Cookie notice
The current 1SCAN.LINK release uses only first-party storage required for security, login and language preference.
Operator and contact
1SCAN.LINK DemoPre-launch demo
Sofia, Bulgaria
privacy@1scan.link
1. What cookies are
Cookies are small values stored by the browser and returned to the relevant website. Similar local browser storage is covered here where it serves the same purpose. 1SCAN.LINK does not use third-party advertising or cross-site profiling cookies.
2. Authentication
The ASP.NET Identity application cookie keeps authorized business users signed in and enforces session security. It is first-party, HttpOnly, Secure in production and restricted by SameSite policy. It lasts for the configured session period or until sign-out, account closure or session revocation.
3. Request security
onescan.antiforgery and its request token protect authenticated state-changing operations from cross-site request forgery. They are first-party and strictly necessary; blocking them prevents protected changes.
4. Language
onescan.locale stores the Bulgarian or English preference. It is first-party, contains no customer or appointment data and can be replaced by changing the language.
5. Push and integrations
Browser notification permission and push subscriptions are controlled by the browser and operating system. The server stores the subscription only after opt-in; this is not an advertising cookie. Google authorization takes place on Google's domain and is governed by Google's own storage notice while that page is open.
6. Consent
Strictly necessary storage is used to provide the service and is not switched off through a consent banner. Analytics, marketing and non-essential third-party cookies are not enabled. Before introducing any such category, 1SCAN.LINK will block it by default, provide equally accessible accept and reject choices, document provider and lifetime, and allow consent to be withdrawn.
7. Controls
You can inspect, block or delete cookies in browser settings. Blocking essential cookies prevents login and protected workspace actions; public booking and legal information may remain available. Signing out and using the account session controls invalidates server-side access even if an expired browser value remains.