This Cookie Notice explains how Fintant Inc. (“Fintant,” “we,” “us,” or “our”) uses cookies and similar browser technologies on its public website and invitation-only portal. It should be read with the Privacy Notice.
1. What cookies and browser storage are
A cookie is a small text record that a website asks a browser to store and return with later requests. Browser storage, such as session storage, lets a site retain limited information within a browser tab or session.
Fintant uses these technologies only for disclosed purposes. Some are strictly necessary to provide account security, authentication, request integrity, organization context, and core portal functionality. Optional analytics, advertising, or marketing technologies require separate approval and, where required, an appropriate consent or opt-out mechanism.
2. Current first-party inventory
The following inventory reflects the implemented application configuration reviewed on July 30, 2026. Cookie names may be environment-specific. Fintant must verify the deployed production inventory before this Notice becomes effective.
Cookie and browser storage inventory.
Name: fintant-accounting-session. Type: Strictly necessary first-party cookie. Purpose: Maintains the authenticated portal session after Fintant’s server validates the approved identity flow. Typical duration: Up to 8 hours, or earlier logout, revocation, or expiry. Access and protection: HTTP-only; SameSite=Lax; Secure in production.
Name: fintant-accounting-csrf. Type: Strictly necessary first-party cookie. Purpose: Supports cross-site request forgery protection by allowing the browser application to send a matching request header. Typical duration: Up to 8 hours, aligned to the session, or earlier logout or expiry. Access and protection: Browser-readable for header submission; SameSite=Lax; Secure in production.
Name: fintant-accounting-auth-state. Type: Strictly necessary first-party cookie. Purpose: Protects the temporary authentication callback and validates that the callback belongs to the initiating browser flow. Typical duration: About 10 minutes, or earlier completion or expiry. Access and protection: HTTP-only; limited to the authentication API path; SameSite=Lax; Secure in production.
Name: fintant-accounting:selected-organization. Type: Browser session storage. Purpose: Remembers the organization selected for display and navigation during the current browser session. Server-side authorization remains authoritative. Typical duration: Until the browser tab or session ends or the value is cleared. Access and protection: Stored in browser session storage; it is not an authentication credential.
The production deployment may use a different host prefix or additional secure attributes. The policy owner must compare this table against an authenticated browser inventory after deployment.
3. Why these technologies are necessary
The current technologies support:
invitation-only account sessions; authentication callback integrity; protection against forged state-changing requests; session expiry and revocation; organization selection and navigation; and reliable operation of the authenticated portal.
Fintant’s server independently verifies the user, organization, role, session, and authorization for protected actions. A browser-stored organization selection does not grant access.
4. Optional analytics, advertising, and marketing
Fintant uses Cloudflare Web Analytics on public marketing pages and the public Book a Call entry page. This limited public-site measurement is separate from product analytics and the authenticated application.
no third-party advertising cookies are required by the portal; Cloudflare Web Analytics sets no analytics cookie or browser-storage value; the beacon measures page host and path without query strings, referrer host, country, device type, browser, operating system, navigation type, page views, visits, and performance timing; Fintant sends no custom event, contact, questionnaire, account, authenticated-user, or Client Financial Data field to Cloudflare Web Analytics; unsampled beacon data is retained for seven days, aggregated Web Analytics data is available for the previous six months, and the current free account uses Cloudflare’s global processing rather than a paid regional metadata boundary; Global Privacy Control or Do Not Track prevents Fintant’s beacon loader from adding the Web Analytics script; no optional production product-analytics provider is approved; and client financial content, credentials, tax identifiers, account numbers, internal notes, reusable file links, and message bodies must not be placed in analytics.
Fintant offers optional Google Analytics on public website pages to understand page visits and improve the website. Google Analytics loads only after you accept analytics. It uses _ga and _ga_S22KZSVZC3 cookies to distinguish browsers and sessions, with a maximum lifetime of 180 days without automatic renewal. We remember your analytics choice in browser storage for up to 180 days. You can accept, decline or withdraw through Analytics settings at the bottom of public pages. Global Privacy Control and Do Not Track keep Google Analytics off. Declining or withdrawing does not affect access to our website or forms.
