Cookie Policy
Effective September 15, 2026 | Last Updated September 15, 2026 | Version 1.0
1. Introduction
This Cookie Policy explains how Ollify LLC ("Ollify," "we," "us," or "our") uses cookies and similar technologies when you use the Ollify platform and related services (collectively, the "Service"). It describes what cookies are, why we use them, which specific cookies we use, and what choices you have.
This Cookie Policy is incorporated into and should be read alongside our Privacy Policy at ollify.app/legal/privacy. Together, they describe how we collect and use information about you. Questions about this policy can be directed to privacy@ollify.app.
Cookies are small text files placed on your device when you use a website or application. They help the service remember information about your session — such as keeping you logged in and protecting against security threats. We do not use cookies for advertising or behavioral tracking. Our cookie usage is limited to what is strictly necessary to operate the platform securely, plus a small number of functional preferences stored locally in your browser. Every cookie used by Ollify is listed in this policy; see Section 3 for how we describe local browser storage.
1.1 Where This Policy Applies: Marketing Site vs. the App. This policy covers two different parts of the Service, which work differently.
The public marketing site (ollify.app pages you can visit without logging in) displays a cookie consent banner the first time you visit, with options to Accept All, Reject Non-Essential, or Manage your choices. A standing "Cookie preferences" link in the footer lets you reopen this banner at any time. Your choice is remembered in your browser and is tied to the version of this Cookie Policy you were shown — if we publish a materially updated version, the banner will show again.
The logged-in app (the Ollify platform itself, once you have an account) does not show a cookie banner. Your business already accepted the Terms of Service, Privacy Policy, and — by reference — this Cookie Policy when your account was created. The app sets only the strictly necessary cookies listed in this policy. Rejecting cookies on the marketing site has no effect on the app — they are governed separately.
2. Strictly Necessary Cookies
Strictly necessary cookies are required for the Ollify platform to function. Without these cookies, you cannot log in, use the Service, or be protected from security threats. Because they are essential to the operation of the Service, these cookies cannot be disabled through our platform. You may block them in your browser settings, but doing so will prevent the Service from working correctly.
Cookie Name | Purpose | Duration | Set By |
nb_session | Authentication — keeps you logged in to your Ollify account. If "Remember Me" is selected at login, the session persists for 14 days. Otherwise, the session expires after 8 hours of inactivity. | 8 hours or 14 days (Remember Me) | Ollify |
admin_session | Authentication for the Ollify admin portal. Keeps admin users authenticated during their session. | 2 hours | Ollify |
nb_ops_session | Authentication for the Ollify operations portal. Keeps ops users authenticated during their session. | 2 hours | Ollify |
admin_oauth_state | Temporary security token used only during admin portal sign-in (single sign-on login handshake). Deleted automatically once login completes. | 10 minutes | Ollify |
ops_oauth_state | Temporary security token used only during operations portal sign-in (single sign-on login handshake). Deleted automatically once login completes. | 10 minutes | Ollify |
csrf_token | Cross-Site Request Forgery (CSRF) protection for the main platform. This cookie is a security token that prevents malicious websites from sending unauthorized requests on your behalf. | 24 hours | Ollify |
admin_csrf_token | CSRF security token for the admin portal. Same function as csrf_token, scoped to the admin interface. | 24 hours | Ollify |
ops_csrf_token | CSRF security token for the operations portal. Same function as csrf_token, scoped to the operations interface. | 24 hours | Ollify |
nb_migration_active | Controls the display of migration-related banners and notices within the platform. This cookie is set when a migration process is active and expires when the banner has been shown. | 2 minutes | Ollify |
nb_unsub_handoff | Temporarily carries your unsubscribe request from the link in an email to the confirmation page, so the request token never appears in a page URL or browser history. | 15 minutes | Ollify |
3. Functional Browser Storage (localStorage / sessionStorage)
In addition to cookies, the Ollify platform uses your browser's localStorage and sessionStorage to store certain preferences and draft data locally on your device. This is different from cookies — these values are stored only in your browser and are not transmitted to Ollify's servers with each request. They do not track you across websites and are not accessible to third parties. The table below covers the storage items that most directly affect your experience. Ollify also stores a number of smaller interface-state preferences the same way — for example, whether you've dismissed a notice, collapsed a panel, pinned a shortcut, or left in-progress text in a form field — so the interface remembers your choices between visits. These are functional only, never leave your browser, and are not used for tracking.
