Cookies

Cookie policy: categories, retention, and your controls

Plain-language description of every cookie category the editorial gateway sets, the retention window we publish, and the controls available to readers at every visit.

GDPR-aligned · Reject optional · Per-category retention

What a cookie is, in plain language

A cookie is a small text file the browser stores on a reader's device at the request of the editorial gateway. The cookie carries a name, a value, an expiry, and a path. The browser sends the cookie back to the gateway on every subsequent request until expiry. Cookies cannot run code, cannot install software, and cannot read other files. They are the most common mechanism on the open web for keeping a reader signed in, for remembering a preference, and for measuring how a reader uses a site.

Three cookie categories the gateway uses

The cookies set by the editorial gateway fall into three buckets: strictly necessary cookies that keep a reader signed in and the consent record intact, optional analytics cookies that record which guides readers actually read, and optional marketing cookies that record a single click-identifier on outbound clicks to the operator. Each bucket has a published retention window, a published lawfulness basis, and a published list of identifiers.

Strictly necessary cookies, in detail

Strictly necessary cookies run the editorial gateway. They enable session management, reader authentication, CSRF protection, and the consent-recording mechanism the gateway uses to honour preferences on later visits. Strictly necessary cookies cannot be disabled in the cookie modal because disabling them breaks the consent flow on every page. The cookies persist for the session and for the consent-record window published in the table.

Strictly necessary cookies in plain English

Strictly necessary cookies are the only category the editorial gateway enables by default. They include session-management cookies that keep a reader signed in, CSRF tokens that prevent cross-site request forgery, and consent-record cookies that record a reader's cookie preferences across visits. None of these cookies process personal data beyond what is strictly needed for the cookie's purpose, and the editorial gateway does not sell or share the data with third parties for advertising or analytics.

A reader changing their browser preferences on a laptop
Per-category retention

We publish the exact retention window for each category rather than rolling them up under a single "30-day" badge.

The cookies set by the editorial gateway fall into three buckets: strictly necessary cookies that keep a reader signed in and the consent record intact, optional analytics cookies that record which guides readers actually read, and optional marketing cookies that record a single click-identifier on outbound clicks to the operator.

Analytics cookies, in detail

Analytics cookies are optional and help the editorial gateway understand which guides are useful to readers. The analytics is aggregated. The analytics does not record a reader's name, email, or contact details. The analytics records the article, the path, the device class, the rough location at the country level, and the time on each article. The analytics data is processed under a Data Processing Agreement with the analytics provider. A reader who rejects analytics cookies can still read every guide on the gateway; the rejection only removes the data collection.

Where the retention window matters

Analytics is the category where retention matters most. A 13-month retention window allows the analytics to cover a full IPL season and the post-season quiet period; a shorter window would cut the analytics off before the season ends. The 13-month figure is not a marketing claim; it is the operational window the analytics provider recommends for product analytics at editorial sites.

Marketing cookies, in detail

Marketing cookies are optional and help the editorial gateway measure outbound clicks to the operator. The marketing data is a single boolean flag set when a reader clicks the primary action button, plus a click identifier that allows us to attribute the click to the source guide. The marketing data is not used for ad targeting. The marketing data is not shared with ad networks. The marketing data is processed under a Data Processing Agreement with the marketing provider.

Marketing cookies, narrowly scoped

A click attribution flag is not a tracking pixel. The editorial gateway does not embed third-party tracking pixels, does not run cross-site retargeting, and does not sell reader data. The marketing category is limited to a single click-id cookie set on outbound clicks to the operator's app or site, and the cookie is purged at the end of the 30-day attribution window.

Published values, in one table

Cookie categories published by the editorial gateway

CategoryPurposeLawfulness basisRetentionOptional?
Strictly necessarySite operation, authentication, CSRFArticle 6(1)(f) GDPRSessionNo AnalyticsAggregated guide usageConsent13 monthsYes MarketingOutbound click attributionConsent30 daysYes Embedded mediaThird-party video, mapsConsentVariesYes PreferenceTheme, language, regionConsent12 monthsYes

Browser-level controls

Most browsers allow readers to block cookies, delete cookies, and clear cookies on demand. Browser-level controls are an alternative to the cookie settings button. The editorial gateway requires strictly necessary cookies to operate; the editorial gateway does not require analytics or marketing cookies. A reader who blocks all cookies in the browser will see a banner reminding them that strictly necessary cookies are required for the consent record and the session.

Browser controls and what they cover

A reader who clears cookies in the browser also clears the consent-record cookie the gateway uses to remember preferences. The next visit will therefore ask the reader to set preferences again. This is by design: the consent record is itself a cookie, and clearing it clears the consent record.

