Cookie Policy
Last updated: 01 July 2026
This Cookie Policy explains how DSource360 Engineering And Trading, trading as DSource360 (“DSource360,” “we,” “us,” or “our”), uses cookies and similar technologies on https://www.dsource360.com.
It should be read together with our Privacy Policy.
1. What Are Cookies?
Cookies are small data files stored on or accessed from a visitor’s device when a website is used.
Cookies and similar technologies may help websites:
- Operate correctly;
- Maintain secure sessions;
- Remember preferences;
- Understand website usage;
- Measure performance;
- Display external content; and
- Support advertising or campaign measurement.
Similar technologies may include:
- Local storage;
- Session storage;
- Pixels;
- Tags;
- Software development kits;
- Device identifiers;
- Embedded scripts; and
- Server-side tracking identifiers.
In this Cookie Policy, “cookies” includes these comparable technologies unless the context requires otherwise.
2. Cookie Categories
DSource360 classifies cookies and similar technologies into the following categories.
2.1 Strictly Necessary
These technologies are required for the website to operate securely or provide a feature explicitly requested by the visitor.
They may support:
- Website security;
- Load balancing;
- Session management;
- Form submission;
- Fraud or abuse prevention;
- Cookie-consent storage;
- Language or accessibility choices;
- Administrative authentication; and
- Essential network functions.
Strictly necessary technologies cannot normally be disabled through the cookie-preference interface because the website may not function correctly without them.
They should not be used for unrelated analytics, profiling, or advertising purposes.
2.2 Preferences and Functionality
These technologies remember optional choices and improve website functionality.
They may remember:
- Theme selection;
- Language;
- Region;
- Display preferences;
- Previously selected services; or
- Optional interface settings.
Where required by applicable law, these technologies will be disabled until consent is provided.
2.3 Analytics and Performance
These technologies help us understand how visitors use the website.
They may collect information about:
- Pages visited;
- Visit duration;
- Navigation paths;
- Referring sources;
- Device and browser types;
- Website errors;
- Performance metrics;
- Campaign attribution; and
- Aggregated interaction events.
Analytics should be configured to minimize data collection where reasonably possible.
Where consent is required, analytics scripts will not load or transmit analytics events until the visitor accepts the Analytics category.
2.4 Marketing and Advertising
These technologies may be used to:
- Measure advertising campaigns;
- Attribute conversions;
- Limit repeated advertisements;
- Build or use audience segments;
- Support remarketing;
- Track interactions across websites or services; or
- Personalize promotional content.
Marketing and advertising technologies must remain disabled unless and until the visitor provides the required consent.
2.5 Embedded Media and External Services
The website may contain embedded content or components from third-party services, such as:
- YouTube or other video providers;
- Vimeo;
- Google Maps;
- Social-media feeds;
- Calendars;
- Chat widgets;
- External forms;
- App-store badges;
- Animation or media delivery services; and
- Other interactive integrations.
These services may place cookies or receive technical information when loaded.
Where required, the embedded component should initially display a privacy placeholder and load only after the visitor accepts the applicable category.
3. Cookies We Use
The production website must maintain an accurate cookie register. The production cookie register must be kept accurate. As of the Foundation/legal launch of the corporate website, the following first-party technologies are expected:
| Cookie or technology | Provider | Category | Purpose | Duration | First/third party |
|---|---|---|---|---|---|
| `dsource-theme` (localStorage) | DSource360 | Preferences | Remembers theme choice when Preferences consent is granted | Until cleared | First party |
| `ds_cookie_consent_v1` (localStorage) | DSource360 | Strictly necessary | Stores consent choices | Up to 12 months | First party |
No analytics or marketing cookies are active on the corporate site until an approved vendor and consent UX (OD-009) are enabled. Do not list inactive third-party cookies as current.
4. Cookie Consent
When a visitor first accesses the website, DSource360 will present a cookie-consent interface where legally required.
Before the visitor makes a choice:
- Strictly necessary technologies may operate;
- Analytics scripts must remain blocked;
- Marketing scripts must remain blocked;
- Advertising pixels must remain blocked;
- Optional personalization scripts must remain blocked;
- Third-party videos and maps should remain blocked where they transmit visitor data; and
- No non-essential consent category should be preselected.
