Cookie Policy
This site runs no tracking. It sets one cookie, to remember the choice you make. Here is how that choice is asked for, recorded, and withdrawn.
Last updated 1 August 2026
The short answer
This site runs no analytics, no advertising and no tracking. It sets one cookie, and only to remember the cookie choice you make yourself.
There is no analytics tag, no advertising tag, no tracking pixel, and no session recorder. Nothing at all is written to your browser's local storage or session storage.
There is exactly one piece of content on this site that comes from another company: the Google map of our Hanoi office on the Contact page. It does not load on its own. Until you allow it, that page shows a plain address panel we drew ourselves, and Google is told nothing about your visit.
Most cookie policies exist to explain a long list of trackers. This one exists to tell you there is not one, to name the single cookie that is there, to name the single embed and how it is held back, and to explain the control we built before we had anything that needed it.
What cookies are
A cookie is a small text file a website asks your browser to store and send back on later requests. Cookies are how a site remembers that you are logged in, and also how advertising networks follow you between sites. Similar technologies, including local storage, session storage, pixels, and browser fingerprinting, do comparable jobs without using a cookie file, and the law generally treats them the same way.
What decides whether permission is needed is not the technology but the purpose. Storage that is strictly necessary to deliver something you asked for needs no permission. Everything else does, and it has to be asked for before the storing happens rather than after.
The one cookie this site sets
There is exactly one, and whether it is written at all depends on you answering the prompt.
| Name | Purpose | Type | Lifetime |
|---|---|---|---|
at_consent | Records the cookie choice you made, the time you made it, and the version of the choice it was made against, so the site can act on it and stop asking | First-party, strictly necessary | 180 days |
That is the complete list. The cookie holds no name, no email address and no identifier for you. It holds your answer. It is written only once you have answered, it is readable by us and by nobody else, it is marked SameSite=Lax so other sites cannot cause it to be sent, and on our live site it is marked Secure so it travels only over an encrypted connection.
What the site does instead of tracking is worth stating positively, because these are the choices that kept the list at one.
- Self-hosted fonts. Our two typefaces are served from our own servers. We do not use a font network, so loading a page does not disclose your visit to a font provider.
- One embed, and it cannot load itself. There are no embedded videos and no social widgets anywhere on this site. There is one map, on the Contact page, and it is not served as a frame at all: the page ships the map's address in an inert attribute and a panel we drew ourselves, and a frame is only created after you allow External content in Cookie settings or press Load map on that page. Pressing the button loads it for that visit and stores nothing.
- First-party forms only. The contact form and the newsletter form both post to our own server. They are the only places the site sends data anywhere, and they send only what you typed.
- No web storage. Nothing is written to local storage or session storage anywhere on this site.
- Server logs. Our hosting records ordinary technical request data to keep the site running and to detect abuse. This is not a cookie, it does not persist on your device, and it is not used to profile you.
The four categories, and what is in them
The prompt groups storage into four categories. The table below is built from the same definitions the prompt itself renders, so the two cannot drift apart.
| Category | What it is for | On this site today |
|---|---|---|
| Strictly necessary (always on) | Needed for the site to work and to remember the choice you make here. It cannot be switched off. | One first-party cookie holding your cookie choice, and the ordinary request data our host records to keep the site up. |
| Preferences | Would remember settings you choose, such as a language or a display preference. | Nothing. The site has no such setting yet. |
| Analytics | Would measure which pages are read and how people move through the site, so we can improve it. | Nothing. This site runs no analytics, and nothing measures your visit. |
| Marketing | Would measure which campaign brought you here, and could be used to show you our adverts on other sites. | Nothing. This site carries no advertising tag and no tracking pixel. |
| External content | Would let content hosted by another company load inside our pages. That company can see your IP address and may set its own cookies. | One Google map of our Hanoi office on the Contact page. It stays as a plain address panel until you allow this, and you can also load it once, without allowing anything, using the button on that panel. |
Three of the four are empty, and we would rather show you an empty category than invent something to put in it. They are defined anyway for a practical reason: a consent mechanism built after the thing it governs is one nobody can check, and defining the categories first means anything we add later arrives switched off instead of switched on.
How we ask, and how your answer is recorded
On your first visit a bar appears at the bottom of the page offering Accept all, Reject all, and Manage preferences. It is not a wall. It does not cover the page and it does not trap your keyboard, because a prompt that blocks reading until you decide is pressuring the decision, and a pressured decision is not freely given.
The rules we held ourselves to are the ones the earlier version of this page promised, in the same words:
- Nothing runs before you allow it. Every optional category starts off. This is enforced in code rather than by policy: a script belonging to a category is served inert and is activated only once your record allows it.