Where the editorial gateway stands on third-party tracking

The editorial gateway does not embed third-party ad networks. The editorial gateway does not run cross-site tracking pixels. The editorial gateway does not sell reader data. The marketing cookies the gateway publishes are limited to click attribution for outbound links to the operator. A reader who wants a fully cookie-free read can use the browser's private-mode setting; the strictly necessary cookies will still be set.

A note on third-party embeds

Where the gateway embeds a third-party video, map, or interactive component, the third party may set its own cookies. The third-party cookies are governed by the third party's own privacy policy; the editorial gateway lists the third-party providers on the privacy page and the cookie modal so a reader can block specific providers before the embed loads.

Where the cookie policy sits in the wider editorial stand

The cookie policy sits inside the wider editorial stand the editorial gateway publishes on the About page. The wider stand covers data minimisation, transparency of analytics, transparency of marketing, and the right of every reader to change preferences. The cookie policy is the operational document; the wider stand is the principle; the two are linked from the About page and from the Cookies policy. A reader who wants to verify the cookie policy against a published framework can compare the Cookies page to the wider stand and to the privacy notice.

How the editorial gateway runs the cookie audit

The editorial gateway runs the cookie audit on a quarterly cadence. The audit scans every page on the gateway, every cookie set by the gateway, and every third-party embed on the gateway. The audit produces a published report that lists every cookie, every third-party provider, and every page that uses each cookie. The audit report is published on the editorial responsibility page; the report carries the date of the audit and the date of the next audit. The audit report is the binding rule. A discrepancy between the audit report and the cookie policy triggers an update on the next refresh; the update is logged in the editorial log. A reader who wants to verify the cookie policy against the audit report can navigate to the editorial responsibility page and read the most recent report.

Frequently asked

How do I change my cookie preferences?

Use the cookie settings button at the bottom of every page or the modal that opens on first visit. Preferences persist for 12 months unless you clear them.

Do you set any advertising cookies?

We do not run third-party ad networks. Marketing cookies are limited to outbound click attribution for our editorial partners.

What happens if I reject optional cookies?

Mandatory cookies keep the gateway reachable and the consent record intact. Embeds that depend on optional categories (the YouTube match clip block, the YouTube embed on the state map page, the polished tables on the points-system page) fall back to text or static placeholders.

How long do strictly necessary cookies persist?

Session cookies persist until the browser tab closes. Authentication cookies persist for 30 days from the most recent visit.

Do you honour Global Privacy Control?

Yes. The gateway reads the GPC signal and treats it as an opt-out of optional categories.

Where is the cookie data processed?

Analytics is processed in India by the analytics provider under a DPA. Marketing data is processed by the marketing provider under a DPA with standard contractual clauses.

How do I file a privacy complaint about cookies?

Use the privacy channel listed on the Contact page. We respond within 7 days for cookie-specific requests.

Can the editorial gateway see my real name?

The editorial gateway does not collect real names. The account identifier is the mobile number; the contact channel accepts a name only when a reader writes in voluntarily.

What about the IP address?

The IP address is collected as device metadata for the bot-detection job. The IP address is not retained beyond 24 hours and is not used for analytics or marketing.

Where can I read the consent record?

The consent record is stored in a single cookie set on the editorial gateway. The reader can inspect the cookie via the browser's developer tools; the cookie name is documented on the privacy page.

Does the editorial gateway share data with the operator?

The editorial gateway shares a single click-id with the operator on outbound clicks to the operator's app or site. The click-id is used by the operator to attribute the click; no other personal data is shared.

How does the Cookies policy sit within the wider editorial network?

The cookies policy is one of the published stops in the editorial network. The wider network covers the editorial method (About), the privacy notice (Privacy), the cookie policy (Cookies), the contact channels (Contact), the DMCA procedure (DMCA), the legal framework (Legal), the editorial responsibility page, and the corrections log. Every stop in the network links to the others through the footer.

Where can I read the underlying source document?

The underlying source document is linked from the editorial log on the editorial responsibility page. The source document is the binding rule; the Cookies policy is the editorial reading. A reader who wants to verify what is written here can navigate to the editorial log and read the source document at first hand.

What if the source document changes?

A source-document change triggers an editorial-log refresh on the next editorial pass. The cookies policy is updated to reflect the change; the editorial log records the date of the change and the date of the refresh. The quarterly audit cycle picks up the change on the next pass.

Looking for what the editorial gateway does on data access?

PLAY NOW