ViaVela

Legal documents › ViaVela Venustas

ViaVela Cookie and Local-Storage Notice

Draft: attorney review pending Puerto Rico · English source stamp 70dfdf64632a

ViaVela Cookie and Local-Storage Notice

DRAFT — for Puerto Rico-licensed counsel review. Not legal advice and not final. Have a licensed Nebraska attorney review — and confirm coverage of applicable U.S. rules (and EU/UK rules, if your visitors reach the portal from there) — before publishing. Company master (2026-09-05). Product-specific terms are supplied by the Product Schedule named in the Order; jurisdiction riders (Puerto Rico) are applied by jurisdictions/PR.md. Attorney review required before use.

Last updated: 2026-07-10

This Notice explains what cookies and similar storage technologies the ViaVela end-user-facing experience (the "Services") uses, and what they are used for. It supplements our [Privacy Policy](PRIVACY_POLICY.md) and [Terms of Service](TERMS_OF_SERVICE.md).

1. What we use

The ViaVela end-user-facing experience is a Progressive Web App (PWA). It does not use third-party advertising or analytics cookies. It uses a small number of first-party browser-storage mechanisms that are strictly necessary for the experience to work.

MechanismPurposeTypical lifetime
localStorage — viavela-client-sessionStores the bearer token + expiry the client portal received after signing in with their phone + one-time passcode (OTP), so you don't have to sign in again on every visit. This is a functional session token, not a tracking identifier.Up to 30 days, or until you sign out / clear browser storage.
localStorage — viavela-self-checkout-stateCaches the current self-checkout selection (services, tip choice, payment method) so a page refresh does not lose your in-progress checkout.Cleared on checkout completion or 24 hours of inactivity.
sessionStorage — booking flow stateTracks the current step of the booking flow (date → service → tech → confirm) so the back/forward buttons work as expected.Cleared when you close the tab.
IndexedDB — PWA service-worker cacheStores the app shell (HTML/CSS/JS) so the portal loads quickly and works on flaky connections.Updated when the salon ships a new version.
HTTP-only authentication cookie (only if the Business uses the optional same-origin sign-in)Carries your authenticated session to the relay over HTTPS.Up to 30 days.

We do not set tracking cookies, advertising IDs, or any cookie/storage used to profile you across other websites.

2. Third parties

The ViaVela Services themselves do not embed third-party trackers. However, the Business may choose to enable optional integrations whose providers may set their own cookies or storage when invoked — for example, a payment processor's hosted checkout iframe or redirect, if the Business enables card payments.

Payment processor (only if the Business enables card payments) — the payment provider's own checkout iframe or redirect may set cookies under the provider's domain. Examples: Stripe, Square, Clover. Those providers' privacy notices govern their cookies.

Bot protection (sign-up page) — Cloudflare Turnstile runs in the browser to tell people from bots and may set its own cookie or storage under cloudflare.com; Cloudflare's privacy notice governs it.

When you reach a third-party page (e.g., the payment processor's hosted checkout), that provider's cookie policy applies to anything it sets, not this Notice.

  • Email service (Gmail API) — used server-side to deliver confirmations and reminders; does not set any cookie or storage in your browser.

SMS/text messaging is not currently enabled.

3. Why we don't show a cookie banner

Because we do not use cookies for advertising, analytics tracking, or any non-essential purpose, we do not need to ask for separate consent before setting the strictly necessary items in Section 1. If your jurisdiction requires a banner anyway (for example, some EU residents accessing the portal), the Business may configure one.

This is consistent with Puerto Rico consumer-protection practice, which does not require a consent banner for storage that is strictly necessary to operate a service you requested.

4. Your controls

You can clear all ViaVela storage at any time:

Sign out of the client portal (top-right of the Account screen) — this clears the viavela-client-session token.

  • Clear site data in your browser — removes all localStorage, sessionStorage, IndexedDB, and cookies for the portal's domain. The portal will continue to work; you will just need to sign in again.
  • Disable storage in your browser — the portal may not function (sign-in and the offline cache require storage).

5. Changes to this Notice

We may update this Notice as the Services evolve or to comply with new law. Material changes will be posted with a new "Last updated" date.

6. Contact

ViaVela Solutions LLC — legal@viavelahq.com — P.O. Box 13001, Offutt AFB, NE 68113.


© 2026 ViaVela Solutions LLC. All rights reserved.

Puerto Rico consumers may also raise a concern with the Departamento de Asuntos del Consumidor (DACO) — see the Privacy Policy, Section 10.

Tell us what your business runs on today.

A notebook, a spreadsheet, a whiteboard, a great memory: that is the system that got you here. We start from there. No forms, no sales funnel: one email, read by a person.

hello@viavelahq.com →