Storage Key | Purpose | Storage Type |
nova-theme | Stores your preferred interface theme (e.g., light or dark mode). This allows the platform to display your preferred theme immediately on load without waiting for a server request. | localStorage |
Form draft data | When you are completing a form and leave the page or close your browser accidentally, the platform saves your progress locally so you can resume where you left off. Draft data is cleared when you submit or discard the form. | sessionStorage |
preferred_navigation_app | Stores which map app (Google Maps, Apple Maps, or Waze) opens when you tap "Get Directions" on a job location. | localStorage |
nova_map_appearance | Stores your preferred map color theme (light, dark, or automatic) so the map opens in your preferred appearance. | localStorage |
Notification sound preferences | Stores whether you have enabled or disabled notification sounds within the platform. This preference is local to your browser and does not sync across devices. | localStorage |
These browser storage values remain on your device until you clear your browser's local storage (through your browser settings) or until they expire. Clearing your browser storage will reset your theme and preference settings. Your form drafts will also be lost if you clear storage while a draft is active.
4. Third-Party Service Cookies
The Ollify platform integrates with third-party services that may set their own cookies when you use related features. These cookies are set by the third-party service, not by Ollify, and are subject to each service's own privacy policy. We describe these cookies below so you know what to expect.
Service | When Set | Privacy Policy |
Mapbox | Mapbox may set cookies related to API analytics and map tile delivery when you use mapping, routing, or geolocation features within the platform. These cookies are used by Mapbox to understand how its API is being used and to improve its service. They are not used by Ollify to track you. | mapbox.com/legal/privacy |
Stripe | Stripe sets cookies when its payment processing interface is activated — for example, when you enter payment information during subscription setup or billing changes. Stripe uses these cookies for fraud detection, payment security, and to remember payment session state. Stripe cookies are only active during a payment flow. | stripe.com/privacy |
Ollify does not control these third-party cookies and is not responsible for the data practices of Mapbox or Stripe. If you have questions about how these services use cookies, please review their respective privacy policies at the links above.
5. Analytics and Advertising Cookies (Two Separate Categories)
ANALYTICS AND ADVERTISING ARE SEPARATE CATEGORIES, AND BOTH ARE CURRENTLY EMPTY
Analytics (measuring how the marketing site is used) and Advertising (ad targeting and retargeting) are two distinct categories in our preferences panel, so you can choose them independently once either is in use. Both exist today for future use, with no active scripts in either — Ollify does not currently use Google Analytics, Meta Pixel, LinkedIn Insight Tag, PostHog Cloud, Hotjar, FullStory, LogRocket, Intercom, Drift, or any other analytics, advertising, session recording, or behavioral tracking technology. We do not set tracking cookies. We do not share data with advertising networks. We do not use remarketing or retargeting. If this changes, we will update this Cookie Policy, display a cookie consent banner, and obtain your consent before activating any analytics or marketing cookies.
If and when Ollify adds any analytics or marketing technology in the future, we will:
Update this Cookie Policy at least thirty (30) days before activating the new technology.
Display a cookie consent banner to all users, clearly describing the new cookies and their purpose.
Obtain your explicit consent before setting any non-essential cookies.
Provide a straightforward opt-out mechanism.
Send an email notification to account holders.
If any such technology includes session replay, heatmap, or screen-recording capability, customer data fields will be masked at the point of capture so that sensitive content is never transmitted to the third-party tool.
6. Your Choices
You have several options for controlling cookies, though some choices will affect how the Service works.
6.1 Cookie Preferences Panel (Marketing Site). On the marketing site, click "Cookie preferences" in the footer at any time to reopen the preferences panel. There you can turn each of the four categories on or off individually — Strictly Necessary (always on, cannot be disabled), Functional, Analytics, and Advertising — and save your updated choice, which is remembered in your browser going forward.
6.2 Browser Cookie Settings. Most web browsers allow you to control cookies through your settings. You can typically:
- (a)
view all cookies set by websites you visit;
- (b)
delete existing cookies;
- (c)
block new cookies from being set; and
- (d)
set preferences for specific websites.
Refer to your browser's help documentation for instructions:
Chrome: Settings > Privacy and Security > Cookies and other site data
Firefox: Settings > Privacy & Security > Cookies and Site Data
Safari: Settings > Privacy > Manage Website Data
Edge: Settings > Cookies and site permissions
IMPORTANT — BLOCKING ESSENTIAL COOKIES
If you block or delete the strictly necessary cookies listed in Section 2 (nb_session, admin_session, nb_ops_session, csrf_token, admin_csrf_token, ops_csrf_token, admin_oauth_state, ops_oauth_state), you will not be able to log in or use the Ollify platform. These cookies are required for the Service to function. They cannot be replaced by alternatives because they serve fundamental authentication and security purposes.
