Version 1.0.2 · Effective
This policy lists every cookie, every localStorage entry, and every sessionStorage entry that Slotlyy sets when you use the platform — whether as a client booking an appointment, a salon owner managing your tenant, or an ops moderator working through the internal platform.
Slotlyy does NOT set third-party marketing / advertising / cross-site-tracking cookies. We use PostHog for product analytics (the booking funnel, and session recordings of salon booking pages with all text and typing masked; booking and review tokens are removed from URLs before anything is sent) and you may opt-out of those at any time per §4 below.
These cookies + storage entries are required for the platform to work. Without them you cannot sign in, complete a booking, or perform money-moving actions like a refund. You cannot opt out of these and continue using Slotlyy.
These improve the booking experience (e.g. preserving your wizard step state across a page refresh). They do not collect personal data beyond what you typed into the booking form.
PostHog product analytics — we measure aggregate booking funnel completion + drop-off, never individual identity. URL booking magic-link tokens are scrubbed before sending events (replaced with [redacted]) so analytics records that someone visited a manage/cancel/ reschedule page, never which specific booking.
On a salon's public booking pages PostHog may also record a session recording: the page layout, clicks and scrolls. All text on the page and everything you type are masked, payment windows are blocked, and network requests, console output and canvas drawings are not captured. No recording is made on the booking confirmation page, on the links used to view, cancel or reschedule a booking, or for the salons described in §5.
| Name | Type | Purpose | Set by | Lifetime | Category |
|---|---|---|---|---|---|
sb-access-token | cookie | Supabase auth session token. Lets you stay signed in across page loads. Set on BOTH slotlyy.com (web) AND ops.slotlyy.com (ops) — distinct values per deployment. | Slotlyy (via Supabase Auth SDK) — first-party | Session (cleared on sign-out) | essential |
sb-refresh-token | cookie | Supabase auth refresh token. Renews your session without re-entering OTP. Set on BOTH slotlyy.com + ops.slotlyy.com (distinct values). | Slotlyy (via Supabase Auth SDK) — first-party | Session (cleared on sign-out) | essential |
slotlyy-client-session | cookie | Client account JWT cookie for `/account/*` flows on slotlyy.com (booking history + saved cards + recovery surfaces). HttpOnly + Secure + SameSite=Lax. Issued after phone-OTP login on /account/login. | Slotlyy (apps/web — `apps/web/src/lib/auth/client-jwt.ts:18`) — first-party | 30 days (sliding refresh on activity) | essential |
ops-impersonation | cookie | Ops impersonation cookie on slotlyy.com — only set when an ops moderator views your tenant read-only (Bible §19.6). Never set during normal partner or client use. | Slotlyy (apps/ops mints; apps/web reads) — first-party | 30 minutes (auto-expires) | essential |
slotlyy-stepup | cookie | Partner-portal step-up authentication factor cookie on slotlyy.com. Confirms you re-authenticated within the last 15 min before doing money-moving or auth-state actions (refunds / role changes / payout config). | Slotlyy (apps/web — `apps/web/src/lib/auth/step-up.ts:45`) — first-party | 15 minutes (auto-expires) | essential |
slotlyy-onboarding-session | cookie | Tenant onboarding session JWT on slotlyy.com. Set when a new tenant owner completes the signup OTP. Scoped to `/api/v1/onboarding` path only so it cannot leak to the wider app surface. Used to authenticate the multi-step onboarding wizard back to the API before the full Supabase session lands. | Slotlyy (apps/web — `apps/web/src/app/api/v1/onboarding/otp/verify/route.ts`) — first-party | 1 hour (auto-expires; user must restart onboarding if they walk away mid-flow) | essential |
