We use essential cookies to keep you signed in and to secure checkout, and optional cookies for personalization. See our Privacy Policy and Cookie Policy.

Cookie Policy

Version 2.2 · Effective 2026-09-09

Suffle Online

Operated by Naucera Travel Private Limited

1. Purpose and Scope

This Cookie Policy explains how Suffle Online may use cookies and similar technologies on its website, web application and related digital interfaces.

It explains what these technologies do, the categories of purposes for which they may be used, how they relate to account sessions and marketplace functionality, and the choices available to users.

This Policy should be read with the Privacy Policy, Terms & Conditions, Data Security & Protection Policy and other applicable Suffle policies.

2. Company and Contact

Suffle Online is operated by Naucera Travel Private Limited.

Website: www.suffleonline.com

General Support / Grievance Email: info@flyshoppy.com

Grievance Officer: Mr. Roopal Jain, Managing Director

Grievance Officer Mobile: 9707669981

Grievance Officer Email: info@flyshoppy.com

Address: 707, N. T. Road, Nalbari-781435 (Assam), India.

3. What Are Cookies?

Cookies are small data files or similar identifiers that a website or service may store on a user's device or browser.

Cookies can help a website remember sessions, preferences, security state and other information necessary to provide or improve a service.

Similar technologies may include local storage, session storage, pixels, SDKs, tags, device identifiers and other mechanisms that perform functions similar to cookies.

4. How Suffle Uses Cookies and Similar Technologies

Suffle may use cookies and similar technologies to operate the website, maintain secure sessions, remember user preferences, support marketplace functionality, understand service performance, protect against abuse and provide relevant features.

Not every category is necessarily active at all times. The technologies actually deployed should be maintained in Suffle's central technology/privacy configuration and reflected in applicable notices.

5. Strictly Necessary Technologies

Strictly necessary technologies may be required for core functions such as login, authentication, session management, security, cart operation, checkout flow, fraud prevention, account protection, load balancing or maintaining requested functionality.

Disabling strictly necessary technologies may cause some parts of Suffle to stop functioning correctly.

6. Authentication and Account Sessions

Cookies or similar session technologies may help keep a logged-in customer or seller session active and associate requests with the correct authenticated account.

They may also support session expiry, re-authentication, security controls and protection against session misuse.

Authentication tokens and other security credentials should be handled according to Suffle's security architecture and must not be exposed to users or AI systems unnecessarily.

7. Shopping Cart and Marketplace Functionality

Cookies or local browser storage may be used to remember cart state, wishlist state, recently viewed products, selected preferences or other marketplace interactions.

Where information is tied to a logged-in account, the relevant account and privacy controls also apply.

8. Preferences and User Experience

Suffle may use technologies to remember non-sensitive preferences such as interface choices, selected location context, display preferences or other requested settings.

Preference storage should be limited to what is reasonably necessary for the stated function.

9. Security and Fraud Prevention

Suffle may use cookies, device signals and related technologies to detect suspicious activity, protect accounts, prevent automated abuse, identify session anomalies and support fraud-prevention controls.

Security-related technologies may operate even when optional preference or analytics technologies are disabled, where they are necessary to protect the service.

10. Performance and Analytics

Where enabled and lawfully permitted, Suffle may use analytics technologies to understand page performance, feature usage, errors, navigation patterns and aggregate marketplace activity.

Analytics should be configured to collect only the information reasonably required for the stated purposes and should not be represented as live or personally identifiable information when it is not.

11. Product Discovery and Personalisation

Suffle may use first-party or permitted analytics/technology signals to improve search, discovery, recommendations, recently viewed products and other marketplace experiences.

Personalisation does not guarantee that a particular product, seller or offer will appear in any particular position. Ranking and discovery are governed by the Ranking & Discovery Transparency Policy.

12. Marketing and Advertising Technologies

Where Suffle enables marketing or advertising technologies, they should be used only for the purposes and legal basis applicable to the relevant processing.

Optional marketing technologies should not be treated as strictly necessary merely for convenience.

Suffle should provide appropriate controls or consent mechanisms where required by applicable law.

13. Third-Party Technologies

Suffle may use third-party services for functions such as payment, security, analytics, communication, customer support, performance monitoring or other platform operations.

