Cookies and local storage
Everything TapCub reads from or writes to a browser — on this website, in the console, through the analytics script and through the chat widget — and why none of it shows a consent banner by default.
Last updated Effective
1. What this page covers
European ePrivacy rules and many national laws regulate storing or reading information on a user's device — not only "cookies" in the narrow sense, but localStorage, sessionStorage, IndexedDB and similar mechanisms too. This page therefore lists every item, whatever the mechanism, grouped by where it occurs: this website, the console, the analytics script on customer sites, and the chat widget on customer sites. If an item is not listed here, we do not write it.
The four mechanisms you will see in the tables mean the following:
- Cookie — a small value the browser sends back to the server with every request to the same domain. An httpOnly cookie cannot be read by scripts; a Secure cookie travels only over HTTPS; SameSite=Lax stops it being sent on most cross-site requests.
- localStorage — key-value storage that stays until it is cleared, readable only by pages on the same origin and never sent to the server automatically.
- sessionStorage — like localStorage, but scoped to one browser tab and cleared when that tab closes.
- Server-side state — things we remember on our servers rather than on the device, such as the daily visitor hash. These are not storage on your device and are not covered by storage rules, but we list them where it helps you understand the picture.
"Duration" in the tables is the maximum lifetime: "until cleared" means the value remains until you clear site data in the browser, "session" means it ends when the browser or tab is closed.
2. This website (tapcub.com)
The marketing site is static. It loads no third-party scripts, fonts or pixels; fonts are self-hosted. It sets no cookies. It writes to localStorage only after you take an action:
| Name | Type | Purpose | Duration |
|---|---|---|---|
tc_lang | localStorage | Remembers the language you chose or that you dismissed the language suggestion, so we do not suggest switching again. | Until cleared |
tc_announce_<id> | localStorage | Remembers that you closed the announcement bar at the top of the page. | Until cleared |
This website is measured with our own analytics script, which writes nothing (see section 4). Campaign parameters such as utm_source in a link are passed through to the sign-up page in the URL only; they are not stored in your browser.
3. The console (app.tapcub.com)
Once you sign in, the console needs to know who you are between page loads and remembers a few interface preferences you set yourself.
| Name | Type | Purpose | Duration |
|---|---|---|---|
Sign-in session | Cookie, httpOnly, Secure, SameSite=Lax | Keeps you signed in and protects the session from scripts. | Session, or up to 30 days with "stay signed in" |
Theme | localStorage | Light or dark preference. Written only when you toggle it; read before first paint to avoid a flash. | Until cleared |
Language | localStorage | Console language, written only when you change it. | Until cleared |
Sidebar and layout | localStorage | Collapsed sidebar, last visited site and similar layout state. | Until cleared |
Payment pages hosted by Stripe, PayPal, Alipay or WeChat Pay set their own cookies under their own policies while you are on their pages.
4. The analytics script on customer sites
The script (about 2 KB) and the mobile and mini-program SDKs write no cookies and no browser storage. Each pageview or event is sent as a request; "the same visitor" is derived on our servers from a daily-rotating salt, the site key, the IP address and the user agent, and the raw IP address is never stored. Nothing persists on the visitor's device, so there is nothing to consent to under storage rules.
| Name | Type | Purpose | Duration |
|---|---|---|---|
(none) | — | In the default anonymous mode the script reads the URL, referrer, language and screen size that the browser exposes and sends them; it stores nothing. | — |
Identification mode (off by default). A customer who needs user profiles that persist across days can switch a site to identification mode in the compliance centre. The script then loads a small extension that stores a first-party device identifier so the same browser can be recognised on later visits, together with the visitor's consent and opt-out state. In this mode storage is written, and for visitors in the EEA and UK the default region rules require consent before the identifier is created — the customer's own consent banner must grant it through the SDK's consent API. Visitors who decline are counted anonymously as above.
| Name | Type | Purpose | Duration |
|---|---|---|---|
wc_did | localStorage + first-party cookie | Random device identifier, written only in identification mode and only after consent where required. | Up to 13 months |
wc_consent | localStorage | The visitor's consent choice and the version of the notice they saw, so the script does not ask again. | Until cleared |
wc_optout | localStorage | Set when the visitor opts out through the site's privacy controls; the script then sends nothing identifying. | Until cleared |
wc_child | localStorage | Child-mode flag set by the site for under-age visitors; forces the anonymous tier. | Until cleared |
If a customer calls identify with their own user ID, that ID travels in the request. Do Not Track and Global Privacy Control are honoured in both modes: when either is set, no identifier is created or stored.
