Cookie Policy
Effective date: 2 September 2026
This Cookie Policy explains how GroveX uses cookies and similar storage or access technologies when you visit or use GroveX websites and web-based services. It should be read together with the GroveX Privacy Policy.
Cookies are small data files stored by a browser. Similar technologies can include local storage, session storage and other mechanisms that allow a website to remember information about a browser, device, session or user preference. In this policy, we refer to these technologies collectively as "cookies and similar technologies".
1. Why GroveX Uses Cookies
GroveX uses cookies and similar technologies where they are necessary or useful to provide secure web services, maintain authentication, recognise a device, protect login flows, remember limited interface state and support the reliable operation of the platform.
At the effective date of this policy, the core first-party cookies identified in the GroveX web authentication flow are primarily security, device and session cookies. If GroveX introduces or activates additional non-essential analytics, advertising or similar technologies, this policy and the applicable user controls should be updated accordingly.
2. Core First-Party GroveX Cookies
The following cookies are used in the current GroveX web authentication flow. Exact use can depend on which features you access and whether you choose an option such as "remember me".
- gx_device - used to recognise the browser or device during security and authentication workflows. It is configured as a persistent cookie with a maximum age of approximately 365 days.
- gx_session - used to maintain an authenticated GroveX web session. It is normally a session cookie; where a supported "remember me" option is selected, it may persist for up to approximately 30 days.
- gx_captcha - temporary security state used during the anti-bot or login security challenge. It is configured for approximately 5 minutes and is cleared when no longer required.
- gx_captcha_ok - temporary state indicating completion of the applicable security challenge. It is configured for approximately 5 minutes and is cleared as the login flow progresses.
- gx_login - temporary state used to complete login verification. It is configured for approximately 10 minutes and is cleared following completion or expiry of the login flow.
These authentication cookies are configured as HTTP-only cookies. In production they are configured to use secure transport settings, a SameSite=Lax policy and the root website path. HTTP-only cookies are not directly readable by ordinary client-side JavaScript.
3. Strictly Necessary and Security Technologies
Strictly necessary technologies are used to provide a service you request or to protect the operation and security of that service. Depending on the feature, these technologies can support:
- login, logout and authenticated session handling;
- device recognition and account-security checks;
- captcha and anti-automation controls;
- fraud prevention and abuse detection;
- load balancing, reliability and service continuity;
- security settings and transaction-protection workflows; and
- remembering information required to complete a user-requested process.
Where applicable law permits strictly necessary technologies without prior consent, GroveX may use them without asking you to opt in because the relevant service cannot be provided securely or correctly without them.
4. Preference and Functional Storage
GroveX web interfaces may use browser storage to remember non-sensitive interface state, such as whether a platform announcement has been seen or a user-interface preference has been selected. Depending on the implementation, this information may be stored in local storage or another browser storage mechanism rather than a traditional cookie.
Disabling browser storage may cause some preferences to reset or may reduce the convenience of certain web features.
5. Analytics and Performance Technologies
Analytics and performance technologies can be used to understand how a website is used, identify errors, measure performance and improve user experience. These technologies may collect information such as page interactions, browser type, device characteristics, approximate location derived from network information, referral information or technical events.
GroveX does not use this policy to claim that a particular third-party analytics provider is active unless that provider is actually implemented. If non-essential analytics technologies are activated and applicable law requires consent, the relevant consent mechanism should be presented before those technologies are activated.
6. Advertising and Marketing Technologies
Advertising or marketing technologies can be used to measure campaigns, limit repeated advertising or understand whether users reached GroveX through a marketing source. Such technologies can be more privacy intrusive than essential cookies.
Where GroveX uses advertising or marketing technologies that require consent under applicable law, GroveX should obtain the required consent before activating them and should provide a way to withdraw or change that choice.
7. Third-Party Technologies
Some GroveX pages or services may interact with third-party infrastructure or content providers. A third party may use its own cookies or similar technologies when its service is loaded or used. Third-party technology can have purposes and retention periods that differ from GroveX first-party cookies.
GroveX seeks to avoid describing a third-party provider in this policy unless the provider is actually part of the service. Users should review notices presented by the relevant third party when interacting directly with an external service or website.
8. Consent and Your Choices
Cookie requirements differ by jurisdiction. Where applicable law requires consent for non-essential cookies or similar technologies, GroveX will seek to implement an appropriate choice mechanism before the relevant technology is activated.
Strictly necessary cookies may remain active because disabling them can prevent login, security verification, account access or other requested functionality from working correctly.
9. Browser Controls
Most browsers allow you to view, block or delete cookies and to clear site data. You can normally find these settings in the privacy, security or site-data section of your browser. Browser controls can also allow you to clear local storage and other stored website data.
If you block or delete GroveX security or session cookies, you may be logged out, required to complete security verification again, or unable to use parts of the platform.
10. Cookie Duration and Retention
Some cookies are session cookies and expire when the relevant browser session ends. Others are persistent and remain until their configured expiry, until they are replaced, or until you delete them. Temporary security cookies are intentionally short-lived.
The core first-party durations described above reflect the current GroveX web authentication implementation at the effective date. GroveX may change technical durations where reasonably necessary for security, functionality or legal compliance and should update this policy when a material change affects the information users need.
11. Information Processed Through Cookies
Depending on the technology, information associated with cookies or browser storage may include a device or session identifier, authentication state, security challenge state, technical browser or device information, timestamps, language or platform information and limited interface preferences. Information processed through cookies is handled in accordance with the GroveX Privacy Policy and applicable privacy and data protection laws.
12. Security
GroveX uses technical controls intended to reduce the risk of unauthorised access to authentication cookies, including HTTP-only settings for core login cookies and secure transport settings in production. No internet service can guarantee absolute security, and users should also protect their devices, browsers and GroveX account credentials.
13. Changes to this Policy
GroveX may update this Cookie Policy to reflect changes to web functionality, storage technologies, service providers or applicable requirements. The effective date above identifies the version currently published.
14. Questions
Questions about this Cookie Policy, privacy practices or the use of cookies can be submitted through the GroveX Help Center or Contact page. Privacy-related requests are handled in accordance with the GroveX Privacy Policy and applicable law.