COOKIE & TOKEN POLICY

Last Updated: July 2026

1. SaaS Architecture & Scope

This Cookie & Token Policy governs the local browser sessions, authentication tokens, and state persistence configurations used within the Jepely SaaS platform. We utilize secure HTTP cookies, server-side session identifiers, and API authorization tokens to maintain secure operator logins, validate Google Workspace integration handshakes, store temporary BI dataset states, and deliver interactive AI dashboard builders safely.

2. Technical Classifications of Cookies & Storage Tokens

To run our web dashboard and automated CRM processing securely, Jepely utilizes the following storage categories:

Essential Session Cookies

Mandatory for core application runtime (e.g., PHP native PHPSESSID). These cookies maintain your active account login, isolate multi-tenant user contexts via Auth::check(), protect against Cross-Site Request Forgery (CSRF), and prevent unauthorized access to administrative endpoints.

OAuth Access & Refresh Tokens

Used specifically when linking external Workspace and CRM services (such as Google Sheets, Google Drive, or Meta platforms). Instead of storing raw passwords, encrypted access and refresh tokens are stored to perform authorized background synchronization actions on your behalf.

Dataset State & Workspace Context

When utilizing the AI Business Intelligence engine or external dataset uploads, temporary session states preserve operational parameters (e.g., selected active sheets, source data context, and file upload identifiers) to prevent state loss during step-by-step dashboard generation.

Security & Anti-Abuse Tracking

Cookies and request header tokens help monitor session validity, track rapid request velocity, protect API dispatchers against brute-force attacks, and maintain isolated tenant environments.

3. OAuth Credentials & Third-Party Integration Management

When connecting your account via Google OAuth or Meta Authentication to manage Google Sheets, Drive files, or social messaging endpoints:

4. Integrated API Providers

Our SaaS application securely interacts with accredited third-party API infrastructures to power automation workflows:

5. Token Lifespans & Storage Duration

Data structures maintained across the platform adhere to two main lifecycles:

6. User Control & Session Management

You may clear or block cookies via your browser's security settings. However, disabling essential session cookies will prevent you from authenticating into the Jepely dashboard, as active cryptographic tokens are required to secure user sessions and prevent unauthorized access.

7. Policy Updates

Jepely may update this policy periodically to align with browser security updates, regulatory changes, or enhancements to our API capabilities.

8. Contact & Compliance Desk

For questions regarding our session security, cookie management, or OAuth data protection, contact our infrastructure team:

Jepely Support & Architecture Desk
Email: [email protected]
Web: https://jepely.com