Cookie Policy
U.S.-first Cookie Policy revision 2026-07-19.us-v1 covering verified first-party technologies, provider technologies, optional processing, and controls.
<!-- tbltap-policy revision=2026-07-19.us-v1 sha256=a4f0d2f000d054b1a62a05eef16083cba79aa4ed3c6f12e3829e9e0e3214491d normalization=lf-strip-marker-trim-final-newline-v1 -->
<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8"><meta name="viewport" content="width=device-width,initial-scale=1">
<title>tbltap Cookie Policy</title>
<style>
:root { color-scheme:light; } body { margin:0; padding:20px 18px 32px; font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Helvetica,Arial,sans-serif; font-size:14px; line-height:1.58; color:#111827; background:#F5F6FA; } main { max-width:900px; margin:0 auto; } h1 { font-size:21px; margin:0 0 4px; } h2 { font-size:16px; margin:22px 0 7px; } p,li { margin:8px 0; } a { color:#1d4ed8; } .meta,.footer { font-size:12px; color:#5f6877; } .footer { margin-top:26px; padding-top:14px; border-top:1px solid rgba(15,23,42,.12); } .table-wrap { overflow-x:auto; } table { width:100%; min-width:760px; border-collapse:collapse; font-size:12px; background:#fff; } th,td { text-align:left; vertical-align:top; padding:8px; border-bottom:1px solid #e5e7eb; } th { font-weight:650; }
</style>
</head>
<body><main>
<h1>tbltap Cookie Policy</h1>
<p class="meta"><strong>Revision 2026-07-19.us-v1</strong> | Effective upon publication</p>
<p>This Policy explains how <strong>Ngassa Holdings LLC, doing business as tbltap</strong> uses cookies, local storage, session storage, software-development-kit storage, pixels, and similar browser or device technologies (together, "browser technologies"). It should be read with the <a href="/docs/privacy">Privacy Policy</a>.</p>
<h2>1. Necessary and optional technologies</h2>
<p><strong>Strictly necessary</strong> technologies provide a service you request or protect that service, such as sign-in, session security, CSRF protection, fraud controls, cart and table continuity, language, accessibility, checkout, and load balancing. Disabling them may break tbltap.</p>
<p><strong>Optional analytics and personalization</strong> measure feature use across visits or use interaction history for recommendations. They are not treated as strictly necessary. tbltap does not currently use Google Analytics, Meta Pixel, third-party advertising cookies, or cross-site ad tracking. Optional tbltap analytics and personalization are off until allowed through the available consent control. A recognized Global Privacy Control signal denies optional analytics and personalization for that browser.</p>
<h2>2. Verified first-party cookies and storage</h2>
<p>The following inventory was reconciled against first-party application emitters for this revision. It names verified core technologies, but it is not a representation that every temporary debugging key, provider-controlled technology, or future feature key is listed. New or changed material technologies require a revised inventory.</p>
<div class="table-wrap"><table>
<thead><tr><th>Name</th><th>Type and purpose</th><th>Code-defined duration</th><th>Classification</th></tr></thead>
<tbody>
<tr><td><code>tbltap_sid</code></td><td>HttpOnly authenticated account session</td><td>180 days for a remembered account session; 12 hours for a short session; earlier sign-out, revocation, or expiry may apply</td><td>Strictly necessary</td></tr>
<tr><td><code>tbltap_csrf</code></td><td>Double-submit protection for authenticated or state-changing requests</td><td>180 days, bounded by the related account session and cleared on session removal</td><td>Strictly necessary</td></tr>
<tr><td><code>tbltap-guest-session</code></td><td>HttpOnly guest ordering, table, and continuity session</td><td>180 days; an eligible active token is refreshed after 30 days</td><td>Strictly necessary when using guest ordering or continuity</td></tr>
<tr><td><code>tt_diner_sid</code></td><td>HttpOnly diner or tab-member continuity for ordering and payment</td><td>365 days</td><td>Strictly necessary for the related diner or tab workflow</td></tr>
<tr><td><code>tbltap-active-restaurant</code></td><td>HttpOnly authorized restaurant context</td><td>90 days; cleared when switching to personal context</td><td>Strictly necessary for owner and staff business context</td></tr>
<tr><td><code>tbltap_active_profile</code></td><td>Legacy readable active profile mirror used by supported profile switching flows</td><td>30 or 90 days depending on the current first-party emitter; replaced when context changes</td><td>Functional and necessary for the requested context switch</td></tr>
<tr><td><code>tbltap_language</code></td><td>Selected interface language cookie</td><td>365 days</td><td>Functional and necessary to honor the selected language</td></tr>
<tr><td><code>tbltap.language</code></td><td>Local-storage mirror of selected language</td><td>Until changed or site data is cleared; code sets no automatic expiry</td><td>Functional and necessary to honor the selected language</td></tr>
