Skip to main content
Apotheca

Cookies

Browsing the marketing site sets no cookies; only the forms' anti-robot check may set two, for the duration of a verification. The application sets three, all of them necessary either to its operation or to your comfort using it. None is advertising-related, and none follows you from one site to another.

The apotheca.ma website

https://apotheca.ma is a static site. It carries no analytics tool, no advertising pixel and no social media button capable of tracking you. Browsing sets no cookies, which is why you see no consent banner on it: there is nothing to consent to.

One exception: the contact and demo pages carry a form protected by Cloudflare Turnstile, an anti-robot check. In the common case it works without any cookie. If it does need to show you a verification, Cloudflare then sets two short-lived technical cookies: cf_chl_rc_n on our domain and cf_chl_persist on cloudflare.com, both lasting about an hour, whose only job is to remember that the check passed.

These are strictly necessary to a security service you request by submitting the form. They serve neither advertising nor analytics, and they do not follow you from one site to another. No other cookie is set on this site.

The Apotheca application

The application (https://app.apotheca.ma) sets the following three cookies:

NamePurposeDurationCategory
tokenKeeps you signed in after login. Without it the application signs you out.24 hoursStrictly necessary
temp_tokenTemporary token between entering your password and completing the second authentication factor.15 minutesStrictly necessary
sidebar_stateRemembers whether you collapsed or expanded the side menu.7 daysFunctional

Both session tokens are sent over HTTPS only and restricted to our own domain (the SameSite=Strict attribute), so that another site cannot cause them to accompany a request to the application.

Strictly necessary cookies cannot be refused without making the application unusable: they are what keeps you signed in. The sidebar_state cookie is a display preference; refusing it only means the side menu reopens on every visit.

Browser local storage

Beyond cookies, the application keeps two entries in your browser's local storage: the profile of the signed-in user (name, email, pharmacy, permissions) and, where applicable, the employee you have switched into. This data does not leave your device, is not passed to any third party, and is cleared on sign-out.

Managing cookies

You can inspect, block or delete cookies from your browser settings, usually under "Privacy" or "Site content and data". Blocking cookies for the application's domain will prevent you from signing in.

Should we one day add an analytics tool, this page will be updated and your consent sought before anything is set.

Further reading

The processing these cookies take part in is described in our privacy policy, and the providers involved on the Subprocessors page.