Legal
Cookie Policy
We use cookies to keep the site working and, where you give consent, to improve your experience. Below is a complete list of the cookies Covered sets or allows.
| Cookie | Category | Purpose | Expiry |
|---|---|---|---|
| __Secure-next-auth.session-token | Essential | AuthenticationKeeps you signed in while you use the platform. Set when you log in and removed when you log out. | 30 days, renewed while you use Covered |
| __Host-next-auth.csrf-token | Essential | Sign-in securityProtects the sign-in form against requests forged by another website. | Session |
| __Secure-next-auth.callback-url | Essential | Sign-in redirectRemembers which page to take you back to after you sign in. | Session |
| __Host-covered.passkey-challenge | Essential | Passkey sign-inHolds a one-time check while you sign in with, or add, a passkey. Cleared as soon as that step finishes. | 5 minutes |
| __Host-covered.sa-pending | Essential | Covered staff sign-inCovered’s own team only (never venue staff or guests). Holds the first sign-in step while the second check is completed. | 10 minutes |
| __Host-covered.sa-code | Essential | Covered staff sign-inCovered’s own team only. Holds a one-time check for an emailed sign-in code, so the code can be verified without storing it. | 10 minutes |
| __Host-covered.sa-challenge | Essential | Covered staff sign-inCovered’s own team only. Holds a one-time check while a passkey is used or added. | 5 minutes |
| __Host-covered.sa-seen | Essential | Covered staff sign-inCovered’s own team only. Records the time of the last request so an unused session ends after an hour. | Until sign-out (at most 12 hours) |
| __Host-covered.manager-mode | Essential | Manager modeSet on a venue’s device when a manager enters the manager password to turn on Manager mode for the staff member signed in there. It stops working when someone taps Lock, when that staff member signs out, after 15 minutes without use, or 60 minutes after it was set. After that it is only used to record when Manager mode ended, and is then removed. | Up to 25 hours |
| selectedVenueId | Essential | Remembers your venueFor accounts with more than one venue, remembers which venue the dashboard is showing. | 30 days |
| operator_locale | Essential | Dashboard languageRemembers the language you chose for the dashboard. | 1 year |
| widget_locale | Essential | Booking page languageRemembers the language you chose on a venue’s booking page. | 1 year |
| __Host-covered.act-as-venue | Essential | Covered support setting up a venueSet only in the browser of a Covered support person who has opened a venue’s dashboard to set it up. It names that one venue and stops working after an hour. Never set for venue staff or guests. | Works for 60 minutes; deleted within 13 hours |
| cookie-consent | Essential | Stores your cookie preferencesRecords whether you accepted all cookies or essential-only so the banner is not shown on every page. | 1 year |
| __stripe_mid | Functional (requires consent) | Stripe fraud preventionSet by Stripe when the payment form loads. Helps detect and prevent fraudulent card transactions. | 1 year |
| __stripe_sid | Functional (requires consent) | Stripe fraud preventionSet by Stripe alongside __stripe_mid when the payment form loads, for the same purpose. | 30 minutes |