go to [email protected]. We respond within 30 days. For a formal complaint, the Grievance Officer is Devansh Dalmia, at [email protected]. Your rights over your personal data, and how to exercise them, are set out in the Privacy Policy.
Questions about this document
Write to [email protected], or reach the Grievance Officer, Devansh Dalmia, at [email protected] or by phone: call us. Every policy on this site is published by Tristack Technologies LLP, which operates QuantGrid and is the entity you contract with.
Registered office: B-35, Vinoba Kunj Apartments, Sector 9, Rohini, Delhi 110085, India · LLPIN ACP-3743 · GSTIN 07AAYFT2516N1ZFSee also Terms, Privacy, Cookies, Refunds, Service delivery, Disclaimer and Risk disclosure.