Cookie Policy
This Cookie Policy explains how Restock, Inc. ("Restock", "we"), uses cookies and similar technologies — including browser local storage — on the Restock platform (the "Service"). It supplements our Privacy Policy.
1. What are cookies and local storage?
Cookies are small text files placed on your device by a website. Local storage is a similar browser mechanism that lets a web application store data on your device between visits. Both let the Service remember information so it can function and remember your preferences.
2. How Restock uses them
Restock is a web application that relies primarily on browser local storage rather than traditional tracking cookies. Local storage keeps you signed in, remembers which workspace (tenant) you have selected, tracks your onboarding progress, and holds demonstration data so the product works without a backend connection. On deploys that run without a backend connection, it also holds the account records created on this device — first and last name, work email, company, phone, role, workspace and plan, plus a value derived from your password with PBKDF2-SHA-256 (the password itself is not stored; accounts created on this device before that derivation shipped may still hold an older, weaker digest until the next sign-in replaces it) — and the business records you enter in the product, such as invoices, contracts and purchase orders.
We do not use advertising or cross-site tracking cookies, and we do not sell or share personal information for behavioral advertising. But "no advertising trackers" is not the same as "not much data": most of the product's state, including the records above, lives in your browser.
3. Categories we use
- Strictly necessary. Required for the Service to operate — for example, keeping your session active and maintaining tenant selection. These cannot be switched off without breaking the Service.
- Functional. Remember your preferences and progress, such as onboarding steps and UI choices, to improve your experience.
- Analytics and error monitoring (optional). Two things run alongside the product rather than as part of it. On deploys connected to our backend, each signed-in page load writes a row recording the page you opened, your role, your workspace and the time — page and role only, never the contents of your records. And where an error-reporting key is configured, pages load a script from
browser.sentry-cdn.comthat reports uncaught errors and can capture a replay of the page session in which an error occurred.
3.1 Your choice, and exactly how far it reaches
The sign-up page and this page show a short prompt asking whether the optional analytics and error monitoring above may run. Your answer is stored in this browser under restock-consent together with the date and the version of this policy, and each answer is also appended to restock-consent-log. Until you answer, the optional categories are treated as declined.
What that answer currently governs: the sign-up page checks it before it loads the error-reporting script. What it does not yet govern: the signed-in page-view analytics described above, and the error-reporting script on pages other than sign-up. Those run wherever they are configured regardless of what is stored here. We would rather write that down than imply a control we have not finished building. Your answer is also stored per browser and per device, so it does not follow you to another machine.
3.2 Requests to other companies on every page load
Loading any Restock page — including this one — fetches a stylesheet and web fonts from rsms.me, and on some pages from fonts.googleapis.com and fonts.gstatic.com. These requests happen as the page renders, before any prompt is shown, and the choice described in 3.1 does not change them. They set no cookie of ours, but the request itself tells those hosts your IP address, your browser's User-Agent, and which page asked for the font. Pages with maps additionally fetch map tiles from tiles.openfreemap.org, api.maptiler.com or api.mapbox.com, and a library from unpkg.com; where error reporting is configured, the script comes from browser.sentry-cdn.com.
4. Storage keys we use
The following are representative keys the Service stores in your browser. Exact keys may evolve as the product develops.
| Key | Type | Category | Purpose | Duration |
|---|---|---|---|---|
restock-auth-session | localStorage | Strictly necessary | Keeps you signed in to your account | Until sign-out or cleared |
restock-tenant | localStorage | Strictly necessary | Remembers your selected workspace/tenant | Until changed or cleared |
restock-onboarding | localStorage | Functional | Tracks onboarding progress and dismissed tips | Persistent until cleared |
restock-demo-data | localStorage | Functional | Holds demonstration / sandbox data for the prototype | Persistent until cleared |
restock-prefs | localStorage | Functional | Remembers UI preferences (e.g., table density, theme) | Persistent until cleared |
restock-auth-users | localStorage | Strictly necessary | On a backend-free deploy, the account records created on this device — name, work email, company, phone, role, workspace, plan, and a PBKDF2-SHA-256 derived password value | Persistent until cleared |
restock-consent | localStorage | Strictly necessary | Your answer to the prompt in section 3.1, with the date and this policy's version | Until cleared, or until this policy's version changes |
restock-consent-log | localStorage | Strictly necessary | Append-only list of those answers, and of the documents named on the sign-up form when an account was created | Persistent until cleared |
5. Service worker and cache storage
Restock installs a service worker at the site root, which keeps two named caches separate from local storage. restock-v5-shell holds the application shell — HTML, JavaScript, CSS and same-origin JSON responses, which on application pages means responses containing your own business data. restock-v5-tiles holds map tiles and map libraries fetched from the third-party hosts named in section 3.2, for up to seven days each. Clearing site data or unregistering the service worker in your browser's settings removes both.
6. How to control cookies and storage
You can change your answer to the optional analytics prompt at any time here:
You can control and delete cookies and local storage through your browser settings. Most browsers let you view stored data, clear it for a specific site, and block or limit cookies. Note that blocking strictly necessary storage will prevent you from staying signed in and may stop the Service from working. To clear Restock's local storage, open your browser's site settings for the Restock domain and clear site data, or use your browser's developer tools. Clearing site data also erases the record of the answer above and of the documents you accepted at sign-up, since both are stored in this browser.
Helpful links for major browsers: Chrome, Safari, Firefox, and Edge each provide instructions in their privacy or site-settings documentation.
7. Changes to this policy
We may update this Cookie Policy as the Service evolves — for example, if we introduce server-side sessions or additional analytics. Material changes will be reflected here with an updated "Last updated" date, and the version stamp above will change, which causes the prompt in section 3.1 to be shown again.
8. Contact
Questions about this policy? Email privacy@restock.supply.