Legal

Sagira Cookies Policy

How Sagira uses cookies and similar technologies

Version 1.0 · Last updated August 30, 2026

Privacy Policy

What are cookies?

Cookies are small text files that websites place on your device or browser. They help websites remember your preferences, keep you signed in, maintain security, and understand how services are used. The term also covers similar technologies such as local storage and session storage in your browser, which Sagira uses as described below.

How Sagira uses cookies

Sagira uses cookies and similar storage for the following real purposes:

  • Authentication — keeping you signed in across page reloads while your session is valid.
  • Security — preventing unauthorised access and supporting step-up verification (email OTP, M-PIN, device biometrics).
  • Functionality — remembering choices such as your light/dark theme preference.
  • Anonymous first-party visit counting on the public website — to tell new visitors from returning ones and avoid double-counting.
  • Payment security — when you reach a checkout that uses Stripe, Stripe loads its own fraud-prevention cookies on the checkout page.
  • Marketing — only if an administrator explicitly enables optional advertising technology (currently Google AdSense) AND you accept Marketing cookies. Marketing cookies are off by default.

Sagira does not currently use any third-party analytics tool such as Google Analytics or the Meta Pixel. If such a tool is added later, the corresponding category must be turned on by you here before it will load.

Types of cookies

Strictly Necessary

Required for login, authentication, security, session management and core application functionality. These cannot be disabled through the optional cookie preference system when they are technically necessary — disabling them would prevent you from logging in or using Sagira.

Functional

Used to remember your choices and preferences (for example, light or dark theme) and to count anonymous visits to the public website. You can switch Functional off in Cookie Settings.

Analytics / Performance

Used to understand how visitors interact with Sagira and to improve performance. No third-party analytics technology is active on Sagira today. This category is reserved so an analytics tool can be added later — and it will only load after you opt in.

Marketing

Used for advertising and advertising measurement. Only applies if an administrator has explicitly enabled optional advertising (currently Google AdSense) and you accept Marketing cookies. Marketing cookies are off by default.

Cookie inventory

The following table lists every cookie or storage item Sagira actually uses. We do not invent cookie names; where a value is set by an infrastructure provider and its exact behaviour depends on that provider's policy, we describe it conservatively.

NameProviderCategoryDurationRequired

base44_access_token (localStorage)

Sagira authentication token. Set after login so you stay signed in across page reloads while your session is valid. Without it login cannot work.

Base44 (first-party)necessaryUntil logout or token expiryYes

token (localStorage)

Mirrored Base44 access token used by the SDK client. Removed on logout.

Base44 (first-party)necessaryUntil logoutYes

base44_app_id / base44_from_url / base44_functions_version / base44_app_base_url (localStorage)

App identity + post-login return URL the Base44 SDK persists so the auth flow can complete and return you to the right page after sign-in.

Base44 (first-party)necessarySession / persistent until clearedYes

sagira_otp_session / mpin / biometric session keys (sessionStorage / localStorage)

Short-lived step-up verification markers (email OTP verified flag, M-PIN / device biometric unlock) used during login and sensitive actions.

Sagira (first-party)necessarySessionYes

theme (localStorage)

Remembers your light/dark theme preference so the app does not flash the wrong theme on the next visit.

Sagira (first-party, next-themes)functionalPersistent until changedOptional

sagira_visitor_id (localStorage) · sagira_session_id / sagira_visit_logged_v1 (sessionStorage) · sagira_visitor_seen (localStorage)

Anonymous first-party visitor count on the public website. Used to tell new visitors from returning ones and prevent double-counting in the same browser session. No personal data, no cross-site tracking, no third-party sharing.

Sagira (first-party)functionalVisitor id: persistent · session id: session · seen/logged: persistent/sessionOptional

Stripe.js cookies (__stripe_mid, __stripe_sid) — only when you reach a Stripe checkout

Fraud-prevention identifiers set by Stripe's JavaScript on the checkout page. Required for Stripe's anti-fraud and card-payment security. Only loaded when a page actually initiates a Stripe checkout.

Stripe (third-party loaded on Sagira's domain during checkout only)necessaryUp to 1 year on the checkout origin; set by StripeYes

Google AdSense cookies — only when an administrator has enabled AdSense and configured a publisher id

Ad personalisation, ad serving and frequency capping by Google AdSense. NOT active by default. Loaded only after an admin explicitly turns AdSense on AND provides a Google AdSense publisher id, and only after you accept Marketing cookies here.