- No pre-ticked boxes. The switches in Manage preferences are unticked in the HTML we send you. A box we ticked on your behalf records our preference, not yours, and it is not consent.
- Refusing is exactly as easy as accepting. Reject all sits beside Accept all at the same size, weight and colour. One click either way.
- Closing the prompt is not consent. Dismissing it without answering leaves everything off, and we ask again next time.
- The site works either way. Nothing here is withheld, delayed or degraded because you said no.
Your answer is recorded so that we can act on it and so that we can show what you chose: the categories you allowed, the time you answered, the version the answer was given against, and whether you used Accept all, Reject all, or the preference dialog. That record lives in the at_consent cookie on your own device and nowhere else.
After 180 days we ask again rather than treating an old answer as permanent, and we ask again if we ever change what a category means. An answer given to one question is not stretched to cover a different one.
Changing or withdrawing your choice
Every page has a Cookie settings button in its footer. It opens the same dialog you saw the first time, shows what you currently allow, and lets you change any of it. Withdrawing everything is one click on Reject all.
That is a legal requirement as well as a courtesy: consent has to be as easy to withdraw as it was to give. Same dialog, same number of clicks, on every page, with no email to send and nobody to ask.
You can also delete the cookie yourself in your browser settings. Nothing on this site depends on it except our knowledge of what you decided.
Europe, Singapore, and the United States
We work with clients across all three, and their rules differ. Rather than detect where you are and apply the weakest rule that fits, we apply the strictest one to everybody. Mis-detecting somebody's country is a real failure mode, and a single standard does not have it.
- European Union and United Kingdom. The ePrivacy Directive requires consent before non-essential storage, and the GDPR requires that consent to be freely given, specific, informed and unambiguous, and as easy to withdraw as to give. That is the standard the prompt is built to.
- Singapore. The Personal Data Protection Act works on notification of purpose plus consent, with a right to withdraw on reasonable notice. The purpose of each category is stated in the prompt itself rather than buried here, and withdrawal takes effect immediately rather than on notice.
- United States. California and the newer state acts use an opt-out model for sale, sharing and targeted advertising. We do none of those, so there is nothing to opt out of. We honour the opt-out preference signal regardless: if your browser sends Global Privacy Control, the optional categories are recorded as refused without our asking, and the prompt tells you that is what happened.
Third parties and outbound links
This site links out to a small number of places, including our profiles on Clutch, GoodFirms, DesignRush, and TechBehemoths, and our Facebook and LinkedIn pages. These are ordinary links. Nothing is loaded from those sites while you are on ours, so they receive nothing until you actually click through.
Once you click, you are on their site and their cookie and privacy practices apply, not ours. We have no control over what they set. If you would rather not be tracked by them, review the settings on those platforms directly.
What happens if this changes
If we ever introduce analytics or any other non-essential cookie, the mechanism described above is what governs it. Concretely:
- This page will name the cookie, its purpose, its provider and its lifetime, before it ships rather than after.
- It will belong to one of the four categories, and it will not run until you have allowed that category.
- If the change alters what a category means, the recorded version changes with it and everyone is asked again.
- Refusing will stay exactly as easy as accepting, with no pre-ticked boxes, and the site will stay fully usable if you refuse.
To keep that honest, our build fails if a tracking script is added to the site while this page still says there is none, and it fails if a cookie is written anywhere other than the single place that writes your consent record. A separate check drives the shipped pages and verifies that the prompt appears on a first visit, that no switch arrives pre-ticked, and that Reject all is as prominent as Accept all. The commitment is enforced by code rather than by memory.
Controlling cookies yourself
Beyond the controls on this site, every major browser lets you block or delete cookies, and most offer a strict tracking-protection mode. Look under Settings, then Privacy. Several browsers and extensions can also send the Global Privacy Control signal described above, which we honour.
Blocking cookies site-wide will not break anything here. The only thing you lose is our memory of what you chose, so you will see the prompt again.
Questions
If you have a question about this policy, or you believe you have found something on this site that sets a cookie we have not named here, please tell us at hello@agiletech.vn. We would want to know.
See also our Privacy Policy for what we do with the personal data you send us.
Common questions
Does the AgileTech Vietnam website use cookies?
Why show a cookie prompt on a site that has no trackers?
How do I change or withdraw my cookie choice?
What happens if AgileTech Vietnam adds analytics later?
Does AgileTech Vietnam honour Global Privacy Control?
Does loading this website tell Google or any font provider that I visited?
What about the links to Clutch, LinkedIn and Facebook?
Still have a question?
If anything here is unclear, or you want our data processing agreement, ISO certificates, or a signed NDA before we talk, just ask. We would rather answer than have you guess.