Partner Cookie Policy
This Partner Cookie Policy explains the cookies and browser storage used specifically on the Deskio AI Partner Program's pages — the partner landing page, login/signup, and the Partner dashboard at /partners/*. It is separate from our general Cookie Policy, which covers the main Deskio AI site and product. If you're both a Partner and a Deskio AI business customer, both policies apply to the respective pages you use.
1. Purpose & Scope of This Policy
This policy lists the actual cookies set on Partner-facing pages, why each one exists, and how long it lasts. It does not cover cookies set on the general marketing site, client CRM, or chat widget — see our general Cookie Policy for those. Nothing on the Partner pages uses advertising or cross-site tracking cookies.
2. Relationship to the General Site Cookie Policy
The Partner Program's public landing page reuses the same site-wide cookie-consent banner and preference cookie described in the general Cookie Policy, since a visitor may arrive at /partners before ever deciding to become a Partner. Once you're signed in to the Partner dashboard, the additional cookies described below come into play, specific to the Program itself.
3. Types of Storage We Use
We use standard HTTP cookies (small pieces of data your browser stores and sends back to us on each request) for everything described in this policy. We do not currently use browser local storage or IndexedDB for anything Partner-specific beyond what your browser handles automatically for the cookies below.
4. Cookie & Storage Inventory
| Cookie | Purpose | Duration |
|---|---|---|
deskio_partner_session | Keeps you signed in to your Partner dashboard. Set when you log in or complete signup verification; required for the dashboard to function. | 7 days, or until you log out |
deskio_partner_csrf | A security token that protects state-changing Partner dashboard actions (such as submitting payout details or requesting a payout) from cross-site request forgery. | 7 days, matched to the session cookie above |
deskio_ref | Referral attribution cookie. Set on a visitor's browser when they arrive via a Partner's referral link, so that a signup within the attribution window is credited to that Partner. See Partner Agreement, Section 2, for how attribution works. | 90 days |
deskio_cookie_consent | Remembers whether a visitor accepted or declined the site-wide cookie consent notice, shared with the general marketing site. | Until cleared, or until the consent record is replaced |
| Third-party (Cloudflare Turnstile) | A one-time human-verification check that runs on Partner login and signup to block automated/bot signups. Cloudflare sets its own cookie for this — we don't control its name or contents. | Set by Cloudflare, per Cloudflare's own cookie policy |
5. Referral Attribution Cookie in Detail
deskio_ref is the mechanism that lets us credit a new business signup to the correct Partner. It stores only your referral code — no personal data about the visitor — for 90 days from the visitor's first click on your referral link. Whoever's referral link a visitor most recently arrived through before signing up gets the credit; the cookie is simply how "most recently" is remembered across the visitor's browsing session. If the visitor clears cookies or uses private/incognito browsing before signing up, this cookie — and the referral credit that depends on it — can be lost, which is the same limitation already disclosed in the Partner Agreement.
6. Session & CSRF Cookies in Detail
deskio_partner_session and deskio_partner_csrf are both set to httponly (unreadable by page JavaScript, reducing exposure to cross-site scripting), samesite=lax, and — in production — secure (sent only over HTTPS). Together they keep your dashboard session authenticated and protect actions like submitting CNIC/banking details or requesting a payout from being triggered by a malicious third-party site. Logging out clears both immediately.
7. Consent Banner Mechanism
The cookie-consent banner shown on the partner landing page is the same mechanism used site-wide: it appears until you choose Accept or Decline, and that choice is remembered via deskio_cookie_consent. Declining does not block the essential cookies described in Section 4 (the session, CSRF, and referral-attribution cookies, and the consent cookie itself) — these are necessary for the Program's core functionality and referral crediting to work at all, and are treated as essential rather than optional, consistent with how essential cookies are treated in our general Cookie Policy.
