Public product information
Cookies and browser storage
This page explains the cookies and similar browser storage currently used by the native.cards web platform. It covers the merchant product, operator tools and public Wallet/programme journeys.
- Last reviewed
- 12 September 2026
- Current category
- Security and functional storage
What is used, by whom and where
“First party” means the storage is written for the native.cards site you are visiting. Supabase supports authentication, but its session cookies are delivered on the platform origin. Exact production hosts, vendors and regions remain subject to the approved production record.
Supabase authentication cookies
- Party
- First party on the native.cards platform, managed for us by Supabase Auth
- Pages and environments
- Sign-in, account recovery and authenticated merchant or operator pages; development, preview/staging and production when configured
- Purpose and data
- Authenticate the account, refresh the signed-in session and protect access to restricted product functions
- Lifetime
- Session/token lifetime controlled by the deployed authentication configuration; refreshed when needed and removed or invalidated on sign-out/expiry
pp_qr_journey cookie
- Party
- First party: native.cards
- Pages and environments
- Public /q/:code and /qr-entry/:code journeys, including authorised previews
- Purpose and data
- Hold an opaque journey identifier and bind the browser to the selected public QR flow; it does not contain a customer name or email
- Lifetime
- 2 hours
pp_wallet_* access cookies
- Party
- First party: native.cards
- Pages and environments
- Email verification, invitation, recovery, Apple pass, Google save and pass-management continuation pages
- Purpose and data
- Hold an opaque authentication handoff or account-bound Wallet session; the emailed link itself does not authenticate the visitor
- Lifetime
- 10 minutes
loyverse_oauth_nonce cookie
- Party
- First party: native.cards; used immediately before and after a user-authorised redirect to Loyverse
- Pages and environments
- Merchant owner POS connection start and callback routes
- Purpose and data
- Match the callback to the connection request and resist login or authorisation CSRF
- Lifetime
- Up to 10 minutes and deleted on callback
Public QR and programme session storage
- Party
- First party: native.cards
- Pages and environments
- Public QR/programme selection and enrolment pages; keys include public-qr-selection, public-qr-join and join
- Purpose and data
- Preserve an in-progress selection or enrolment in the current browser tab and recover the requested flow
- Lifetime
- Current tab/session, or earlier when the flow consumes or clears it
Authenticated interface local storage
- Party
- First party: native.cards
- Pages and environments
- Mobile merchant dashboard and Pass designs; key native.cards.mobile-experience-notice.seen
- Purpose and data
- Remember that the desktop-experience notice was already shown so it is not repeated across reloads or tabs during the same signed-in period
- Lifetime
- Until sign-out, the next successful sign-in or deletion through browser settings
Wallet design/editor local and session storage
- Party
- First party: native.cards
- Pages and environments
- Authenticated Pass designs pages; keys include wallet-design-draft, wallet-design-context, wallet-pass-studio and wallet-studio-v2
- Purpose and data
- Autosave an unfinished design on that browser, restore editor context and reduce accidental loss before a server save
- Lifetime
- Session context ends with the tab; recovery copies remain until saved, published, discarded, superseded or cleared in browser settings
Cache Storage: native-cards-static-v3
- Party
- First party: native.cards
- Pages and environments
- The scanner page, in browsers that support and register the platform service worker
- Purpose and data
- Cache only the web-app manifest and native.cards icon for the installable app shell
- Lifetime
- Until replaced by a later cache version, the site data is cleared or the browser removes it
No optional tracking storage is currently loaded
The reviewed platform code does not currently load advertising cookies, social pixels, session replay, Google Analytics or cross-site behavioural tracking. Security storage is used only for the requested sign-in, QR, Wallet or integration flow. Browser settings can block or clear it, but the requested flow or local draft recovery may then stop working.
If optional analytics or advertising technology is introduced, it must be assessed and—where required—kept off until the visitor makes a valid choice. A notice dismissal is never treated as consent to optional use.
Other parties and destinations
Apple Wallet, Google Wallet, Loyverse and a merchant’s own linked site may use storage on their own apps or domains under their notices. Their storage is not a native.cards first-party cookie merely because a user reached them from this platform. The Loyverse nonce described above is ours; storage set after the redirect is governed by the destination.
How to control browser storage
Use your browser’s privacy or site-data controls to inspect, block or delete cookies, local storage, session storage, service workers and caches. Clearing editor storage removes only the browser recovery copy; it does not by itself delete a draft already saved to the service.
This operational disclosure does not replace the full privacy notice or a merchant programme notice. Contracting/controller identity, contact, final BM/English treatment and production vendor facts remain launch blockers until approved and verified.