The visitor should be offered:
- Accept All;
- Reject Non-Essential; and
- Customize.
Rejecting non-essential cookies must not prevent access to ordinary website content, except where a feature genuinely depends on the rejected third-party technology.
5. Changing or Withdrawing Consent
Visitors can change or withdraw their consent at any time through the Cookie Settings link in the website footer.
When consent is withdrawn:
- Future non-essential scripts in the relevant categories must stop loading;
- Optional cookies should be deleted where technically possible;
- The new preference should be stored;
- The withdrawal should be recorded; and
- The visitor should not face a more difficult process than the process used to provide consent.
Withdrawing consent does not make earlier processing unlawful where that processing was based on valid consent at the time.
6. Browser Controls
Visitors may also use browser settings to:
- Block cookies;
- Delete stored cookies;
- Clear local storage;
- Restrict third-party cookies; or
- Receive warnings before cookies are stored.
Blocking all cookies may affect security, form processing, preferences, or other website features.
Browser controls do not replace the website’s consent mechanism where prior consent is legally required.
7. Third-Party Technologies
Third-party providers may process information according to their own privacy and cookie policies.
DSource360 should review providers before deployment and should avoid activating unnecessary trackers.
Third-party technologies used in production may include:
- our hosting provider (to be named when contracted);
- our CDN/security provider (to be named when contracted);
- an analytics provider (none active until OD-009 consent UX ships);
- our email/form delivery provider (to be named when contracted);
- a video provider (blocked until consent where required);
- a maps provider (blocked until consent where required);
- a customer-support provider (to be named when used);
- an advertising provider (none active until approved); and
- DSource360 first-party consent storage (or a named CMP if later approved).
The production version of this policy must identify actual providers rather than retaining generic placeholders.
8. Retention of Consent Records
DSource360 may retain a record of:
- The visitor’s consent selection;
- Consent timestamp;
- Policy or consent-interface version;
- Categories accepted;
- Categories rejected;
- Approximate region or consent regime; and
- A pseudonymous consent identifier.
Consent records should be retained only for as long as reasonably necessary to demonstrate compliance and manage the visitor’s preferences.
9. Changes to This Cookie Policy
We may update this Cookie Policy when:
- Cookies are added or removed;
- A service provider changes;
- Website features change;
- Retention periods change;
- Consent requirements change; or
- Applicable laws or regulatory guidance change.
The updated version will be published with a revised “Last updated” date.
10. Contact
Questions about our use of cookies may be sent to:
DSource360 Engineering And Trading Trading as DSource360 Email: dsource360@gmail.com Address: B5, House- 8, Avenue-1, Block-A, Mirpur-10, Dhaka-1216 Website: https://www.dsource360.com
Developer Implementation Specification — OD-009
A. Default Consent State
On the visitor’s first page load:
```text necessary = granted preferences = denied analytics = denied marketing = denied embedded_media = denied ```
No script assigned to a denied category may execute before consent.
B. Consent Banner
The first layer should contain:
Heading: Your Privacy Choices
Message: We use essential technologies to operate and secure this website. With your permission, we may also use analytics, preference, embedded-media, and marketing technologies. You can accept all, reject non-essential technologies, or manage each category.
Buttons:
- Accept All
- Reject Non-Essential
- Customize
The Accept All and Reject Non-Essential actions should have comparable prominence and accessibility.
C. Preference Centre
The second layer should provide individual controls for:
| Category | Default | User control |
|---|---|---|
| Strictly necessary | Enabled | Locked |
| Preferences | Disabled | Toggle |
| Analytics | Disabled | Toggle |
| Marketing | Disabled | Toggle |
| Embedded media | Disabled | Toggle |
Each category must have a plain-language explanation and an expandable list of actual providers and technologies.
D. Consent Storage
Store:
```json { "consentVersion": "version identifier", "timestamp": "an ISO-8601 timestamp", "necessary": true, "preferences": false, "analytics": false, "marketing": false, "embeddedMedia": false, "region": "an optional region code", "consentId": "a pseudonymous identifier" } ```
Do not store names, email addresses, or unnecessary personal information in the consent cookie.
