Cookie Policy
This policy explains what cookies and similar technologies are, the types we use across all TableOne services, the third-party cookies involved, and how you can manage and disable them.
01Introduction & Scope
This Cookie Policy explains how F&B POS (“we”) uses cookies and similar storage technologies on this site and across our Service web apps — including the Merchant dashboard, the Order ordering app, the Admin panel, the Book & Host reservation apps, and the Member loyalty app.
This policy is an inseparable part of our Privacy Policy and Terms & Conditions. For a full explanation of the personal data we process, please read the Privacy Policy.
02What Cookies & Similar Technologies Are
A cookieis a small text file stored on your device (computer, tablet, or phone) when you visit a site. Cookies let a site remember your actions and preferences over a period of time so you don't have to re-enter them every time you visit or move between pages.
Besides cookies, we may also use similar technologies that store data in your browser:
- Local Storage & Session Storage — store preferences and session context (e.g. the active business/brand/outlet, display theme) within your browser.
- IndexedDB & browser cache — store app data and assets to speed up loading and support offline mode in certain apps.
- Service Worker — a background script that caches assets so an app (e.g. the Merchant dashboard installable as a PWA) stays responsive and reopens quickly.
- Pixels / web beacons & tokens — small markers or tokens that help secure sessions and understand interactions with the Service.
Cookies can be session cookies (deleted when you close the browser) or persistent (lasting until they expire or are deleted). They can also come from us (first-party) or from service providers we use (third-party).
03Why We Use Cookies
We use cookies and similar technologies to:
- keep your login session active and secure across all Service pages;
- remember your preferences, such as the active business/brand/outlet context and display theme;
- protect the Service from abuse, bots, and unauthorized access attempts;
- maintain data consistency and support offline mode in the relevant apps;
- understand how the Service is used so we can maintain and improve its quality.
04Types of Cookies We Use
a. Essential Cookies (Required)
Needed for the Service to function and cannot be turned off through our system. They cover login session maintenance (authentication tokens), request security, load balancing, and keeping flows such as ordering, reservation, or payment intact. Without these cookies, parts of the Service will not work properly.
b. Functional & Preference Cookies
Help the Service remember choices you make — such as the active business, brand, and outlet, language, and display theme — to provide a more personal and consistent experience. Disabling them may prevent some preferences from being saved.
c. Security & Anti-Abuse Cookies
Used to detect and prevent suspicious activity and malicious automation, including through bot protection (e.g. hCaptcha) and network/CDN services (e.g. Cloudflare), and to enforce account-security mechanisms such as single active sessions.
d. Analytics & Performance Cookies
Help us understand how visitors and users interact with the Service — pages visited, features used, and errors/performance (e.g. error monitoring) — in aggregate, so we can improve it. This data is kept aggregate where possible and is not used to directly identify you.
05List of Cookies & Technologies Used
The following tables give examples of the main cookies and storage that may be used in our Service. Actual names and durations may change with technical updates, and some markers only appear in certain apps or flows.
Essential & Security
| Name / Marker | Provider | Purpose | Duration |
|---|---|---|---|
| access_token / tokenEssential | TableOne | Stores the authentication token so the login session stays active and is validated per request. | Session / until expiry |
| refresh_tokenEssential | TableOne | Renews the login session without you having to sign in repeatedly. | Persistent (limited) |
| token_versionSecurity | TableOne | Supports the single active session policy — logging in from a new device ends the old session. | Session |
| __cf_bm / cf_clearanceSecurity | Cloudflare | Bot management, attack mitigation, and securing network traffic (CDN). | ≤ 1 year |
| hCaptchaSecurity | hCaptcha | Distinguishes humans from bots on sign-up and login forms. | Session / short persistent |
Functional, Preference & Analytics
| Name / Marker | Provider | Purpose | Duration |
|---|---|---|---|
| scope-store (Local Storage)Functional | TableOne | Remembers the active business, brand, and outlet context in the Merchant dashboard. | Persistent |
| theme / UI preferencesPreference | TableOne | Stores your display-theme choice and other interface preferences. | Persistent |
| Service Worker cache (PWA)Functional | TableOne | Caches app assets for fast loading and offline support (e.g. the Merchant dashboard). | Until updated/cleared |
| Tawk.toFunctional | Tawk.to | Enables the support chat widget and remembers your conversation history. | Persistent |
| SentryAnalytics | Sentry | Monitors errors and Service performance for quality improvement. | Session / short persistent |
06Third-Party Cookies & Technologies
Some Service functions rely on third-party providers that may place their own cookies or similar technologies. These third parties' use of data is subject to each provider's privacy policy, including:
- Cloudflare — network/CDN infrastructure, traffic security, and bot mitigation;
- Midtrans — a third-party payment gateway that processes transactions (e.g. QRIS, cards, e-wallets) on payment pages/flows;
- hCaptcha — protecting forms from bots and abuse;
- Tawk.to — the customer-support chat widget in some apps;
- Sentry — application error and performance monitoring;
- Social networks — if you follow links to our social channels, those platforms may place their own cookies.
We do not control cookies placed by third parties. Please refer to each provider's privacy/cookie notice for details and management options.
07Cookies in Device Apps (POS, Kiosk, KDS/ODS)
Our device apps — such as POS (cashier), Kiosk, and KDS/ODS (kitchen & queue displays) — generally do not use browser cookies, but rather local on-device storage (e.g. a local database and config files) to store device credentials, licenses, and the data needed for the app to run, including in offline mode. The handling of that data is explained in our Privacy Policy.
08Legal Basis & Consent
For essential and security cookies, we rely on our legitimate interests and the need to provide the Service you request. For certain functional, preference, and analytics cookies, we may request your consent in line with applicable regulations, including Indonesia's Personal Data Protection Law. You can withdraw consent or change your choices at any time through your browser settings as described below.
09How to Manage & Disable Cookies
Most browsers let you view, manage, block, and delete cookies through their settings menu. You can also clear site data (including Local Storage and cache) from your browser. General instructions are available in each browser's help center:
- Google Chrome — Settings → Privacy and security → Cookies and other site data;
- Mozilla Firefox — Settings → Privacy & Security → Cookies and Site Data;
- Safari — Preferences → Privacy → Manage Website Data;
- Microsoft Edge — Settings → Cookies and site permissions.
Please note: blocking or deleting essential cookies may sign you out, lose your preferences, or cause some Service features to not work as intended.
10Changes to This Policy
We may update this Cookie Policy from time to time to reflect changes in technology, law, or how we operate. We will notify you of material changes through the Service or by posting the latest version on this page along with the update date. By continuing to use the Service, you are deemed to agree to the updated policy.
11Contact Us
For questions about our use of cookies or other privacy requests, please contact us:
© 2024–2026 TableOne. All rights reserved. Effective version: June 20, 2026.