Skip to content

Browser data · effective 15 July 2026

Cookie and browser-storage notice.

The cookies, local browser storage, offline cache, and push information used by Nabaperks.

Browser storage

CS-2026-07

Customer verification and session cookies

The HttpOnly nabaperks_pending_phone and nabaperks_pending_email cookies each last up to 10 minutes while a phone number or email is checked. After phone verification, the signed HttpOnly nabaperks_customer_session cookie normally lasts 30 days and identifies a revocable server-side customer session.

Merchant and administrator authentication

Merchant and administrator sign-in uses Supabase authentication cookies. These cookies support authenticated sessions and are refreshed or removed through the authentication flow. Their exact names and duration are controlled by the current Supabase session configuration.

Session storage

Nabaperks uses sessionStorage for short-lived information in the current browser tab or session. This includes first-party marketing-funnel continuity and rotating venue-proof selections. The funnel uses a session-only token rather than a persistent browser analytics identity.

Local storage

Local storage may hold an in-progress merchant onboarding draft, a remembered refusal of the soft location prompt, dismissal of the app-install prompt, and dismissal of the birthday-profile prompt. The birthday dismissal is reconsidered after 30 days. Other entries remain until replaced, removed by the application, or cleared in the browser. None is authoritative server-side loyalty, billing, reward, or consent state.

Offline cache

The Nabaperks service worker caches the offline page, selected icons, and static application assets. Authenticated application routes, customer state, and API requests are treated as network-only and are not used as an offline source of truth.

Push notifications and analytics

If you enable browser push notifications, Nabaperks stores the browser push endpoint and encryption keys needed to deliver messages. Erasure disables stored subscriptions and cancels queued notifications. Optional PostHog analytics is sent from the server only when pseudonymous processing is configured; the current implementation does not create a PostHog browser cookie or persistent PostHog browser identity.

Your browser controls

You can remove cookies, local storage, session storage, cached assets, and notification permissions through your browser settings. Blocking authentication or verification cookies prevents the related signed-in or identity-checking features from working. Clearing convenience storage can reset drafts, dismissals, or interface preferences without deleting server-side loyalty records.