Legal

Cookie Policy

How Tuskers.lk uses cookies and similar technologies, and how you can manage them.

2. Who we are and scope of this policy

This Cookie Policy is issued by Tuskers Digital Services (Private) Limited (referred to as Tuskers, we, us or our).

It applies to tuskers.lk, Tuskers subdomains, future Tuskers mobile applications and other digital services operated by or on behalf of Tuskers Digital Services (Private) Limited that link to this policy. These are collectively called the Tuskers Services or the Platform.

The policy applies to visitors, account holders, customers, freelancers, business service providers, business representatives and other people who use the Tuskers Services from Sri Lanka or another country.

This policy explains storage and tracking technologies. The separate Tuskers Privacy Policy explains the wider collection, use, disclosure, retention and protection of personal data. The Terms and Conditions govern use of the Platform. If this policy conflicts with a mandatory requirement of applicable law, that requirement will apply.

This policy does not govern a third-party website, application or service merely because Tuskers links to it. Once a user leaves the Tuskers Services, the third party's own terms and privacy notices apply.

3. What cookies and similar technologies are

A cookie is a small text file or identifier stored by a website in a browser or device. Cookies can recognise a browser, maintain a session, remember a choice or help measure activity.

Tuskers may also use technologies that perform similar functions:

  • local storage, which stores information in the browser and can remain after the browser is closed;
  • session storage, which normally lasts until a browser tab or session is closed;
  • pixels, tags and web beacons, which can record that a page, advertisement, link or email was viewed or used;
  • software development kits and application identifiers, which may perform similar functions in a future mobile application;
  • device, fraud and security identifiers, which help detect suspicious activity or protect transactions;
  • URL and campaign parameters, which can identify how a user reached Tuskers; and
  • server logs, which record requests, IP addresses, device or browser information and security events even when no browser cookie is stored.

Some of these technologies contain or are linked to information that can identify or distinguish a person, account, browser or device. Tuskers treats that information in accordance with the Privacy Policy and applicable data-protection law.

4. First-party, third-party, session and persistent technologies

TermMeaning
First-partySet or controlled through the Tuskers domain, even where a service provider helps Tuskers operate it
Third-partySet or received by another provider, such as Google, Meta, tawk.to, HNB, CyberSource or an authentication provider
SessionNormally deleted when the browser or relevant session closes
PersistentRemains until its stated expiry, the user deletes it, consent is withdrawn and deletion is technically possible, or the provider replaces it

Cookie duration is not the same as server-side data retention. For example, an analytics cookie may expire after a stated period while Tuskers retains associated analytics records for a shorter period. A support chat may use a session cookie, but the support record may be retained for the period stated in the Privacy Policy.

7. Google Maps and address assistance

Google Maps may help display a location, identify an area or assist with address entry. Tuskers does not intend to load Google Maps cookies or comparable identifiers until the user:

  • gives functional-cookie consent; or
  • deliberately opens or uses the map feature after being told that Google content will load.

When loaded, Google may receive IP address, browser and device information, map interactions, and the location or address entered or selected. Google may set its own cookies or use similar identifiers under Google's policies. The exact names and lifetimes can vary by Google service, login status, browser and configuration.

Tuskers does not intend to retain a user's complete Google Maps search history. Tuskers does retain the city, district, task address or other location that the user finally submits to the Platform where needed for the account or task. The precise task address remains restricted as explained in the Privacy Policy and Terms and Conditions.

If a future Tuskers application requests precise device location, Tuskers will use the device-permission prompt and provide any additional notice required before collection. Tuskers does not currently collect precise GPS location through ordinary website cookies.

8. tawk.to live chat

Tuskers uses tawk.to to provide optional live chat and support. The chat widget and its optional browser storage remain blocked until the user gives functional consent or deliberately opens the chat feature after an appropriate notice.

Once activated, tawk.to may use cookies, local storage and session storage to keep the chat connected, synchronise it across pages or tabs, recognise a returning browser and remember widget state. A technology may be essential to the chat after the user chooses to use it even though live chat is not essential to browse the rest of Tuskers.

Chat content, attachments, contact details supplied in chat and support history are personal data separate from the cookie itself. They are handled under the Tuskers Privacy Policy. Users should never send passwords, OTPs, CVVs or full card numbers through live chat.

9. Payments, fraud checks and 3-D Secure

Tuskers uses HNB and CyberSource for card-payment processing. Payment interfaces, fraud checks, card authentication and 3-D Secure may use session cookies, device information or similar technologies when a user starts checkout.