We send Google only public page paths without URL query strings or fragments and referring website origins, alongside the technical browser, device and connection information used by its analytics service. We do not send form answers, contact fields, financial data, authenticated identifiers or protected and token-bearing page paths. Advertising personalization and Google Signals are disabled. Google processes analytics data under its service terms and privacy information and may process data outside your country. Cookie lifetime is separate from data retention in the Google Analytics property. How Google uses information from sites that use its services
Fintant uses the limited Cloudflare measurement for the legitimate business purposes of understanding aggregate public-site use and improving performance. It is not used for advertising, remarketing, individual profiles, cross-site tracking, authenticated activity, booking or submission proof, or financial-work evidence. If law requires a different notice or prior choice for a visitor, Fintant will disable the technology for that context or provide the required choice before use.
5. Scheduling, meeting, and other third-party services
Fintant embeds Acuity Scheduling on the public Book a Call and request-confirmation pages for a free introductory call. Loading those pages connects the browser directly to Acuity, which may set its own cookies or browser storage under its privacy and cookie notices.
Current third-party scheduling technology.
Provider technology: Acuity PHPSESSID or equivalent provider session cookie. Purpose: Maintains the provider-side scheduling session while a visitor views availability and submits an appointment request. Observed duration: Observed provider maximum of approximately 30 days; the provider may end or replace it earlier. Access and protection: Set by app.acuityscheduling.com; observed Secure, HTTP-only, and SameSite=None. Exact provider behavior may change.
The Acuity scheduler is approved only for limited business-contact scheduling, not Client Financial Data. Users should not enter tax information, bank information, credentials, source documents, or client financial content into the public scheduling flow. A direct Acuity link is also available when the embedded service cannot be used.
6. Your choices
You can use browser controls to view, block, or delete cookies and browser storage. Blocking strictly necessary cookies or storage may prevent login, organization selection, secure form submission, or other portal functions.
Cloudflare Web Analytics does not use an analytics cookie. You can prevent its script from loading by enabling Global Privacy Control or Do Not Track in a supported browser, or by using a content blocker. These choices do not affect essential cookies, public forms, navigation, or portal access.
Use Analytics settings at the bottom of public pages to change or withdraw your Google Analytics choice. Withdrawal stops further Google Analytics collection and removes this integration’s analytics cookies from this browser. It does not delete data already collected by Google. Other optional technology that requires consent will also offer a separate choice before activation. Fintant does not sell personal information or share it for cross-context behavioral advertising.
7. Cookie duration and session termination
The duration in the inventory is a maximum or typical duration. A cookie may end earlier when:
you log out; an administrator or Fintant revokes the session; the authentication flow completes or expires; the browser clears the cookie or session storage; a security event requires session invalidation; or the service changes the relevant state.
Server-side session and authorization records may be retained separately for security, audit, dispute, and legal purposes under the Privacy Notice and applicable Client Agreement.
8. Do Not Track
Some browsers send a “Do Not Track” preference. Although there is no single accepted standard governing that signal, Fintant currently treats it as an instruction not to load Cloudflare Web Analytics. This implementation choice does not turn Do Not Track into a universal instruction for unrelated essential service functions and does not affect any right to use a legally required consent control or recognized opt-out mechanism.
9. Changes to this Notice
Fintant may update this Notice when its technology, providers, purposes, law, or choices change. Material changes will receive notice appropriate to their effect. The Notice will identify its effective date and prior material versions will be archived.
10. Contact
Privacy questions and cookie choices: privacy@fintant.ai
General support: support@fintant.ai
Mail: Fintant Inc., 73-12 35th Avenue, Suite A45, Jackson Heights, NY 11372
Do not include credentials or Client Financial Data in ordinary email.