Legal

Cookie Policy

Effective: June 30, 2026 Version 1.0 GDPR · CCPA · ePrivacy

1 Who We Are

EMLOCA ("Employee Locator") operates the domain emloca.com as data controller. This Cookie Policy applies to all cookies, browser storage, and similar tracking technologies used on the EMLOCA website and web application.

By continuing to use our website or logging into the platform, you acknowledge this Policy. Where law requires your consent before placing non-essential cookies, we will request it explicitly.

2 What Are Cookies

Cookies are small text files that a website stores on your browser or device when you visit. They help the site remember information about your session — such as that you are logged in — across page loads and browser restarts (for persistent cookies).

We also use browser local storage, which is similar to cookies but stored within your browser rather than sent in HTTP headers. EMLOCA uses local storage exclusively to maintain your authenticated session on the web dashboard.

We distinguish between:

3 Storage We Use

EMLOCA keeps its storage footprint minimal. We use two categories:

Category A Strictly Necessary

These are essential for the platform to function. They enable authentication and security. They cannot be disabled without breaking login and dashboard functionality.

NameTypePurposeDuration
hut_token localStorage JWT authentication token. Identifies your authenticated session and authorizes access to the dashboard and API. Generated on login, cleared on logout. Up to 7 days (or until logout)
PHPSESSID Cookie (HTTP) Standard PHP session identifier. Used by the server to associate HTTP requests with a session context. Does not contain personal data. Session (cleared on browser close)

Category B Functional / Preferences

These improve your experience by remembering preferences. They are not strictly required to use EMLOCA, but enhance usability.

NameTypePurposeDuration
emloca_ui_prefs localStorage Stores your dashboard preferences: sidebar collapse state, active map layer, selected employee filters. Allows the dashboard to restore your preferred layout between sessions. 1 year (or until cleared)
cookie_consent Cookie (HTTP) Records that you have acknowledged this Cookie Policy so we do not display the notice repeatedly. 1 year
What we do NOT use: EMLOCA does not use advertising cookies, behavioral tracking cookies, social media tracking pixels, cross-site fingerprinting, analytics SDKs that phone home to third parties (such as Google Analytics), or any technology designed to build profiles for targeted advertising. We have no advertising partnerships.

4 Legal Basis for Storage

CategoryLegal Basis (GDPR)California (CCPA)
Strictly Necessary (A) Legitimate interest / Contractual necessity — without these, the service cannot function Not subject to opt-out; necessary for service delivery
Functional (B) Legitimate interest / User consent where required under ePrivacy Directive Not sold or shared for cross-context behavioral advertising

For GDPR purposes: processing under legitimate interest has been assessed as not overriding users' fundamental rights, given the minimal, functional nature of storage used. For California residents: we do not sell personal information collected via cookies or local storage to third parties.

5 Third-Party Services

EMLOCA uses a small number of third-party services that may interact with your browser. We have selected providers that align with our minimal-tracking approach:

ServicePurposeStorage ImpactTheir Policy
OpenStreetMap / Leaflet.js Map tile rendering for the live employee map. Tiles are loaded directly from OpenStreetMap servers. OpenStreetMap may set server-side logs of tile requests (your IP, tile coordinates). No cookies set by Leaflet.js itself. osmfoundation.org
Let's Encrypt SSL/TLS certificate authority that secures emloca.com with HTTPS. No cookies. Certificate validation happens transparently at the TLS layer. letsencrypt.org
Telegram Bot API Optional alert delivery. Only active if the Account Administrator has configured Telegram notifications. No cookies set by Telegram in the EMLOCA dashboard. Telegram's own apps have separate cookie handling. telegram.org
Google Fonts Loads the Inter typeface used on the landing page and legal pages. Google may set cookies or log requests when loading font files. This applies only to non-authenticated pages (landing page, legal pages), not the dashboard. Google Privacy Policy
Bootstrap CDN (jsDelivr) Loads CSS and icon fonts for the interface. jsDelivr may log requests (IP, browser). No tracking cookies are set by jsDelivr per their privacy policy. jsdelivr.com

We have no control over cookies or tracking technologies used by third-party websites we may link to from our content.

6 Managing Your Cookies & Storage

Browser Settings

You can control or delete cookies through your browser settings. Instructions for major browsers:

Note: Deleting or blocking Category A (strictly necessary) storage — particularly hut_token from localStorage — will log you out of the EMLOCA dashboard and require you to sign in again.

Clearing Local Storage

To clear EMLOCA's localStorage data in Chrome or Edge: open DevTools (F12) → Application tab → Local Storage → emloca.com → delete entries, or select "Clear site data."

Platform-Level Control

You can log out of EMLOCA at any time by clicking your account menu → Logout. This clears the hut_token from localStorage and ends your session. Dashboard preference data will be cleared automatically within 1 year.

Do Not Track (DNT)

Some browsers transmit a "Do Not Track" signal. Because EMLOCA already does not use behavioral tracking, advertising cookies, or cross-site analytics, our existing practices are consistent with DNT principles regardless of the signal received.

7 International Data Transfers

EMLOCA servers are located in the United States. For users in the EEA, United Kingdom, or Switzerland, the use of cookies and local storage on our platform involves the transfer of session-related data to servers in the US. We use Standard Contractual Clauses and appropriate safeguards for such transfers where applicable.

8 Children's Privacy

EMLOCA is a business platform for users aged 18 and older. We do not knowingly use cookies to collect information from individuals under 18.

9 Updates to This Policy

We may update this Cookie Policy to reflect changes in our technology, service, or legal requirements. Material changes will be communicated by:

Continued use of EMLOCA after an update constitutes acceptance of the revised Policy.

10 Contact

For questions about our cookie and storage practices, or to exercise your privacy rights:

EMLOCA — Privacy
Email: privacy@emloca.com
Response time: 30 business days

EEA residents may also contact their national data protection authority. Authorities are listed at edpb.europa.eu.