Google (third-party)marketingSet by Google per Google's cookie policy (typically up to 13 months)Optional

Analytics / Performance cookies

Sagira has no third-party analytics tool active today (no Google Analytics, no Meta Pixel, no Mixpanel). This category is reserved so additional analytics can be added later — and they will only load after you opt in here.

Not currently configuredanalyticsN/A until a tool is configuredOptional

Third-party services & external technologies

Sagira integrates with the following external services. Some of these set cookies on your browser; others are server-side API integrations or only load on specific pages (for example a payment provider that loads only at checkout).

  • Base44 Platform

    Backend-as-a-service: hosting, database, authentication, file storage, serverless functions.

    Cookies on your browser: localStorage authentication token + app param keys (see Strictly Necessary).

  • Google (Gmail, Google Calendar, Google Meet)

    Optional OAuth integrations for BPO / company users to sync their own Google Calendar and send email through their own Gmail account. Server-side API calls only.

    Cookies on your browser: Only when a user explicitly initiates a Google connection. Sagira does not use Google Sign-In popups that set Google cookies on our origin.

  • Stripe

    Payment processing for supported checkout flows.

    Cookies on your browser: Stripe.js is loaded only on Stripe checkout pages and may set __stripe_mid / __stripe_sid (fraud-prevention). See Strictly Necessary.

  • PayMongo, Maya, PayPal, Wise

    Optional payment / payout providers. Used only when a transaction selects that provider.

    Cookies on your browser: These providers live on their own domain (their cookies stay on their domain). Sagira does not embed their tracking on every page.

  • Google AdSense

    Advertising on Sagira pages — only if/when an administrator explicitly enables it.

    Cookies on your browser: When enabled AND you accept Marketing cookies, Google's adsbygoogle script loads and Google may set advertising cookies on our domain. Off by default.

  • TradingView (embedded market chart widget)

    Optional market-chart iframe on certain crypto pages.

    Cookies on your browser: Loaded as an iframe from tradingview.com; any cookies it sets are isolated to the TradingView origin, not first-party on Sagira.

  • OpenStreetMap (react-leaflet map tiles)

    Restaurant / destination map discovery.

    Cookies on your browser: Map tiles are served as images; no cookies are set on the Sagira visitor's browser by the tile server.

Changing or withdrawing consent

You can change or withdraw your optional cookie preferences at any time — no need to manually delete cookies. Use the button on this page, or the Cookie Settings link in the Sagira footer, to reopen the preferences drawer.

What happens if you reject optional cookies

Sagira continues to work normally when you reject optional cookies. You can still log in, browse, use the marketplace, use VA features, use BPO features where you are authorised, access your account, and use necessary security functions. Only optional analytics/marketing functionality may be unavailable.

Security of stored data

Where technically applicable, Sagira uses Secure and HttpOnly-appropriate transport for authentication data via the Base44 authentication platform. Sagira does not place passwords, private keys, seed phrases, or sensitive financial information in cookies. The Base44 authentication token lives in localStorage at the SDK's discretion (this is how the Base44 platform stores authentication tokens) and is cleared on logout.

Variations by jurisdiction

Cookie and privacy requirements can vary depending on your location and applicable law (for example, the Philippines Data Privacy Act, the EU/UK ePrivacy / GDPR framework, California's CCPA, and similar laws). A cookie banner alone does not make Sagira legally compliant with every jurisdiction. This policy should be reviewed by Sagira's legal or privacy professional before commercial launch in multiple jurisdictions.

Connection to our Privacy Policy

Cookie usage is part of Sagira's broader privacy practices. Please also read our Privacy Policy for the full picture of how Sagira handles your data. The two documents are intended to stay consistent; if anything appears to conflict, the Privacy Policy takes precedence for data-handling questions and this document takes precedence for cookie-specific details.

Future regional privacy requirements

Sagira intends to operate across the Philippines, ASEAN and international markets. The consent architecture is versioned and category-based so additional regional privacy requirements (for example, separate consent per purpose, retention limits, or data-export rights) can be accommodated without rewriting the system.

Privacy Policy