Cookie policy
Last updated: 5 August 2026
This policy explains which cookies Vault sets, why, and how you can control them. The short version: we only use strictly-necessary cookies that make the service work. No analytics, no advertising, no cross-site tracking.
2. Cookies we set
All cookies we set are first-party, HttpOnly where they hold credentials, and used for one purpose only:
| Cookie | Purpose | Duration |
|---|---|---|
| vault_session | Operator sign-in: a signed token that keeps staff authenticated to the management app. | 7 days |
| vault_portal | Tenant sign-in: a signed token that keeps storage customers authenticated to the tenant portal. | 7 days |
| vault_site | Remembers which site an operator selected in the site switcher, so lists stay filtered. | 1 year |
| vault_2fa | Short-lived signed token holding the pending second-factor step between password and TOTP verification. | 10 minutes |
| vault_auth0_state | Single sign-on security: correlates the SSO redirect with its callback (only set when SSO is enabled). | 10 minutes |
| vault_auth0_nonce | Single sign-on security: prevents token-replay during the SSO handshake (only set when SSO is enabled). | 10 minutes |
We also use your browser's localStorage for one item: vault_cookie_notice_v1, which remembers that you dismissed the cookie notice. It stores the word "dismissed" and nothing else.
3. No analytics or marketing cookies
We do not set analytics cookies (no Google Analytics or similar), advertising cookies, or social-media trackers, and we do not fingerprint your device. If we ever introduce anything non-essential, we will ask for your opt-in consent first and update this policy before setting it.
4. PECR & strictly-necessary cookies
The Privacy and Electronic Communications Regulations (PECR) require consent for cookies except those that are strictly necessary to provide a service you request. Every cookie in the table above falls in that exempt category (they exist solely to authenticate you and remember your site selection), so we do not need to ask for consent. We still show a one-time transparency notice ("essential cookies only") so you know exactly where you stand.
5. How to control cookies
You can delete or block cookies at any time through your browser settings (usually under "Privacy" or "Site settings"). Blocking vault_session or vault_portal will prevent you from signing in; the others degrade specific features but leave the rest of the service working. You can also clear the saved cookie-notice dismissal by clearing your browser's site data.
6. Changes to this policy
We will update this page if the cookies we use change, and the "last updated" date at the top will change accordingly. Questions: [[email protected]].
