1 Who We Are
EMLOCA ("Employee Locator") operates the domain emloca.com as data controller. This Cookie Policy applies to all cookies, browser storage, and similar tracking technologies used on the EMLOCA website and web application.
By continuing to use our website or logging into the platform, you acknowledge this Policy. Where law requires your consent before placing non-essential cookies, we will request it explicitly.
2 What Are Cookies
Cookies are small text files that a website stores on your browser or device when you visit. They help the site remember information about your session — such as that you are logged in — across page loads and browser restarts (for persistent cookies).
We also use browser local storage, which is similar to cookies but stored within your browser rather than sent in HTTP headers. EMLOCA uses local storage exclusively to maintain your authenticated session on the web dashboard.
We distinguish between:
- Session storage: Cleared when you close the browser tab.
- Persistent storage: Retained for a defined period, even after the browser is closed.
- First-party storage: Set directly by emloca.com.
- Third-party cookies: Set by external services we use (see Section 5).
3 Storage We Use
EMLOCA keeps its storage footprint minimal. We use two categories:
Category A Strictly Necessary
These are essential for the platform to function. They enable authentication and security. They cannot be disabled without breaking login and dashboard functionality.
| Name | Type | Purpose | Duration |
|---|---|---|---|
| hut_token | localStorage | JWT authentication token. Identifies your authenticated session and authorizes access to the dashboard and API. Generated on login, cleared on logout. | Up to 7 days (or until logout) |
| PHPSESSID | Cookie (HTTP) | Standard PHP session identifier. Used by the server to associate HTTP requests with a session context. Does not contain personal data. | Session (cleared on browser close) |
Category B Functional / Preferences
These improve your experience by remembering preferences. They are not strictly required to use EMLOCA, but enhance usability.
| Name | Type | Purpose | Duration |
|---|---|---|---|
| emloca_ui_prefs | localStorage | Stores your dashboard preferences: sidebar collapse state, active map layer, selected employee filters. Allows the dashboard to restore your preferred layout between sessions. | 1 year (or until cleared) |
| cookie_consent | Cookie (HTTP) | Records that you have acknowledged this Cookie Policy so we do not display the notice repeatedly. | 1 year |
4 Legal Basis for Storage
| Category | Legal Basis (GDPR) | California (CCPA) |
|---|---|---|
| Strictly Necessary (A) | Legitimate interest / Contractual necessity — without these, the service cannot function | Not subject to opt-out; necessary for service delivery |
| Functional (B) | Legitimate interest / User consent where required under ePrivacy Directive | Not sold or shared for cross-context behavioral advertising |
For GDPR purposes: processing under legitimate interest has been assessed as not overriding users' fundamental rights, given the minimal, functional nature of storage used. For California residents: we do not sell personal information collected via cookies or local storage to third parties.
5 Third-Party Services
EMLOCA uses a small number of third-party services that may interact with your browser. We have selected providers that align with our minimal-tracking approach:
| Service | Purpose | Storage Impact | Their Policy |
|---|---|---|---|
| OpenStreetMap / Leaflet.js | Map tile rendering for the live employee map. Tiles are loaded directly from OpenStreetMap servers. | OpenStreetMap may set server-side logs of tile requests (your IP, tile coordinates). No cookies set by Leaflet.js itself. | osmfoundation.org |
| Let's Encrypt | SSL/TLS certificate authority that secures emloca.com with HTTPS. | No cookies. Certificate validation happens transparently at the TLS layer. | letsencrypt.org |
| Telegram Bot API | Optional alert delivery. Only active if the Account Administrator has configured Telegram notifications. | No cookies set by Telegram in the EMLOCA dashboard. Telegram's own apps have separate cookie handling. | telegram.org |
| Google Fonts | Loads the Inter typeface used on the landing page and legal pages. | Google may set cookies or log requests when loading font files. This applies only to non-authenticated pages (landing page, legal pages), not the dashboard. | Google Privacy Policy |
| Bootstrap CDN (jsDelivr) | Loads CSS and icon fonts for the interface. | jsDelivr may log requests (IP, browser). No tracking cookies are set by jsDelivr per their privacy policy. | jsdelivr.com |
We have no control over cookies or tracking technologies used by third-party websites we may link to from our content.
6 Managing Your Cookies & Storage
Browser Settings
You can control or delete cookies through your browser settings. Instructions for major browsers:
- Chrome: Settings → Privacy and Security → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy → Manage Website Data
- Edge: Settings → Cookies and site permissions
- Opera: Settings → Advanced → Privacy & security → Site Settings → Cookies
Note: Deleting or blocking Category A (strictly necessary) storage — particularly hut_token from localStorage — will log you out of the EMLOCA dashboard and require you to sign in again.
Clearing Local Storage
To clear EMLOCA's localStorage data in Chrome or Edge: open DevTools (F12) → Application tab → Local Storage → emloca.com → delete entries, or select "Clear site data."
Platform-Level Control
You can log out of EMLOCA at any time by clicking your account menu → Logout. This clears the hut_token from localStorage and ends your session. Dashboard preference data will be cleared automatically within 1 year.
Do Not Track (DNT)
Some browsers transmit a "Do Not Track" signal. Because EMLOCA already does not use behavioral tracking, advertising cookies, or cross-site analytics, our existing practices are consistent with DNT principles regardless of the signal received.
7 International Data Transfers
EMLOCA servers are located in the United States. For users in the EEA, United Kingdom, or Switzerland, the use of cookies and local storage on our platform involves the transfer of session-related data to servers in the US. We use Standard Contractual Clauses and appropriate safeguards for such transfers where applicable.
8 Children's Privacy
EMLOCA is a business platform for users aged 18 and older. We do not knowingly use cookies to collect information from individuals under 18.
9 Updates to This Policy
We may update this Cookie Policy to reflect changes in our technology, service, or legal requirements. Material changes will be communicated by:
- Updating the effective date on this page
- Posting a notice on emloca.com for at least 30 days
- Re-requesting consent where legally required
Continued use of EMLOCA after an update constitutes acceptance of the revised Policy.
10 Contact
For questions about our cookie and storage practices, or to exercise your privacy rights:
Email: privacy@emloca.com
Response time: 30 business days
EEA residents may also contact their national data protection authority. Authorities are listed at edpb.europa.eu.