A third-party provider may place or access its own cookies or similar identifiers depending on the service configuration.

Third-party technology use is subject to the provider's applicable terms and privacy practices, in addition to Suffle's contractual and privacy controls.

14. Payment and Checkout

Payment processing is handled through Suffle's configured payment architecture and Razorpay where applicable.

Suffle should not use cookies to store card numbers, CVV, UPI PIN, ATM PIN, banking passwords or other prohibited payment credentials.

Payment confirmation and order confirmation are determined by verified payment records, not merely by browser state or a cookie.

15. Seller and Customer Separation

Cookie/session information must not be used to give a customer access to a seller account or to give one seller access to another seller's account or data.

Backend authorisation remains the primary access-control mechanism; cookies are not a substitute for server-side authentication and authorisation.

16. Connected Apps and Accounts

Cookies or session identifiers may support a legitimate connection between Suffle and an authorised provider session where applicable.

Connection status, provider access and imported information are governed by the Connected Apps & Accounts Policy.

Suffle must not use cookies to bypass provider authentication, CAPTCHA, MFA, OTP or other security controls.

17. Gmail and Email Features

Where Gmail or another email service is connected through an authorised mechanism, browser/session technologies may support the connection workflow.

Email data processing is governed by the Gmail / Email Data Policy and Privacy Policy.

Suffle must not ask users to provide an email password where a supported secure authentication method is available.

18. AI and Cookies

Suffle AI may use authorised account/session context to provide features requested by the user, subject to applicable permissions and privacy controls.

A cookie or browser identifier does not by itself authorise AI to access private account data, connected services or perform actions.

AI must not infer that a user has completed an order, payment, booking or other action solely from browser-side information.

19. Tracking and Automated Processing

Cookie and similar-technology signals may be used as one input to security, analytics, personalisation or service-performance systems.

Where Suffle uses automated processing for tracking or other purposes, the relevant processing is governed by the AI Tracking / Automated Processing Notice and Privacy Policy.

Tracking records must not be fabricated from missing cookie data.

20. Cookie Categories

Suffle may organise technologies into categories such as: Strictly Necessary; Authentication/Security; Preferences; Analytics/Performance; Personalisation; and Marketing/Advertising.

The exact categories and individual technologies deployed may change as the platform evolves.

A current cookie inventory should be maintained by Suffle rather than relying on this Policy as a fixed technical list.

21. Cookie Inventory and Governance

Suffle should maintain a central cookie/technology register identifying the technology name, provider, purpose, category, duration, first-party/third-party status and applicable consent or legal basis.

Technology changes should be reviewed through the platform's privacy/security governance process.

Unused or obsolete technologies should be removed where appropriate.

22. Duration and Expiry

Some cookies are session cookies and normally expire when the relevant browser session ends. Others may remain for a defined period according to their configured expiry.

The actual duration should be based on the technical configuration and stated purpose rather than being assumed from this general Policy.

Longer-lived identifiers should have a documented purpose and retention rationale.

23. Browser Controls

Most modern browsers provide controls to block, delete or restrict cookies and local storage.

Users may use browser settings to manage cookies, but blocking necessary technologies may affect login, cart, checkout, security or other Suffle functionality.

Browser controls may not provide the same granularity as Suffle's own consent or preference controls where such controls are available.

24. Consent and Optional Technologies

Where applicable law requires consent for optional cookies or similar technologies, Suffle should obtain and record consent through an appropriate mechanism before activating the relevant technologies.

Users should be able to withdraw or change consent through the available preference mechanism where required.

Withdrawal of consent does not invalidate processing that was lawfully completed before withdrawal.

25. Legal Bases and Personal Data

Cookies may involve personal data or information that can be linked to a user or device.

Processing of personal data is governed by Suffle's Privacy Policy and applicable Indian data-protection requirements.

The legal basis and notice requirements applicable to a particular technology depend on its actual purpose, data involved and applicable law.

26. Data Minimisation

Suffle should configure cookies and similar technologies to collect only information reasonably necessary for the stated purpose.

Identifiers should not be retained indefinitely merely because the technology permits it.

Where aggregate or less identifiable information is sufficient, Suffle should prefer that approach.

27. Security of Cookie Data

Suffle should use appropriate technical and organisational safeguards for session identifiers and other cookie-related data.