These technologies are treated as strictly necessary for the payment requested by the user. They are not activated for general advertising merely because a payment is made. The payment provider, issuing bank, card scheme or authentication service may set or receive its own identifiers under its privacy and security rules.

Full card numbers and CVVs are submitted directly to the payment gateway and are not stored by Tuskers. Tuskers may retain transaction references, payment status, receipts, refunds, commissions, payout information, fraud alerts and technical payment records as described in the Privacy Policy.

10. CAPTCHA, security challenges and social sign-in

Tuskers may use a CAPTCHA, bot-detection service or other security challenge on registration, login, contact, task or payment-related forms. The provider had not been finally selected when this policy was prepared. Tuskers will identify the provider in the live notice or update this policy when confirmed.

Security technologies may process IP address, browser and device signals, interaction timing and challenge results. Where a challenge is genuinely necessary to protect a form, account or transaction, it may operate as strictly necessary. Tuskers will limit it to the protected action and will not use the challenge itself for unrelated advertising.

If optional social sign-in is enabled, the provider is contacted only when the user selects that sign-in method. The provider may use cookies to authenticate the user and may disclose the profile information the user authorises. Ordinary email-and-password registration remains subject to the options offered by Tuskers.

11. Detailed cookie and technology register

The following register describes technologies confirmed for launch or reasonably expected for the stated Tuskers functions. Not every item is active on every page or device. First-party identifiers may use an equivalent technical name chosen during deployment, and third-party names or durations can change without Tuskers controlling that change. The category and purpose rules in this policy still apply.

Technology or identifierProviderCategoryPurpose and data involvedTypical duration
Account session or authentication identifier, name may varyTuskersStrictly necessaryMaintains a signed-in session and links requests to the correct account without placing account credentials in each page requestSession; up to 30 days only if a persistent sign-in option is offered and selected
Anti-forgery or request-integrity token, name may varyTuskersStrictly necessaryHelps prevent unauthorised form submissions, session misuse and cross-site request forgerySession or until the protected form or session expires
Security, rate-limit or infrastructure-routing identifier, name may varyTuskers and AWSStrictly necessaryProtects availability, routes requests, detects abnormal traffic and supports secure Platform deliveryUsually session to 24 hours; security logs may be retained separately
Cookie preference or consent identifier, name may varyTuskers or its consent toolStrictly necessaryRemembers optional-category choices and the relevant policy or banner versionUp to 6 months, then renewed or requested again
Checkout, payment-session, fraud or 3-D Secure identifiers, names varyHNB, CyberSource, issuing bank or card schemeStrictly necessaryOperates the payment requested by the user, helps prevent fraud and completes card authenticationUsually the checkout or authentication session; provider-controlled security records may last longer
CAPTCHA or security-challenge identifiers, provider to be confirmedSecurity providerStrictly necessary when enabled on a protected actionDistinguishes legitimate interactions from abuse using IP, browser, device and challenge signalsSession or provider-defined; the live notice will identify material persistent use
Language, interface or display preference, name may varyTuskersFunctionalRemembers an optional language or display choice on the same browserUp to 12 months unless cleared sooner
Google Maps cookies, local storage or device identifiers, names varyGoogleFunctionalLoads map content, supports address assistance and processes map interactions after consent or deliberate activationSession to persistent periods determined by Google; some Google identifiers may last up to 2 years
twk_idm_keytawk.toFunctionalManages the visitor connection and avoids unnecessary duplicate chat connectionsSession
tawk_uuid_propertyId or an equivalent property-specific UUIDtawk.toFunctionalRecognises a returning chat browser and supports continuity of the optional chat experience6 months according to tawk.to's published register
TawkConnectionTimetawk.toFunctionalSynchronises and manages chat connections, including across multiple tabsSession
twk_token_*, PreviousNav and related browser storagetawk.toFunctionalMaintains chat state, navigation context and connection behaviour after the chat feature is activatedSession storage is cleared with the tab; local storage remains until cleared or replaced under provider settings
Social sign-in authentication cookies, provider to be confirmedSocial-login providerFunctionalCompletes an optional sign-in requested by the user and returns authorised profile informationUsually session, with any persistent login controlled by the provider and user
_gaGoogle Analytics 4Analytics and performanceDistinguishes browsers or users for aggregated audience and usage measurementUp to 2 years according to Google's published GA4 cookie information
_ga_<measurement-id>Google Analytics 4Analytics and performancePersists session state for the relevant Tuskers GA4 data streamUp to 2 years according to Google's published GA4 cookie information
_fbpMeta PixelAdvertisingIdentifies a browser for advertising delivery, campaign measurement and site analytics after consent90 days according to Meta's published cookie information
Mobile-app local storage, app-instance or SDK identifiers, exact names to be stated before useTuskers and enabled app providersCategory depends on purposeProvides the website-equivalent function in a future Tuskers application; optional analytics and advertising identifiers require the applicable choice or device permissionSession or the period stated in the app notice and settings

Cookie names can contain a property, measurement or account identifier, so the displayed name may not exactly match the placeholder shown above. Tuskers will periodically review the live Platform and update this register when a new material technology, provider or purpose is introduced.

