Privacy & Cookies

Cookie Policy

Learn how EliteHMS uses cookies and local browser storage to secure your session and optimize dashboard performance.

1. What Are Cookies?

Cookies are small text files stored on your browser or device when you visit websites. EliteHMS uses strictly necessary cookies and browser storage to maintain secure staff logins, restore sessions, and remember interface preferences.

2. Cookies We Use

httpOnly Refresh Token Cookie (Strictly Necessary)

Purpose: Stores a 30-day encrypted refresh token that silently restores your logged-in session when you open the app, avoiding constant password re-entry during busy work weeks.

Duration: 30 days • Type: httpOnly, Secure
Access Token (Local Storage)

Purpose: Short-lived 15-minute JWT access token used by your browser to authenticate API calls to our backend servers.

Duration: 15 minutes • Type: LocalStorage
Theme & Navigation Preferences (LocalStorage)

Purpose: Stores your chosen color theme (light/dark) and sidebar module visibility customizations.

Duration: Persistent • Type: LocalStorage

3. Analytics & Third-Party Cookies

On our marketing website (www.elitehms.online), we use privacy-focused analytics (Google Analytics / Microsoft Clarity) to understand page visits and improve our documentation. No clinical or patient data is ever sent to analytics providers.

4. Managing Cookies

You can clear cookies and local storage through your web browser settings at any time. Note that clearing strictly necessary session cookies will require re-authenticating with your account credentials.