E. Script-Control Rules
Use explicit consent gating.
Example conceptual mapping:
```text Google Analytics / Firebase Web Analytics → analytics Meta Pixel / Google Ads / LinkedIn Insight → marketing YouTube / Vimeo iframe → embedded_media Google Maps → embedded_media or preferences Theme and language storage → preferences CSRF, consent and security cookies → necessary ```
Third-party scripts must not be placed directly in the global layout without a consent wrapper.
F. Google Consent Mode
Where Google services are used, initialize optional consent states as denied before loading or sending measurement data.
Update the relevant consent state only after the visitor’s action.
Consent Mode must not be treated as a replacement for script blocking where prior consent is required.
G. Embedded Video and Maps
Before consent, display a local placeholder containing:
```text This content is provided by the relevant service provider. Loading it may allow the provider to process information about your device and activity.
[Allow and Load Content] ```
Selecting the button should:
- Obtain consent for the relevant category;
- Store the updated preference;
- Load the requested content; and
- Update other components governed by the same accepted category.
H. Consent Withdrawal
Add a persistent Cookie Settings link in the footer.
When a category changes from accepted to rejected:
- Stop future scripts and network calls in that category;
- Remove known first-party optional cookies;
- Call available provider opt-out or reset methods;
- Prevent the scripts from loading on subsequent navigation;
- Save the updated consent record; and
- Refresh the affected page components if necessary.
I. Consent Renewal
Request consent again when:
- The consent model materially changes;
- A new processing purpose is introduced;
- A new material provider or category is added;
- The policy version requires renewed consent; or
- The existing consent record reaches the counsel-approved expiration period.
Do not repeatedly display the banner merely to pressure visitors into accepting.
J. Accessibility Requirements
The banner and preference centre must:
- Be fully keyboard accessible;
- Trap focus correctly when presented as a modal;
- Provide visible focus states;
- Use semantic buttons;
- Include accessible labels;
- Support screen readers;
- Meet production contrast requirements;
- Avoid relying only on colour;
- Respect zoom and responsive layouts; and
- Allow dismissal only through a valid consent choice where consent is required.
K. Audit and Quality Assurance
Before production release:
- Run a clean-browser cookie scan;
- Test before any choice;
- Test Accept All;
- Test Reject Non-Essential;
- Test each custom category combination;
- Test withdrawal;
- Test consent expiration;
- Test private/incognito mode;
- Test embedded videos and maps;
- Test analytics debug mode;
- Test navigation without a full page reload;
- Test mobile and desktop;
- Verify no analytics request fires before consent;
- Verify no marketing pixel fires before consent;
- Verify consent preferences survive appropriate navigation;
- Verify the cookie table matches production;
- Record the policy and consent-interface version; and
- Repeat the audit after every material third-party integration.
L. Content Management Requirements
The CMS should allow authorized administrators to maintain:
- Privacy Policy text;
- Terms of Use text;
- Cookie Policy text;
- Effective dates;
- Previous policy versions;
- Cookie categories;
- Cookie names;
- Providers;
- Purposes;
- Durations;
- Policy contact information; and
- Consent-interface copy.
Legal content changes should follow a controlled publish workflow:
```text Draft → Internal Review → Legal Review → Approved → Scheduled/Published ```
Maintain an immutable or access-controlled history of published legal-policy versions.
Required decisions before publishing
Finalize these fields with your lawyer and operations team:
- Legal entity name;
- Registered business address;
- Privacy and legal email addresses;
- Governing court or district;
- Children’s minimum age;
- Actual third-party providers;
- Actual cookie inventory;
- Retention periods;
- Whether recruitment forms will be included;
- Whether Google Analytics, Meta Pixel, LinkedIn Insight, YouTube, Maps, chat, or CRM scripts will be used;
- Whether the site will actively target users in the EU, UK, Canada, California, or other regulated markets.
The policy should describe only technologies actually deployed in production. Do not publish placeholder providers or claim security controls that have not been implemented.