12. Information collected through these technologies

Depending on the category and user choice, Tuskers or its providers may collect:

  • IP address and an approximate country, region or city derived from it;
  • browser type and version, operating system, device type, screen information and language;
  • a cookie, app-instance, advertising, session or device identifier;
  • date, time, session duration and request information;
  • page or screen address, title, referrer and general navigation path;
  • campaign source, medium, advertisement or referral information;
  • clicks, feature interactions, form start or completion events and general task-category activity, without intentionally recording private field contents;
  • performance, crash, error, latency and network information;
  • consent choice, time and policy or banner version;
  • chat-connection information after live chat is activated;
  • map interactions after a map is activated; and
  • payment-session and fraud signals after checkout is started.

Tuskers uses this information to operate and secure accounts, provide requested features, prevent abuse, measure and improve the Platform, understand campaign performance, personalise promotions where permitted, maintain evidence of choices and comply with legal obligations.

13. Email pixels and tracked links

Tuskers uses Brevo for email and marketing communications. A promotional or operational email may contain a small pixel, a provider-hosted image or a uniquely coded link that records delivery, opening or clicking. These technologies are not always browser cookies, but they can collect similar information, such as the email campaign, date and time, IP address, device or email-client information and the link selected.

Tuskers may use this information to confirm delivery, protect accounts, measure campaign performance, avoid sending irrelevant messages and personalise future promotions where permitted. Tuskers will not use an email pixel to collect the content of unrelated emails.

A recipient can opt out of promotional email using the unsubscribe method in the message or by contacting support@tuskers.lk. Blocking remote images in an email application can prevent some open tracking but may not prevent link or delivery measurement. Necessary OTPs, security alerts, task updates, payment messages and other operational communications may continue while relevant to an account or transaction.

14. Data minimisation and sensitive information

Tuskers will take reasonable steps to avoid placing sensitive or confidential information in analytics or advertising events. In particular, Tuskers will not intentionally send the following to GA4 or Meta Pixel:

  • passwords, OTPs or security answers;
  • full card numbers or CVVs;
  • NIC or passport numbers or copies;
  • bank-account instructions;
  • full task addresses;
  • private task attachments, support messages or complaint evidence;
  • medical records, police clearances or professional-verification documents; or
  • the unrestricted contents of task forms, questions or replies.

Tuskers may use aggregated or general events, such as viewing a public page, starting registration, selecting a broad task category or completing a permitted workflow. Developers, administrators and providers must not create analytics event names or URL parameters that expose private field values.

If Tuskers discovers that sensitive information was sent to an analytics or advertising provider in error, Tuskers may disable the event, request deletion where available, correct the implementation and take any other action required by the Privacy Policy or law.

15. Third-party providers and their own practices

Third-party providers may act for Tuskers when delivering a contracted service and may also determine some processing independently, especially when a user is signed in to the provider or directly uses its feature. Their technology, locations and retention practices may change.

Provider or serviceTuskers useFurther provider information
Google Analytics 4Usage measurement after analytics consentGoogle's GA4 cookie information and Google Privacy Policy
Google MapsMap display and address assistance after functional consent or deliberate activationGoogle Privacy Policy and Google cookie information
Meta PixelAdvertising and campaign measurement after advertising consentMeta Cookie Policy and Meta Privacy Policy
tawk.toOptional live chat after functional consent or deliberate activationtawk.to cookie information and tawk.to Privacy Policy
HNB and CyberSourcePayment, fraud prevention and card authentication after checkout is requestedHNB Cookie Policy and Visa Global Privacy Notice for Visa and its affiliates
AWSHosting, infrastructure, security and Platform delivery, primarily in SingaporeAWS Privacy Notice
BrevoEmail delivery, campaign measurement and preference administrationBrevo Privacy Policy

These links are supplied for convenience. Tuskers does not control a provider's external website or guarantee that a provider will keep the same page address, cookie name or retention period.