8. Third-Party Cookies (Cloudflare Turnstile)
Partner login and signup use Cloudflare Turnstile, a privacy-oriented CAPTCHA alternative, to block automated bot signups and credential-stuffing attempts against Partner accounts. Turnstile may set its own cookie as part of that verification; we do not control its contents, and Cloudflare's own cookie policy (linked in the table above) governs it.
9. What We Don't Use Cookies For
We do not use advertising cookies, cross-site tracking pixels, or any cookie designed to build an advertising profile of a Partner or website visitor on the Partner pages. The fraud-detection signals described in our Partner Privacy Policy (IP address and device/signal matching used to detect self-referral) are derived from request-level data at the time a Referred Client account is created, not from a persistent tracking cookie planted for that purpose.
10. Legal Basis for Cookie Use
The essential cookies in Section 4 are necessary to provide the Partner Program's core functionality — you cannot stay logged in, submit payout details safely, or have a referral correctly attributed without them — and are used on that basis rather than requiring separate opt-in consent. The consent-preference cookie itself, and any future non-essential cookie we might add, would be used only with your consent via the banner described in Section 7.
11. How Cookies Relate to Fraud Prevention
Because the referral-attribution cookie (deskio_ref) is what links a new signup back to a specific Partner, it's also the first input into the self-dealing fraud check described in our Partner Privacy Policy — once an attributed signup happens, we compare that new account's details against the referring Partner's own account details, independent of the cookie itself, to flag likely self-referral for admin review.
12. Managing, Blocking & Deleting Cookies
Most browsers let you view, block, or delete cookies through their Privacy or Site Settings. You can clear Deskio AI's Partner-page cookies at any time this way, which will log you out of the Partner dashboard and reset the cookie-consent banner and Turnstile's own state on your next visit.
13. Consequences of Blocking Essential Cookies
If you block or delete the essential cookies described in Section 4, the Partner dashboard will not function — you will be unable to stay logged in, submit payout details, or have your browsing correctly attributed as a referral. This is expected: these cookies are the mechanism the dashboard is built on, not an optional enhancement.
14. Cross-Device & Cross-Browser Referral Limitations
Referral attribution via deskio_ref is tied to a single browser on a single device. If a prospective client clicks your referral link on their phone but later signs up from a different device or browser, the cookie set on the first device won't carry over, and the signup may not be attributed to you. This is a structural limitation of cookie-based attribution, not a bug, and is the same limitation already disclosed in the Partner Agreement, Section 2.
15. Children & Minimum Age
Consistent with the Program's 18-and-over eligibility requirement described in our Partner Terms of Service, the Partner dashboard and its cookies are not directed at anyone under 18. The public referral link and landing page can be viewed by any visitor (referral attribution itself doesn't require the visitor to be an adult — the age requirement applies to who can become a Partner and sign up as one, not to a prospective client merely clicking a link).
16. International Visitors
The Program is Pakistan-only for Partners, but a referral link may be clicked from anywhere, and the deskio_ref cookie is set the same way regardless of the visitor's location. We don't vary Partner-page cookie behavior by region beyond the standard consent-banner mechanism already described.
17. Cookie Retention Summary
In summary: deskio_partner_session and deskio_partner_csrf last 7 days or until logout; deskio_ref lasts 90 days from the referral click; deskio_cookie_consent lasts until you clear it or replace your choice; and Cloudflare Turnstile's cookie follows Cloudflare's own retention, outside our control.
18. Do Not Track
Because we don't set advertising or cross-site tracking cookies on Partner pages in the first place, we don't currently respond differently to a browser's "Do Not Track" signal on these pages — there's no tracking to disable beyond what's already off by default.
19. Changes to This Policy
We may update this Partner Cookie Policy as the Program's technical implementation evolves — for example, if we add a new integration that sets its own cookie. We will post the updated policy here with a new "Last updated" date.
20. Contact
Questions about this Partner Cookie Policy can be directed to Zertix Studio via our Contact page.