Cookie Notice
This notice explains how Covey uses cookies, local storage, OAuth state, security checks, PWA cache entries, and similar browser technologies on paycovey.com and related dashboards.
1. Cookie and storage types
Used for login, signup, owner dashboard access, PWA launch behavior, and session cookies such as protected admin or restaurant-owner sessions.
Used for Cloudflare protection, Turnstile checks, rate limiting, abuse prevention, CSRF-style flow checks, OAuth state, and replay protection.
Used for installed-app behavior, cached pages, local draft state, display preferences, and account setup progress.
Stripe Checkout may use cookies or storage to complete card verification, payment setup, billing portal, fraud checks, and payment authentication.
Covey does not currently claim Meta Pixel, TikTok Pixel, LinkedIn ads, or similar ad pixels on core pages. If enabled later, this notice will be updated and required choices will be provided.
2. Provider-specific notices
- Cloudflare: hosting, security, Turnstile, Workers, routing, and logs.
- Google: Google OAuth sign-in where the user chooses that method.
- Stripe: hosted card verification, billing, fraud prevention, receipts, and payment metadata.
- Supabase: database, auth-token records, restaurant/customer records, and operational data storage.
3. Your choices
You can delete cookies and local storage in your browser, manage device permissions, revoke Google access in your Google Account, and manage Stripe payment methods through Stripe-hosted flows when available. Blocking essential cookies may break login, Turnstile, PWA behavior, checkout, QR/widget unlocks, and owner dashboard access.
4. Do Not Track and Global Privacy Control
Because no single DNT standard applies uniformly, Covey does not currently change behavior automatically for DNT signals. Where applicable law requires honoring Global Privacy Control or another signal, Covey will treat it according to that law and the feature configuration.