<tr><td><code>tbltap_privacy</code></td><td>Cookie copy of analytics and personalization choices, policy revision, and update time</td><td>365 days or until the choice is changed or cleared</td><td>Strictly necessary to remember privacy choices</td></tr>
<tr><td><code>tbltap.privacy.preference</code></td><td>Local-storage copy of the same privacy choice</td><td>Until changed or site data is cleared; code sets no automatic expiry</td><td>Strictly necessary to remember privacy choices</td></tr>
<tr><td><code>tbltap-app-token</code>, <code>tbltap-app-refresh</code>, <code>sb-access-token</code>, <code>tbltap-platform-token</code>, and <code>tbltap-platform-token-legacy</code></td><td>Authentication handoff, access, refresh, or platform session technologies used only in applicable sign-in surfaces</td><td>Tracks the token or provider session lifetime supplied to the applicable flow; no single fixed duration applies across emitters</td><td>Strictly necessary when that authentication flow is used</td></tr>
<tr><td><code>tbltap_web_auth_vault</code></td><td>Temporary web authentication vault reference</td><td>Bound to the associated temporary authentication handoff; removed or invalid after completion or expiry</td><td>Strictly necessary when that authentication handoff is used</td></tr>
<tr><td><code>tbltap_staff_portal</code></td><td>Authorized staff portal session</td><td>16 hours</td><td>Strictly necessary for staff portal access</td></tr>
<tr><td><code>tbltap_to_fresh</code></td><td>One-time take-order refresh signal</td><td>20 seconds and cleared after use</td><td>Strictly necessary for the requested take-order refresh</td></tr>
<tr><td>Cart, checkout, table, setup-resume, and safe-return keys</td><td>Local or session storage that preserves an in-progress requested flow</td><td>Session-based, feature-expiry based, or until completion or clearing; exact keys vary by flow</td><td>Strictly necessary for the requested flow</td></tr>
<tr><td>Appearance, accessibility, dismissed functional notices, and similar interface keys</td><td>Local storage that remembers an affirmative interface choice</td><td>Until changed, reset, or site data is cleared unless the feature defines a shorter expiry</td><td>Functional</td></tr>
<tr><td>tbltap-controlled analytics or personalization identifiers</td><td>First-party local storage or event identifiers used to measure interactions across visits or support nonessential recommendations</td><td>Only after permission; until withdrawal, feature expiry, or site-data clearing</td><td>Optional analytics or personalization</td></tr>
</tbody>
</table></div>
<h2>3. Provider-controlled technologies</h2>
<p>Cloudflare or another security and delivery provider may set provider-named security, bot-management, load-balancing, or abuse-prevention cookies for a session or a provider-defined security period. Stripe, identity providers, app stores, maps, or other providers may set their own technologies on embedded or redirected surfaces for payment, authentication, fraud prevention, or requested content. Names and expiration are controlled by the provider and may change independently; consult the provider's current notice and browser storage view. tbltap classifies provider technologies as necessary only when they are used to secure or deliver the feature you requested and does not use them to build a cross-site advertising profile.</p>
<h2>4. Your choices</h2>
<p>Use the tbltap cookie banner or privacy settings to allow, deny, or withdraw optional analytics and personalization. Choosing "Continue without optional" or enabling Global Privacy Control keeps both optional categories off. Withdrawal applies prospectively and stops tbltap-controlled optional collection and use; optional identifiers are removed where technically feasible. Necessary technologies remain because they support requested features and security.</p>
<p>You can clear site data or block cookies in browser settings, but doing so may sign you out, empty a cart, reset language choices, or break ordering and payment continuity. Provider controls may also be available on the provider's surface. "Do Not Track" is not a uniform legal or technical standard, so tbltap does not respond to it separately from GPC and the tbltap consent control.</p>
<h2>5. Changes and contact</h2>
<p>We may update this Policy as technologies or law change. The revision above identifies the disclosed configuration. Questions or privacy requests may be sent to <a href="mailto:[email protected]">[email protected]</a>.</p>
<p class="footer">Revision 2026-07-19.us-v1. Material changes to cookies, storage, purposes, or controls require an updated inventory and revision.</p>
</main></body>
</html>
Contact tbltap support and include the document title so we can route your question quickly.
Contact support