Cookie Policy
Effective date: 2026-08-02
This policy explains cookies and similar browser storage used by ExcuseMe. Contact privacy@excuseme.pro.
1. Current rule
ExcuseMe currently uses first-party storage for authentication, security, ordering, language/accessibility preferences and a user-requested OAuth/loyalty flow. We do not currently set advertising or cross-site analytics cookies.
Our assessment is that the listed storage is necessary for a service the user requests or for security. We will not enable non-essential analytics or advertising storage without any prior-consent mechanism required in the relevant country.
2. Cookies
| Cookie/category | Purpose | Typical lifetime |
|---|---|---|
| Supabase authentication cookies | Secure staff/customer sign-in and token refresh | up to 30 days, rolling while used |
em_session_id | HttpOnly proof of the QR/NFC ordering session and access to order/tab status | fixed 24 hours |
em_fraud_device | Random opaque first-party anti-abuse identifier; it is not derived from browser/device characteristics | fixed 90 days, not extended on read |
NEXT_LOCALE, NEXT_CUSTOMER_LOCALE | Separate staff and guest language choice | 1 year |
| theme, font-size and staff-palette cookies | Requested display/accessibility preference | 1 year |
em_active_tenant | Venue selected by a multi-venue admin | up to 180 days; cleared on sign-out or reset |
em_auth_return, signup-intent/token cookies | Return safely from sign-in or a requested invitation/signup flow | about 10 minutes; an invitation token may last up to its stated validity |
Exact Supabase cookie names can vary by project. Authentication cookies are Secure in production where appropriate, SameSite-scoped and server-only where the library supports it.
3. Other browser storage
sessionStorageholds the current cart/order session (em_session) and a short-lived AI chat-session reference scoped per venue (em_chat_session_id:<venue>) for the current tab. It clears when the browser tab/session ends, subject to browser behaviour.localStoragemay hold: an "active order" marker (em_active_order:<venue>:<code>) that stores your just-placed order id so we can show a link back to its status, and which self-expires after 24 hours; a debug preference in non-production use; and a pending loyalty opt-in selected immediately before Google sign-in. The pending loyalty value is used only to finish that requested flow and is removed after success; no loyalty processing begins unless server-side evidence is recorded.- For staff and venue-admin users,
localStoragealso remembers interface layout preferences (such as sidebar width, which sections are expanded, saved table column widths, and the last-opened settings tab). These are display conveniences only and hold no personal data about guests. - Service-worker/cache storage may cache application assets and public menu resources for reliability; authenticated responses and secrets must not be deliberately cached for offline sharing.
4. Control
Browser controls can delete or block storage. Blocking authentication or ordering storage may prevent sign-in, cart continuity, QR ownership checks, tabs or order-status access. Language, theme and font-size cookies can be reset in the interface or browser.
5. Provider content
Google OAuth, when activated and deliberately opened, may set its own cookies on its domains under its notices. We do not treat those as ExcuseMe advertising cookies. Venue subscriptions are invoiced by us and settled by bank transfer, so no third-party checkout is opened and none of its cookies are set. Embedded third-party marketing media must not be added without a new assessment and any required consent control.
We will update this policy before materially changing storage purposes or enabling a non-essential category.