Public product information

Cookies and browser storage

This page explains the cookies and similar browser storage currently used by the native.cards web platform. It covers the merchant product, operator tools and public Wallet/programme journeys.

Last reviewed
12 September 2026
Current category
Security and functional storage

What is used, by whom and where

“First party” means the storage is written for the native.cards site you are visiting. Supabase supports authentication, but its session cookies are delivered on the platform origin. Exact production hosts, vendors and regions remain subject to the approved production record.

Supabase authentication cookies

Party
First party on the native.cards platform, managed for us by Supabase Auth
Pages and environments
Sign-in, account recovery and authenticated merchant or operator pages; development, preview/staging and production when configured
Purpose and data
Authenticate the account, refresh the signed-in session and protect access to restricted product functions
Lifetime
Session/token lifetime controlled by the deployed authentication configuration; refreshed when needed and removed or invalidated on sign-out/expiry

pp_qr_journey cookie

Party
First party: native.cards
Pages and environments
Public /q/:code and /qr-entry/:code journeys, including authorised previews
Purpose and data
Hold an opaque journey identifier and bind the browser to the selected public QR flow; it does not contain a customer name or email
Lifetime
2 hours

pp_wallet_* access cookies

Party
First party: native.cards
Pages and environments
Email verification, invitation, recovery, Apple pass, Google save and pass-management continuation pages
Purpose and data
Hold an opaque authentication handoff or account-bound Wallet session; the emailed link itself does not authenticate the visitor
Lifetime
10 minutes

loyverse_oauth_nonce cookie

Party
First party: native.cards; used immediately before and after a user-authorised redirect to Loyverse
Pages and environments
Merchant owner POS connection start and callback routes
Purpose and data
Match the callback to the connection request and resist login or authorisation CSRF
Lifetime
Up to 10 minutes and deleted on callback

Public QR and programme session storage

Party
First party: native.cards
Pages and environments
Public QR/programme selection and enrolment pages; keys include public-qr-selection, public-qr-join and join
Purpose and data
Preserve an in-progress selection or enrolment in the current browser tab and recover the requested flow
Lifetime
Current tab/session, or earlier when the flow consumes or clears it

Authenticated interface local storage

Party
First party: native.cards
Pages and environments
Mobile merchant dashboard and Pass designs; key native.cards.mobile-experience-notice.seen
Purpose and data
Remember that the desktop-experience notice was already shown so it is not repeated across reloads or tabs during the same signed-in period
Lifetime
Until sign-out, the next successful sign-in or deletion through browser settings

Wallet design/editor local and session storage

Party
First party: native.cards
Pages and environments
Authenticated Pass designs pages; keys include wallet-design-draft, wallet-design-context, wallet-pass-studio and wallet-studio-v2
Purpose and data
Autosave an unfinished design on that browser, restore editor context and reduce accidental loss before a server save
Lifetime
Session context ends with the tab; recovery copies remain until saved, published, discarded, superseded or cleared in browser settings

Cache Storage: native-cards-static-v3

Party
First party: native.cards
Pages and environments
The scanner page, in browsers that support and register the platform service worker
Purpose and data
Cache only the web-app manifest and native.cards icon for the installable app shell
Lifetime
Until replaced by a later cache version, the site data is cleared or the browser removes it

No optional tracking storage is currently loaded

The reviewed platform code does not currently load advertising cookies, social pixels, session replay, Google Analytics or cross-site behavioural tracking. Security storage is used only for the requested sign-in, QR, Wallet or integration flow. Browser settings can block or clear it, but the requested flow or local draft recovery may then stop working.

If optional analytics or advertising technology is introduced, it must be assessed and—where required—kept off until the visitor makes a valid choice. A notice dismissal is never treated as consent to optional use.

Other parties and destinations

Apple Wallet, Google Wallet, Loyverse and a merchant’s own linked site may use storage on their own apps or domains under their notices. Their storage is not a native.cards first-party cookie merely because a user reached them from this platform. The Loyverse nonce described above is ours; storage set after the redirect is governed by the destination.

How to control browser storage

Use your browser’s privacy or site-data controls to inspect, block or delete cookies, local storage, session storage, service workers and caches. Clearing editor storage removes only the browser recovery copy; it does not by itself delete a draft already saved to the service.

This operational disclosure does not replace the full privacy notice or a merchant programme notice. Contracting/controller identity, contact, final BM/English treatment and production vendor facts remain launch blockers until approved and verified.