16. International and cross-border processing

Tuskers is based in Sri Lanka and its primary AWS hosting region is Singapore. Google, Meta, tawk.to, CyberSource, Brevo, security providers, social-login providers and their subprocessors may process identifiers and related information in other countries where they operate.

Those countries may have different data-protection laws. Tuskers will seek to use lawful transfer conditions and appropriate safeguards, which may include contracts, provider due diligence, confidentiality requirements, access controls, data minimisation, encryption or other security measures.

Customers outside Sri Lanka understand that using a Sri Lankan platform and its global technology providers can involve international data processing. Further information appears in the Tuskers Privacy Policy.

18. How to manage or delete cookies

18.2 Browser and device controls

Most browsers allow users to inspect, block or delete cookies and site data. Mobile operating systems may provide advertising, tracking, location and application-permission controls. Blocking all cookies can sign a user out, prevent preferences from being remembered, stop payment authentication or make security-protected functions unavailable.

Deleting cookies can also delete the stored consent choice, causing the banner to appear again. Private or incognito browsing limits some local persistence but does not make a user anonymous to Tuskers, an internet provider or a third-party service.

18.3 Provider controls

Google, Meta and other providers may offer account, advertising or opt-out controls. For example, Google provides an Analytics opt-out browser add-on, although provider tools may not stop Tuskers from collecting information through its own necessary systems. Users should consult the provider links above for current options.

18.4 Do Not Track and universal signals

Browser Do Not Track signals are not interpreted consistently across the internet. Tuskers' Cookie Settings are the primary control for optional technologies. Where applicable law requires Tuskers to recognise a valid universal opt-out signal and the technology supports it, Tuskers will seek to apply that signal to the relevant advertising or sharing activity.

19. Effect of refusing optional technologies

A person can reject non-essential technologies and still browse public pages, create or use an account and access core task functions that do not require them.

The following limitations may apply:

  • Google Maps may not display or assist with an address until deliberately activated;
  • live chat may remain unavailable, although email, telephone or other support methods remain available;
  • language or interface choices may need to be selected again;
  • optional social sign-in may not work, requiring another offered login method;
  • Tuskers may be less able to diagnose performance issues or understand feature use; and
  • advertising may be less relevant and campaign results may not be attributed accurately.

Strictly necessary payment, security and account-session technologies can still operate when the user requests the relevant core function.

20. Children and adult-managed use

A person must be at least 18 years old to create, own or independently operate a Tuskers account. A minor may receive services only through an adult-owned and adult-controlled customer account, and a minor cannot act as a service provider.

The adult account holder is responsible for the account, cookie choices and information submitted on behalf of the minor. Tuskers does not knowingly use advertising cookies to build a personalised advertising profile about a child. If Tuskers learns that optional tracking was used in a manner inconsistent with this rule, Tuskers may disable the tracking, delete or restrict related information where reasonably possible and take other appropriate action.

21. Security and user responsibilities

Tuskers uses reasonable organisational and technical safeguards for identifiers and related data. These may include encrypted transmission, access controls, limited administrative access, monitoring, provider review and data-minimisation rules. No browser, transmission or storage system is completely secure.

Users should:

  • keep devices, browsers and applications updated;
  • protect account passwords and OTPs;
  • sign out of shared devices;
  • review browser extensions that may read site data;
  • avoid submitting sensitive information into public fields or external tracking parameters; and
  • promptly report suspected account compromise or unexpected tracking behaviour.

Tuskers will never ask a user to provide a password, OTP, full card number or CVV through a public task question, analytics form or advertising field.

22. Changes to this policy

Tuskers may update this Cookie Policy when technologies, providers, legal requirements or Platform features change. The updated policy will show a new effective or last-updated date.

If a change introduces a new non-essential purpose, materially expands tracking or otherwise requires fresh consent, Tuskers will reset or update the consent interface and request a new choice. Continued use alone does not replace consent where consent is required.

Minor corrections, clearer explanations or changes that do not alter a user's choices may be made without a new banner, although the updated policy will remain available on the Platform.

23. Contact Tuskers

Questions, requests or complaints about cookies and related personal data can be sent to Tuskers using the following details:

PurposeContact
Cookie or privacy requestshello@tuskers.lk with the subject line Cookie or Privacy Request
Platform assistancesupport@tuskers.lk
Complaints or disputescomplaints@tuskers.lk
Hotline+94 77 766 9420
Correspondence7th Floor, Sathara Building, No. 122, Avissawella Road, Maharagama, Sri Lanka

Tuskers handles privacy and cookie requests through its general company contacts rather than a named officer. It may request reasonable information to verify identity before disclosing or deleting account-related records.