This Cookie Notice explains how Fintant Inc. (“Fintant,” “we,” “us,” or “our”) uses cookies and similar browser technologies on its public website and invitation-only portal. It should be read with the Privacy Notice.
1. What cookies and browser storage are
A cookie is a small text record that a website asks a browser to store and return with later requests. Browser storage, such as session storage, lets a site retain limited information within a browser tab or session.
Fintant uses these technologies only for disclosed purposes. Some are strictly necessary to provide account security, authentication, request integrity, organization context, and core portal functionality. Optional analytics, advertising, or marketing technologies require separate approval and, where required, an appropriate consent or opt-out mechanism.
2. Current first-party inventory
The following inventory reflects the implemented application configuration reviewed on July 30, 2026. Cookie names may be environment-specific. Fintant must verify the deployed production inventory before this Notice becomes effective.
Cookie and browser storage inventory.
Name: fintant-accounting-session. Type: Strictly necessary first-party cookie. Purpose: Maintains the authenticated portal session after Fintant’s server validates the approved identity flow. Typical duration: Up to 8 hours, or earlier logout, revocation, or expiry. Access and protection: HTTP-only; SameSite=Lax; Secure in production.
Name: fintant-accounting-csrf. Type: Strictly necessary first-party cookie. Purpose: Supports cross-site request forgery protection by allowing the browser application to send a matching request header. Typical duration: Up to 8 hours, aligned to the session, or earlier logout or expiry. Access and protection: Browser-readable for header submission; SameSite=Lax; Secure in production.
Name: fintant-accounting-auth-state. Type: Strictly necessary first-party cookie. Purpose: Protects the temporary authentication callback and validates that the callback belongs to the initiating browser flow. Typical duration: About 10 minutes, or earlier completion or expiry. Access and protection: HTTP-only; limited to the authentication API path; SameSite=Lax; Secure in production.
Name: fintant-accounting:selected-organization. Type: Browser session storage. Purpose: Remembers the organization selected for display and navigation during the current browser session. Server-side authorization remains authoritative. Typical duration: Until the browser tab or session ends or the value is cleared. Access and protection: Stored in browser session storage; it is not an authentication credential.
The production deployment may use a different host prefix or additional secure attributes. The policy owner must compare this table against an authenticated browser inventory after deployment.
3. Why these technologies are necessary
The current technologies support:
invitation-only account sessions; authentication callback integrity; protection against forged state-changing requests; session expiry and revocation; organization selection and navigation; and reliable operation of the authenticated portal.
Fintant’s server independently verifies the user, organization, role, session, and authorization for protected actions. A browser-stored organization selection does not grant access.
4. Optional analytics, advertising, and marketing
As of this draft:
no third-party advertising cookies are required by the portal; no optional production product-analytics provider is approved; optional analytics must remain disabled until the provider, event allow-list, privacy review, consent class, retention, region, and opt-out controls are approved; and client financial content, credentials, tax identifiers, account numbers, internal notes, reusable file links, and message bodies must not be placed in analytics.
If Fintant later introduces optional analytics or marketing technologies, this Notice and the consent interface will be updated before activation. The updated inventory will identify the provider, purpose, data, duration, and choice available.
5. Scheduling, meeting, and other third-party services
Fintant may link to or embed an approved third-party scheduling or meeting service. A third-party service may set its own cookies or browser storage under its privacy and cookie notices.
Fintant will not enable a third-party embed for production until the provider, configuration, data flow, notice, and required choice have been approved. Users should not enter Client Financial Data, tax information, bank information, credentials, or source documents into a public scheduling flow.
If a third-party scheduling service is presented as a link rather than an embedded service, its technology generally operates after you choose to visit that provider.
6. Your choices
You can use browser controls to view, block, or delete cookies and browser storage. Blocking strictly necessary cookies or storage may prevent login, organization selection, secure form submission, or other portal functions.
Where optional technology requires consent, Fintant will provide a choice before activation and will allow withdrawal through an accessible preference control. Withdrawal will not affect processing that occurred lawfully before the preference changed.
Fintant does not currently sell personal information or share it for cross-context behavioral advertising. If a future practice is subject to a legally recognized opt-out signal, such as Global Privacy Control, Fintant will implement and describe the required handling before activation.
7. Cookie duration and session termination
The duration in the inventory is a maximum or typical duration. A cookie may end earlier when:
you log out; an administrator or Fintant revokes the session; the authentication flow completes or expires; the browser clears the cookie or session storage; a security event requires session invalidation; or the service changes the relevant state.
Server-side session and authorization records may be retained separately for security, audit, dispute, and legal purposes under the Privacy Notice and applicable Client Agreement.
8. Do Not Track
Some browsers send a “Do Not Track” preference. Because there is no single accepted standard governing that signal, the current service does not rely on it as a universal privacy instruction. This does not affect any right to use a legally required consent control or recognized opt-out mechanism.
9. Changes to this Notice
Fintant may update this Notice when its technology, providers, purposes, law, or choices change. Material changes will receive notice appropriate to their effect. The Notice will identify its effective date and prior material versions will be archived.
10. Contact
Privacy questions and cookie choices: privacy@fintant.ai General support: support@fintant.ai Mail: Fintant Inc., 73-12 35th Avenue, Suite A45, Jackson Heights, NY 11372
Do not include credentials or Client Financial Data in ordinary email.