Cookie Policy

Version 1.0.2 · Effective

Revision history (2 prior versions)
  • v1.0.1 — Promised to disable analytics for an account within 5 business days on an email request, and called past analytics never personally identifying. Slotlyy has no per-account analytics switch; corrected in 1.0.2, which points to Do Not Track and promises a reply only.
  • v1.0.0 — Initial published version. Described PostHog as funnel analytics with "no personally identifiable information" and mentioned session recording only for PHI-bearing salons; corrected in 1.0.1, which says salon booking pages may be recorded with all text and typing masked.
Engineering template — counsel review pending. This page lists every cookie and storage key Slotlyy sets, taken directly from the code. Counsel reviews it before Slotlyy publicly launches; this notice is removed once that review is done.

1. What this policy covers

This policy lists every cookie, every localStorage entry, and every sessionStorage entry that Slotlyy sets when you use the platform — whether as a client booking an appointment, a salon owner managing your tenant, or an ops moderator working through the internal platform.

Slotlyy does NOT set third-party marketing / advertising / cross-site-tracking cookies. We use PostHog for product analytics (the booking funnel, and session recordings of salon booking pages with all text and typing masked; booking and review tokens are removed from URLs before anything is sent) and you may opt-out of those at any time per §4 below.

2. Cookie + storage categories

2.1 Essential (no opt-out — required)

These cookies + storage entries are required for the platform to work. Without them you cannot sign in, complete a booking, or perform money-moving actions like a refund. You cannot opt out of these and continue using Slotlyy.

2.2 Functional (no opt-out — improves UX)

These improve the booking experience (e.g. preserving your wizard step state across a page refresh). They do not collect personal data beyond what you typed into the booking form.

2.3 Analytics (opt-out available)

PostHog product analytics — we measure aggregate booking funnel completion + drop-off, never individual identity. URL booking magic-link tokens are scrubbed before sending events (replaced with [redacted]) so analytics records that someone visited a manage/cancel/ reschedule page, never which specific booking.

On a salon's public booking pages PostHog may also record a session recording: the page layout, clicks and scrolls. All text on the page and everything you type are masked, payment windows are blocked, and network requests, console output and canvas drawings are not captured. No recording is made on the booking confirmation page, on the links used to view, cancel or reschedule a booking, or for the salons described in §5.

