Legal
Cookies
Every cookie Tappa sets, what it is for and how long it lasts. Tappa sets no advertising or analytics cookie and embeds nothing from another site.
The cookies Tappa sets
All of them are necessary to sign in and to record a shift. There is no advertising cookie, no analytics cookie and nothing embedded from another site — every stylesheet, typeface and script this product loads is served from this domain, so no third party is contacted by opening a page.
| Name | What it is for | Lifetime | Sent to | Attributes |
|---|---|---|---|---|
| tappa_session | Remembers which employee this phone belongs to, so a tap at a plaque knows who tapped. Set once, when the personal invitation link is opened. | 365 days | / | HttpOnly · SameSite=Lax · Secure |
| tappa_activation | Carries the invitation while that one page is being completed, so the code stays out of the address bar, out of browser history and out of any link that leaves this site. Cleared as soon as the invitation is used. | 15 minutes | / | HttpOnly · SameSite=Lax · Secure |
| tappa_admin_session | Keeps a manager signed in to the dashboard. A separate cookie from the employee one, sent only to the dashboard, so neither can be used in the other's place. | 12 hours | /admin | HttpOnly · SameSite=Lax · Secure |
| tappa_admin_login | Protects the dashboard sign-in form against being submitted from another site. Exists only while somebody is on the sign-in page. | 15 minutes | /admin | HttpOnly · SameSite=Lax · Secure |
| tappa_admin_choice | Set only when one person manages more than one organisation: it carries the choice being offered, signed by this server, between the password step and the pick-a-business step. | 5 minutes | /admin | HttpOnly · SameSite=Lax · Secure |
| tappa_admin_confirm | Set for a moment when a manager is asked to confirm something that cannot be undone, so the confirmation belongs to that manager, that session and that one action. | 10 minutes | /admin | HttpOnly · SameSite=Lax · Secure |
| tappa_admin_reset | Protects the 'I cannot get in' form against being submitted from another site. Exists only while somebody is on that page. | 15 minutes | /admin | HttpOnly · SameSite=Lax · Secure |
| tappa_admin_reset_link | Carries a recovery link while a new password is being chosen, so the link stays out of the address bar and out of browser history. Cleared as soon as the link is used or refused. | 1 hour | /admin/reset/new | HttpOnly · SameSite=Lax · Secure |
| tappa_signup | Protects the registration form against being submitted from another site. Exists only while somebody is filling the form in. | 30 minutes | /signup | HttpOnly · SameSite=Lax · Secure |
| tappa_signup_state | Carries the answers already given — the business name, the VAT number and the places — from one step of the registration form to the next, signed by this server. It never holds a password. Cleared as soon as the business is created. | 30 minutes | /signup | HttpOnly · SameSite=Lax · Secure |
Secure is set whenever Tappa is served over https, which is every deployment that is not a developer's own machine. HttpOnly means no page script can read the value.
This text has not been published yet
Nothing on this page is in force. It is a placeholder so the document has an address before it has a text, and it will be replaced with the real one — no part of it should be relied on in the meantime.
Waiting on
- The controller and contact point, as for the privacy policy.
- Confirmation of the legal basis: these cookies are the ones without which the service cannot be delivered, which is the basis this document will state.