LEGAL
Cookie & Storage Policy
Version 2026-09-30-v2 · effective 30/09/2026
Cookie & Storage Policy
Status: Draft for review — not yet published.
1. Scope
This policy explains how CheckOpp uses cookies, local storage, session storage and similar browser technologies when you use checkopp.com and the CheckOpp Operator Console.
2. Current approach
CheckOpp currently uses only storage technologies required for authentication, security, continuity of a user-requested workflow, and recovery of unfinished operator work.
CheckOpp does not use advertising cookies, behavioural tracking cookies or retargeting cookies. CheckOpp uses Vercel Web Analytics for aggregate usage measurement. Vercel Web Analytics is privacy-oriented analytics and does not rely on tracking cookies for advertising or behavioural profiling.
3. Strictly necessary cookie
checkopp_operator_session
Provider: CheckOpp
Type: first-party, strictly necessary cookie
Purpose: authenticates access to the protected CheckOpp Operator Console for authorized OWNER and EXPERT users.
Security: HttpOnly, Secure, SameSite=Strict, Path=/.
Duration: up to 12 hours, or until logout or revocation.
This cookie is required for the Operator Console to function and is not used for advertising or behavioural tracking.
4. Supabase Auth browser session storage
Client account sign-in is currently handled with Supabase Auth in the browser.
The client application stores the authentication session in browser storage managed by the Supabase client library. The stored session can include access and refresh tokens required to keep the user signed in and to authorize access to their own CheckOpp data.
Purpose: authentication and authenticated Case access.
Duration: controlled by the authentication session and cleared or invalidated when the user signs out or the session otherwise ends.
5. Applicability-check session storage
Storage key: checkopp_applicability
Type: sessionStorage
Purpose: temporarily carries an approved applicability-check result into the Case creation flow.
The stored object may include:
- applicability check identifier;
- result and scope basis;
- expiry time;
- the project description entered by the user.
The item is removed after use, when it expires, or when the browser session ends.
6. Operator amendment draft local storage
Storage key pattern: checkopp:operator:amend:<attention-id>
Type: localStorage
Purpose: allows an authorized operator to recover an unfinished amendment draft in the Operator Console.
The stored draft may include:
- internal attention/result identifiers;
- amendment reason;
- required inputs;
- amendment proposal;
- evidence references.
These drafts automatically expire after 7 days and are also removed after a successful amendment commit. They are not used for tracking.
7. Analytics and marketing technologies
CheckOpp uses Vercel Web Analytics to understand aggregate website usage, including page views, traffic sources and general device or geographic information made available by the service. This analytics does not use tracking cookies for advertising or behavioural profiling.
CheckOpp does not use Google Analytics, Meta Pixel, LinkedIn Insight or similar advertising/behavioural tracking technologies.
If non-essential analytics, advertising or marketing technologies are introduced in the future, this policy will be updated and any consent mechanism required by applicable law will be implemented before those technologies are activated.
8. Managing browser storage
You can use your browser settings to inspect or clear cookies and local browser storage.
Clearing strictly necessary authentication storage may sign you out or interrupt an in-progress workflow.
9. Changes to this policy
This policy may be updated when CheckOpp changes its use of browser storage, authentication, analytics or third-party services. The active public version will identify its version and effective date.
10. Contact
Questions about cookies, browser storage or privacy should be directed through the contact details published in the CheckOpp Legal Notice and Privacy Policy.
Published version: 2026-09-30-v2