Sensitive session information should be protected against theft, fixation, replay and unauthorised disclosure through appropriate security controls.

Security practices are further described in the Data Security & Protection Policy.

28. Do Not Use Cookies for Prohibited Credentials

Suffle must not intentionally store prohibited sensitive credentials in ordinary cookies or browser storage, including passwords, OTPs, UPI PINs, CVV, ATM PINs or banking passwords.

Payment and authentication secrets must be handled through appropriate secure systems and provider mechanisms.

29. Third-Party Links and External Websites

Suffle may link to external websites or provider pages that have their own cookie and tracking practices.

Once a user leaves Suffle's controlled environment, the external provider's applicable policies may govern its technologies.

Suffle does not control every cookie or identifier used by an external website.

30. Children and Minors

Suffle's collection and use of information relating to children or minors is governed by applicable law and the Privacy Policy.

Cookie or tracking mechanisms should not be used to circumvent age-related protections or collect information from children unlawfully.

31. Cookie Misuse and Security

Users must not attempt to manipulate, forge, steal, replay or exploit Suffle cookies, session identifiers or browser storage to obtain unauthorised access or benefits.

Such activity may violate the Acceptable Use Policy and may result in security controls, suspension or other lawful action.

32. Impact on Ranking and Discovery

Where lawful and appropriately configured, technology signals may contribute to personalisation or service-performance analysis.

They do not override the central marketplace rules for seller approval, product approval, serviceability, inventory or other eligibility conditions.

Ranking and discovery factors are described in the Ranking & Discovery Transparency Policy.

33. Changes to Cookies and Technologies

Suffle may add, remove or modify cookies and similar technologies as features, security requirements, providers or legal obligations change.

Where a material change requires updated notice or consent, Suffle should provide the appropriate notice or preference mechanism.

34. Relationship with Other Policies

This Policy should be read with the Terms & Conditions, Privacy Policy, Data Security & Protection Policy, Connected Apps & Accounts Policy, Gmail / Email Data Policy, Ranking & Discovery Transparency Policy, AI Tracking / Automated Processing Notice and Suffle AI Terms.

Specialised policies may contain more specific rules for the relevant feature or data category.

35. Legal and Implementation Note

This Cookie Policy describes the intended governance framework for cookies and similar technologies. The live implementation should maintain an accurate technology inventory and should reflect the actual scripts, SDKs, local-storage mechanisms and third-party services deployed on Suffle.

Consent, notice, retention and user-choice mechanisms should be implemented according to applicable Indian law and the actual purposes of each technology.

This Policy should be reviewed by qualified Indian privacy/e-commerce counsel before publication and periodically thereafter.

36. Policy Updates

Suffle may update this Policy to reflect changes in technology, platform functionality, third-party services, security practices or applicable law.

The current effective version should be maintained through Suffle's central legal/policy management system.

Critical Cookie Rules

·       Cookies and similar technologies must not be treated as a substitute for server-side authentication and authorisation.

·       Strictly necessary technologies may be required for login, security, cart, checkout and core functionality.

·       Suffle must not intentionally store passwords, OTPs, UPI PINs, CVV, ATM PINs or banking passwords in cookies or ordinary browser storage.

·       Optional analytics, personalisation or marketing technologies should be enabled and managed according to applicable consent and privacy requirements.

·       Payment and order confirmation must rely on verified backend/payment records, not browser cookies.

·       Customer, seller and connected-account access must remain isolated through backend controls.

·       Suffle should maintain a current cookie/technology inventory rather than assuming that this Policy lists every live technology.

Related Suffle Policies

·       Terms & Conditions

·       Privacy Policy

·       Data Security & Protection Policy

·       Connected Apps & Accounts Policy

·       Gmail / Email Data Policy

·       Ranking & Discovery Transparency Policy

·       AI Tracking / Automated Processing Notice

·       Suffle AI Terms

·       Acceptable Use Policy

Cookie Management Implementation

The production Suffle application should use a central cookie/technology consent and governance mechanism where required, with documented categories, purposes, providers, durations, consent status and withdrawal controls. The implementation should be consistent across public marketplace pages, customer account areas, seller areas and checkout, without creating duplicate consent or tracking systems.