3. The full inventory

NameTypePurposeSet byLifetimeCategory
sb-access-tokencookieSupabase auth session token. Lets you stay signed in across page loads. Set on BOTH slotlyy.com (web) AND ops.slotlyy.com (ops) — distinct values per deployment.Slotlyy (via Supabase Auth SDK) — first-partySession (cleared on sign-out)essential
sb-refresh-tokencookieSupabase auth refresh token. Renews your session without re-entering OTP. Set on BOTH slotlyy.com + ops.slotlyy.com (distinct values).Slotlyy (via Supabase Auth SDK) — first-partySession (cleared on sign-out)essential
slotlyy-client-sessioncookieClient account JWT cookie for `/account/*` flows on slotlyy.com (booking history + saved cards + recovery surfaces). HttpOnly + Secure + SameSite=Lax. Issued after phone-OTP login on /account/login.Slotlyy (apps/web — `apps/web/src/lib/auth/client-jwt.ts:18`) — first-party30 days (sliding refresh on activity)essential
ops-impersonationcookieOps impersonation cookie on slotlyy.com — only set when an ops moderator views your tenant read-only (Bible §19.6). Never set during normal partner or client use.Slotlyy (apps/ops mints; apps/web reads) — first-party30 minutes (auto-expires)essential
slotlyy-stepupcookiePartner-portal step-up authentication factor cookie on slotlyy.com. Confirms you re-authenticated within the last 15 min before doing money-moving or auth-state actions (refunds / role changes / payout config).Slotlyy (apps/web — `apps/web/src/lib/auth/step-up.ts:45`) — first-party15 minutes (auto-expires)essential
slotlyy-onboarding-sessioncookieTenant onboarding session JWT on slotlyy.com. Set when a new tenant owner completes the signup OTP. Scoped to `/api/v1/onboarding` path only so it cannot leak to the wider app surface. Used to authenticate the multi-step onboarding wizard back to the API before the full Supabase session lands.Slotlyy (apps/web — `apps/web/src/app/api/v1/onboarding/otp/verify/route.ts`) — first-party1 hour (auto-expires; user must restart onboarding if they walk away mid-flow)essential
slotlyy-mfa-challengecookiePartner-portal 2FA bridge cookie on slotlyy.com. Short-lived hand-off between phone-OTP verification and TOTP challenge during the partner login flow when 2FA is enrolled. Scoped to `/partner/2fa` path. Only set transiently; cleared on TOTP success.Slotlyy (apps/web — `apps/web/src/app/api/v1/auth/owner/otp/verify/route.ts`) — first-party5 minutes (auto-expires after TOTP completes; supersedes the deprecated `challengeToken` JSON field per Item #13.1 SEC-009 fix)essential
slotlyy-ops-stepupcookieOps platform step-up authentication factor cookie on ops.slotlyy.com. Confirms an ops moderator re-authenticated within the last 15 min before doing privileged ops actions (refunds / KYC review / tenant state changes). Only ops-team members on @slotlyy.com emails ever receive this cookie.Slotlyy (apps/ops — `apps/ops/src/lib/ops/step-up.ts:23`) — first-party15 minutes (auto-expires)essential
slotlyy-ops-pending-logincookieOps platform 2FA bridge cookie on ops.slotlyy.com. Short-lived hand-off between email/password verification and TOTP challenge during the ops login flow. Only ops-team members ever receive this cookie.Slotlyy (apps/ops — `apps/ops/src/lib/ops/mfa-session.ts:109`) — first-party5 minutes (auto-expires after TOTP completes)essential
slotlyy-ops-mfa-sessioncookieOps platform post-2FA session cookie on ops.slotlyy.com. Proves an ops moderator completed both email/password + TOTP within the 8-hour inactivity window (Bible §19.3). Only ops-team members ever receive this cookie.Slotlyy (apps/ops — `apps/ops/src/lib/ops/mfa-session.ts:113`) — first-party8 hours (Bible §19.3 inactivity timeout)essential
__cf_bmcookieCloudflare bot-mitigation. Distinguishes humans from automated traffic.Cloudflare — third-party (proxy layer)30 minutesessential
cf_clearancecookieCloudflare bot-mitigation clearance token after a challenge.Cloudflare — third-party (proxy layer)30 minutesessential
booking-wizard-statesessionStorageBooking-wizard step state (service + staff + date + details). Lets you refresh the booking page without losing your selection.Slotlyy — first-party (sessionStorage; cleared on browser tab close)Session (cleared on tab close)functional
ph_*localStoragePostHog product analytics identity: a random ID that lets us see how the booking flow is completed and where people drop off and, on salon booking pages, links the session recording described in section 2.3. It is not your name, phone number or email. Booking and review tokens are removed from page URLs before events are sent.PostHog — third-party (default eu.i.posthog.com; configurable via NEXT_PUBLIC_POSTHOG_HOST env var)Until cleared via opt-out OR browser data clearanalytics

4. Opting out of analytics

PostHog analytics is opt-out at the browser level. Two ways to opt out:

  1. Browser Do-Not-Track signal. If your browser sends the DNT: 1 header, PostHog automatically disables tracking. This is the cleanest way — turn it on in your browser's privacy settings; the opt-out applies to every site you visit, not just Slotlyy. (Slotlyy initialises the PostHog browser SDK with respect_dnt: true in apps/web/src/lib/analytics/posthog.ts so this claim is mechanically true; lock-test asserts the flag stays set per Cardinal Rule #16.)
  2. Manual opt-out. Email [email protected] with subject "Opt-out analytics" and we will reply. Slotlyy has no per-account analytics switch yet, so Do Not Track (method 1) is the way to stop analytics collection today.

Clearing your browser's local storage will also remove the PostHog identity entry — but unless you opt out via one of the methods above, a fresh identity will be created on your next visit.

5. PHI-bearing tenants — extra restrictions

When you visit a Slotlyy booking page for a PHI-bearing tenant (a salon in one of Slotlyy's health-related business types, such as spas, massage and wellness studios and clinics — per HIPAA classification), Slotlyy mechanically disables PostHog session recording on every page of that salon via the recordingAllowed() gate. Page-view + funnel events still fire but session video is suppressed. This is a privacy hardening for the tenants most likely to be handling sensitive medical context. Recording never runs on the booking confirmation page or on the links used to view, cancel or reschedule a booking, and in any recording all text on the page and everything typed are masked. A salon whose type cannot be read is treated as PHI-bearing.

Related documents

Contact

Cookie / privacy questions: [email protected]