5. The chat widget on customer sites
The launcher bubble writes nothing while closed. Storage is written only after a visitor opens the window and sends a message — the minimum needed so the conversation they asked for survives a page refresh.
| Name | Type | Purpose | Duration |
|---|---|---|---|
Chat session token | sessionStorage | An opaque random string issued by the server after the first message, so the same conversation reopens after a refresh. It encodes nothing about the visitor. | Until the tab closes |
Remembered conversation | localStorage (opt-in) | If the visitor turns on "remember this conversation", the token moves to localStorage so they can continue later. | 30 days, only when enabled by the visitor |
Widget state | sessionStorage | Whether the window was open or minimised, so navigation between pages does not close it. | Until the tab closes |
The window itself runs inside an iframe: the host page cannot read the conversation and the widget cannot read the host page. They exchange only open, close and unread-count messages.
6. Why there is no banner by default
Under ePrivacy Article 5(3), national laws such as Germany's TTDSG §25, and comparable rules elsewhere, storage that is strictly necessary to provide a service the user has explicitly requested does not require prior consent. Every item on this page falls into that category: a session cookie to stay signed in to a console you logged into, preferences you set yourself, and a chat token written only after you chose to start a conversation. Nothing here is used for tracking across sites, advertising or profiling.
Whether your site needs a banner depends on everything else it runs. TapCub analytics in its default anonymous mode does not add a reason for one. If you switch a site to identification mode, the device identifier is not strictly necessary, and visitors in the EEA, the UK and other consent jurisdictions must be asked first — the SDK waits for your banner's answer. If you add our chat widget, you still need to mention chat in your privacy policy, because conversation content is personal data; see why our chat widget starts without a banner for the details.
7. Shared reports and embedded dashboards
Customers can share a report by public link or embed a dashboard on their own site. A viewer of a shared report is not signed in, so no session cookie is set. The shared page writes nothing to the viewer's device; the report's date range and filters live in the URL, not in storage. If the customer protects a shared link with a password, the password check is remembered for the duration of the tab in sessionStorage and nowhere else.
| Name | Type | Purpose | Duration |
|---|---|---|---|
Shared-report access | sessionStorage (only if password-protected) | Remembers that you entered the correct password for this shared report. | Until the tab closes |
8. What we deliberately do not do
Some techniques are used by analytics or chat tools to work around storage rules. We do not use any of them, and we commit not to introduce them without changing this page and the consent position first:
- no client-side fingerprinting scripts — no canvas, font, audio or hardware probing;
- no cookies in the default anonymous mode — the only cookie the script can ever set is the identification-mode device ID in section 4, after consent where required — and no CNAME aliasing to make our requests look first-party;
- no ETag, cache or link-decoration tricks to persist an identifier across visits;
- no third-party cookies, pixels or tag managers loaded by our script or widget;
- no cross-site linking of visitors between different customers' sites — the visitor hash includes the site key, so the same person on two sites produces two unrelated values;
- no storage before the visitor acts: the launcher bubble is purely visual until clicked.
9. Third-party cookies
We set no third-party cookies and no third-party service sets cookies through us on this website or in the console. The only exceptions are the payment providers' own hosted pages, and notification channels you connect yourself from within the console, which operate under their own policies. Ad platforms whose click IDs we read — for example gclid or ttclid in the landing URL — set their cookies on their own domains before the visitor reaches your site; we only read the parameter from the URL and do not touch their cookies.
10. How to control storage
You can clear localStorage and cookies in your browser at any time; the console will sign you out and this website will forget your language choice. Blocking storage entirely on a customer site means the chat conversation will not survive a refresh on that device, but analytics continues to work because it never needed storage. Browser Do Not Track and Global Privacy Control signals are respected by the analytics script: when either is set, the pageview is counted in aggregate and no visitor hash is computed.
To verify any statement on this page yourself, open the browser's developer tools, choose the Application or Storage tab, and look at Cookies, Local Storage and Session Storage for the domain in question before and after you open the chat. You should see exactly what the tables above describe and nothing else.
11. If you run TapCub on your own site
You can copy the tables in sections 4 and 5 into your own cookie or privacy notice. Keep the wording precise: say "the analytics script sets no cookies and stores nothing on your device" and "the chat widget stores one session token after you start a conversation". Do not say "this site uses no cookies" unless that is true for everything else you run — site builders, embedded videos, payment forms and ad pixels usually do set cookies, and those need their own treatment in your notice and, where required, a consent mechanism.
If your site is subject to a consent-management platform, you can classify the analytics script in anonymous mode as "strictly necessary" or run it outside the consent gate, and classify the chat widget the same way, because its only storage follows an explicit visitor action. In identification mode, wire your platform's analytics consent category to the SDK's consent call instead.
12. Changes to this page
If we ever add an item that does not fit the strictly-necessary exemption, this page and a consent mechanism are updated before the item ships, and existing customers are told in advance. Smaller changes — a renamed key, a shorter duration — are reflected here on release. The "Last updated" date at the top of the page tells you when the list last changed, and earlier versions are available on request.
13. Contact
Questions about this document go to [email protected] or through the contact page.
Also read