slotlyy-mfa-challenge | cookie | Partner-portal 2FA bridge cookie on slotlyy.com. Short-lived hand-off between phone-OTP verification and TOTP challenge during the partner login flow when 2FA is enrolled. Scoped to `/partner/2fa` path. Only set transiently; cleared on TOTP success. | Slotlyy (apps/web — `apps/web/src/app/api/v1/auth/owner/otp/verify/route.ts`) — first-party | 5 minutes (auto-expires after TOTP completes; supersedes the deprecated `challengeToken` JSON field per Item #13.1 SEC-009 fix) | essential |
slotlyy-ops-stepup | cookie | Ops platform step-up authentication factor cookie on ops.slotlyy.com. Confirms an ops moderator re-authenticated within the last 15 min before doing privileged ops actions (refunds / KYC review / tenant state changes). Only ops-team members on @slotlyy.com emails ever receive this cookie. | Slotlyy (apps/ops — `apps/ops/src/lib/ops/step-up.ts:23`) — first-party | 15 minutes (auto-expires) | essential |
slotlyy-ops-pending-login | cookie | Ops platform 2FA bridge cookie on ops.slotlyy.com. Short-lived hand-off between email/password verification and TOTP challenge during the ops login flow. Only ops-team members ever receive this cookie. | Slotlyy (apps/ops — `apps/ops/src/lib/ops/mfa-session.ts:109`) — first-party | 5 minutes (auto-expires after TOTP completes) | essential |
slotlyy-ops-mfa-session | cookie | Ops platform post-2FA session cookie on ops.slotlyy.com. Proves an ops moderator completed both email/password + TOTP within the 8-hour inactivity window (Bible §19.3). Only ops-team members ever receive this cookie. | Slotlyy (apps/ops — `apps/ops/src/lib/ops/mfa-session.ts:113`) — first-party | 8 hours (Bible §19.3 inactivity timeout) | essential |
__cf_bm | cookie | Cloudflare bot-mitigation. Distinguishes humans from automated traffic. | Cloudflare — third-party (proxy layer) | 30 minutes | essential |
cf_clearance | cookie | Cloudflare bot-mitigation clearance token after a challenge. | Cloudflare — third-party (proxy layer) | 30 minutes | essential |
booking-wizard-state | sessionStorage | Booking-wizard step state (service + staff + date + details). Lets you refresh the booking page without losing your selection. | Slotlyy — first-party (sessionStorage; cleared on browser tab close) | Session (cleared on tab close) | functional |
ph_* | localStorage | PostHog product analytics identity: a random ID that lets us see how the booking flow is completed and where people drop off and, on salon booking pages, links the session recording described in section 2.3. It is not your name, phone number or email. Booking and review tokens are removed from page URLs before events are sent. | PostHog — third-party (default eu.i.posthog.com; configurable via NEXT_PUBLIC_POSTHOG_HOST env var) | Until cleared via opt-out OR browser data clear | analytics |
PostHog analytics is opt-out at the browser level. Two ways to opt out:
DNT: 1 header, PostHog automatically disables tracking. This is the cleanest way — turn it on in your browser's privacy settings; the opt-out applies to every site you visit, not just Slotlyy. (Slotlyy initialises the PostHog browser SDK with respect_dnt: true in apps/web/src/lib/analytics/posthog.ts so this claim is mechanically true; lock-test asserts the flag stays set per Cardinal Rule #16.)Clearing your browser's local storage will also remove the PostHog identity entry — but unless you opt out via one of the methods above, a fresh identity will be created on your next visit.
When you visit a Slotlyy booking page for a PHI-bearing tenant (a salon in one of Slotlyy's health-related business types, such as spas, massage and wellness studios and clinics — per HIPAA classification), Slotlyy mechanically disables PostHog session recording on every page of that salon via the recordingAllowed() gate. Page-view + funnel events still fire but session video is suppressed. This is a privacy hardening for the tenants most likely to be handling sensitive medical context. Recording never runs on the booking confirmation page or on the links used to view, cancel or reschedule a booking, and in any recording all text on the page and everything typed are masked. A salon whose type cannot be read is treated as PHI-bearing.
Cookie / privacy questions: [email protected]