6.3 Browser localStorage and sessionStorage. You can clear your browser's local storage and session storage through your browser's developer tools or privacy settings. Clearing local storage will reset your theme preferences, map preferences, and notification sound settings. Clearing session storage during an active session will discard any unsaved form drafts.
6.4 Do Not Track. Some browsers support a "Do Not Track" (DNT) signal that tells websites not to track you. Because we do not currently use analytics or advertising cookies, our tracking practices do not change based on whether your browser sends a DNT signal — we respect your privacy the same way regardless. If we add analytics technologies in the future, we will evaluate and implement appropriate DNT responses at that time.
6.5 Sale, Sharing, and Global Privacy Control (GPC). Ollify does not sell or share your personal information, as those terms are defined under California and other state privacy laws — including for cross-context behavioral advertising — whether collected through cookies or otherwise.
Some browsers and browser extensions send a Global Privacy Control (GPC) signal, which communicates a request to opt out of the sale or sharing of personal information. Because Ollify does not sell or share personal information in the first place, honoring a GPC signal does not change how we treat your data — the opt-out you are requesting is already the case for everyone, with or without the signal. If this changes in the future, we will honor GPC signals as a valid opt-out request under applicable law.
6.6 Third-Party Cookie Controls. To opt out of cookies set by Mapbox or Stripe, please refer to their respective privacy policies and opt-out mechanisms:
Mapbox opt-out: mapbox.com/legal/privacy
Stripe opt-out: stripe.com/privacy
7. Changes to This Cookie Policy
We may update this Cookie Policy from time to time to reflect changes in our cookie usage, the technologies we use, or applicable law. When we make material changes — including adding any new category of cookies or activating analytics or marketing technologies — we will:
Post the updated Cookie Policy at ollify.app/legal/cookie-policy with a new "Last Updated" date at least thirty (30) days before the change takes effect.
Send an email notification to the email address associated with your account.
Display an in-app notification.
For non-essential cookies: display a cookie consent banner and obtain your consent before activating.
For minor changes (such as correcting a typo or clarifying an existing description without changing our actual practices), we may update this policy without advance notice.
8. Contact Us
If you have questions about this Cookie Policy, the cookies we use, or your choices, please contact us:
Privacy / Cookie Questions | privacy@ollify.app |
Mailing Address | Ollify LLC, 901 N State St. STE N, Jackson, MS 39202 |
Privacy Policy | ollify.app/legal/privacy |
Cookie Policy | ollify.app/legal/cookie-policy |
Response Time | We respond to all privacy requests within 45 days |
9. Full Cookie and Storage Reference
The table below lists every cookie used by the Ollify platform as of the Last Updated date, along with the local storage and session storage items that most directly affect your experience. Every item in the Strictly Necessary and Functional categories is first-party, set directly by Ollify. Every item in the Third-Party category, by definition, is set by that named third party (Mapbox or Stripe), not by Ollify. It does not separately list every smaller interface-state preference described in Section 3.
Name / Key | Type | Purpose | Duration | Category |
nb_session | Cookie | User authentication (main platform) | 8h / 14d (Remember Me) | Strictly Necessary |
admin_session | Cookie | Admin portal authentication | 2 hours | Strictly Necessary |
nb_ops_session | Cookie | Ops portal authentication | 2 hours | Strictly Necessary |
admin_oauth_state | Cookie | Admin portal SSO login handshake | 10 minutes | Strictly Necessary |
ops_oauth_state | Cookie | Ops portal SSO login handshake | 10 minutes | Strictly Necessary |
csrf_token | Cookie | CSRF security — main platform | 24 hours | Strictly Necessary |
admin_csrf_token | Cookie | CSRF security — admin portal | 24 hours | Strictly Necessary |
ops_csrf_token | Cookie | CSRF security — ops portal | 24 hours | Strictly Necessary |
nb_migration_active | Cookie | Migration banner display control | 2 minutes | Strictly Necessary |
nb_unsub_handoff | Cookie | Email unsubscribe confirmation handoff | 15 minutes | Strictly Necessary |
nova-theme | localStorage | User interface theme preference | Until cleared | Functional |
Form draft data | sessionStorage | Auto-save form draft progress | Session / until submitted | Functional |
preferred_navigation_app | localStorage | Preferred navigation app for directions | Until cleared | Functional |
nova_map_appearance | localStorage | Map color theme preference | Until cleared | Functional |
Notification sounds | localStorage | Notification sound on/off preference | Until cleared | Functional |
Mapbox cookies | Third-party cookie | Mapbox API analytics (mapping features) | Per Mapbox policy | Third-Party |
Stripe cookies | Third-party cookie | Payment fraud detection and session state (checkout only) | Per Stripe policy | Third-Party |