Cookie Policy
Version: 1.0
Last updated: August 20, 2026
Effective date: September 1, 2026
Website: https://www.hisicar.com
1. Scope
This Cookie Policy explains how Shanghai Sitou Technology Co., Ltd. and the specifically identified HISICAR entity use Cookies and similar technologies on the HISICAR website.
It covers HTTP Cookies, local and session storage, device identifiers, pixels, SDK storage and server-side events linked to a browser, device, account or anonymous identifier. The Privacy Policy explains the related Personal Data processing.
Continuing to browse is not consent to non-essential technologies where consent is required.
2. Categories
2.1 Strictly necessary
These technologies provide authentication, security, session continuity, fraud prevention, load management or a function expressly requested by the user. They cannot be disabled through the consent manager. Blocking them in the browser can prevent login, account, payment or support functions.
2.2 Functional
These remember language, user-requested likes and other optional preferences. They are enabled after a user requests the function and, where local law requires, after consent.
2.3 Analytics and recommendation
These measure use or connect activity to recommend vehicles. They are off by default until valid consent in jurisdictions requiring prior consent. A non-personalised browsing path remains available where required.
2.4 Marketing and attribution
These attribute visits, inquiries or conversions to a campaign, agent or referral partner, or support targeted advertising. They are non-essential and are off by default until valid consent where required.
3. Current first-party Cookies
The current HISICAR website uses the following first-party Cookies. Duration is measured from creation or the most recent permitted refresh.
| Cookie | Category | Purpose | Duration |
|---|---|---|---|
hisicar-access-token |
Strictly necessary | Authenticated session access | Current default: 30 minutes; the configured token period applies |
hisicar-refresh-token |
Strictly necessary | Secure renewal of an authenticated session | Current default: 14 days; the configured token period applies |
hisicar-auth-challenge |
Strictly necessary | Temporary email or WhatsApp authentication challenge | 10 minutes |
hisicar-auth-mfa |
Strictly necessary | Temporary MFA verification or enrolment | 10 minutes |
hisicar-auth-return-to |
Strictly necessary | Safe internal return path after authentication | 10 minutes |
hisicar-support-session-claim |
Strictly necessary for requested chat | Connects a user-requested anonymous support session after login | 30 minutes |
hisicar-locale |
Functional | Remembers language selection | 1 year |
hisicar-liked-vehicles |
Functional | Remembers vehicles actively liked by an unauthenticated user | 1 year |
hisicar-anonymous-id |
Functional and analytics/recommendation | Maintains requested anonymous interactions and can link activity/recommendation events | 1 year; non-essential use requires consent where applicable |
hisicar-ref-code |
Marketing/attribution | Attributes an inquiry or support session to a referral partner | 90 days |
Authentication and anonymous-support Cookies are HttpOnly, use SameSite controls and use the Secure flag in production where configured. A security attribute does not by itself make a Cookie legally necessary.
4. Purpose separation for the anonymous identifier
The anonymous identifier can support both a feature requested by a user, such as an anonymous support session or liked-vehicle state, and non-essential recommendation measurement.
The identifier must not be used for analytics or recommendation in an opt-in jurisdiction unless technical purpose separation, a functioning consent interface and server-side consent enforcement are operational. Until those controls are verified, it may be used only for the specifically requested function and security, and export to a recommendation or analytics service remains disabled.
After account login, authorised anonymous activity may be associated with the account to preserve the requested support or vehicle interaction. The Privacy Policy explains this linkage and the available rights.
5. Third-party technologies
Third parties may receive device/browser information or set their own technologies only when the relevant feature is enabled or requested.
| Provider or feature | When activated | Typical purpose and information |
|---|---|---|
| Stripe | The Buyer opens an eligible Stripe checkout | Secure checkout, authentication, fraud prevention, payment, refund and dispute; device, IP, checkout and transaction data |
| The user chooses Google sign-in | Authentication, security and approved identity claims | |
| Apple | The user chooses Sign in with Apple | Authentication, security and approved identity claims |
| The user chooses WeChat website login | QR/login authentication and approved profile claims | |
| Telegram | Only if Telegram Login is enabled and chosen | OIDC/widget authentication and separately approved permissions |
| Google Maps | Only if a map component is enabled and loaded | Map display, place search, routing, IP/device interaction and optional location |
| Embedded media or social links | The user activates the embed or follows the link | Content delivery and the provider’s own measurement/security |
WhatsApp Business support is ordinarily opened through a link or used through message delivery rather than treated as a general website tracking Cookie. The provider still processes account, telephone, device and message information under its own policy.
The Third-Party Services Notice provides service-specific information and links to provider policies.
6. Consent in opt-in jurisdictions
Where prior consent is required, HISICAR does not enable optional Cookies, scripts or server-side exports unless the consent interface is operational. That interface must provide:
- Accept all;
- Reject non-essential; and
- Manage choices.
The choices must be equally clear. Non-essential categories must not be preselected. The website must not use misleading colour, size, placement, repeated prompts or an unrelated consent wall.
The consent record must include:
- category choices;
- consent-policy and vendor-list version;
- date and time;
- region used to select the consent rule;
- consent identifier; and
- withdrawal or change history.
When optional technologies are enabled, withdrawal must remain available through a persistent Cookie Settings control and must be as easy as acceptance. Withdrawal stops future non-essential collection and transmission to the relevant provider. Where these controls are not operational, optional technologies must remain disabled. Data already processed is handled under the Privacy Policy and applicable law.
7. Other regional models
Where local law permits a notice or opt-out model, HISICAR still:
- gives this notice before or at collection;
- provides category controls;
- honours applicable universal opt-out or browser signals for the activities within their legal scope;
- does not use an inaccurate IP-region inference to reduce legal rights; and
- applies the more protective setting when the applicable rule is uncertain.
8. Login and payment choices
Selecting a third-party login or payment button is a request to use that core feature. Before redirecting or loading the feature, HISICAR identifies the provider and links the relevant notice.
Only technologies necessary to complete the requested login or payment are treated as necessary. Optional advertising or analytics offered by a provider is not automatically necessary merely because it appears in the same service.
9. Google Maps and location
Google Maps is loaded only where the feature is enabled and permitted by the user’s consent settings. In a prior-consent jurisdiction, optional map scripts and storage remain blocked until consent unless a documented local exception applies.
Precise device location requires an affirmative user action and browser/device permission. Rejecting location does not prevent text entry of an address, port, store or warehouse where that alternative is reasonably available.
HISICAR does not use a map permission for continuous background tracking.
10. Browser and device controls
Most browsers allow a user to view, block and delete Cookies. Blocking strictly necessary Cookies can prevent login, MFA, secure checkout, account or anonymous support. Deleting functional Cookies resets language and liked-vehicle preferences. Rejecting analytics or marketing does not prevent public browsing, inquiry or purchase.
Browser controls operate separately from the HISICAR consent record. After deleting Cookies, a user may need to set preferences again.
11. Retention and deletion
Each Cookie expires according to Section 3 or earlier when the purpose ends. Authentication and temporary-state Cookies are deleted on logout or completion where the implementation permits. Server-side records connected to a Cookie follow the Privacy Policy retention schedule and are not kept merely because a Cookie identifier once existed.
12. Updates and audits
HISICAR scans the production website at least quarterly and after adding or changing a tag, SDK, login, payment method, embedded service, map or analytics provider.
An unknown technology is blocked until it is identified, assessed, classified and added to this Policy and the consent manager. A material new non-essential purpose requires renewed consent where applicable.
Prior versions are available on request from info@hisicar.com.
13. Contact
Questions or requests about Cookies may be sent to info@hisicar.com.