Skip to content
Nalo Social

Cookie Policy

Effective date: June 6, 2026

What are cookies?

Cookies are small text files stored on your device when you visit a website. Nalo Social uses a small, focused set of cookies to make the service work correctly. We do not use advertising or tracking cookies.

Essential cookies

These cookies are required for the service to function. You cannot opt out of them while using the platform.

sb-*

Supabase auth session

Set by Supabase Auth when an organizer signs in. Stores the session token that authenticates the organizer to the dashboard and API. The cookie name includes the Supabase project reference (e.g. sb-[ref]-auth-token). These are httpOnly and Secure. They expire with the session or after the configured refresh period.

nalo_attendee

Attendee device identity

Set at check-in on the attendee's device (phone or kiosk). Stores a signed, opaque token that identifies this device as a checked-in attendee for the current event. Used to authorize scan-to-connect, privacy preference updates, and the profile page without requiring a full account. httpOnly, Secure, SameSite=Strict. Expires 7 days after check-in, or sooner if the attendee signs out from their profile page or clears their cookies. Attendees can sign out, export, or delete their data at any time from that page.

nalo_org

Active organization

Set when an organizer selects an organization in the dashboard. Stores only the active organization ID so the correct org context loads on each page without an extra database round-trip. It is not httpOnly (it holds no sensitive value), SameSite=Lax. Cleared on sign-out or when the organizer switches organizations.

Analytics cookies

We use Vercel Web Analytics to understand how the site is used in aggregate. Vercel Analytics is privacy-friendly: it does not use cookies to track individuals, does not fingerprint devices, and does not share data with third parties for advertising.

Vercel Web Analytics

Aggregate usage metrics

Counts page views and measures performance. No personal identifiers are stored. Data is aggregated and cannot be used to identify individual visitors. See Vercel's analytics privacy policy for details.

Managing cookies

You can clear cookies at any time through your browser settings. Note that clearing the auth session cookies will sign you out of the dashboard, and clearing the attendee cookie will remove your check-in state for the current event (you can re-check-in at the event to restore it).

Attendees do not need to dig through browser settings: your profile page has buttons to sign out of the current device, export a copy of your data, and delete your data. Organizers can sign out of the dashboard from the dashboard menu, which clears both the auth session and the active organization cookie.

Because we only use essential and privacy-respecting analytics cookies, we do not show a cookie consent banner. If this changes, we will update this policy and add appropriate controls.

Questions

Email grow@naloseed.com with any questions about our use of cookies.