SmartRep Cookie and device-storage notice
_Last updated: 17 September 2026_ This notice explains the cookies and similar browser-storage technologies used by the SmartRep website and application.
The short version
SmartRep does not use advertising cookies, audience measurement, behavioural analytics, tracking pixels or social-media trackers. SmartRep itself sets no marketing cookies or tracking identifiers. Cloudflare's security layer may use a strictly necessary cookie when it presents a security challenge. Visiting SmartRep may also install the service worker and static PWA application-shell cache described below.
The application uses limited first-party device storage to keep an authorised user signed in, support its PWA app shell and protect an unsent case capture if the network fails. Public signup and the website contact form load Cloudflare Turnstile solely to prevent automated abuse.
These functions are used only to provide or secure the service requested by the user. SmartRep therefore does not display a cookie-consent banner. Irish ePrivacy rules still require clear information about the technology and its purpose, which this notice provides. If SmartRep adds any non-essential storage or tracking, it will be kept off until the user has made a valid choice.
Storage used by the SmartRep application
| Name and technology | Purpose | When used | Lifetime |
|---|---|---|---|
td_crm_token (first-party Local Storage) | Holds the signed session token that authenticates the user and identifies their SmartRep account and office. It is not a tracking identifier. | After a successful login | Removed on logout. The server rejects it after a maximum of seven days and the application removes it on the next failed validation. |
td_crm_offline_reps (first-party Local Storage) | Temporarily protects a case capture entered while the device cannot reach SmartRep, so it can be submitted only to the same office and by the same user when connectivity returns. It can contain the case information entered by the user. | Only when a case submission fails for a retryable network or service reason | Each queued item is removed after successful submission. Clearing site data removes any unsent items. |
td_crm_offline_reps_quarantine (first-party Local Storage) | Safely separates older offline captures that pre-date office and user scoping so they cannot be submitted into the wrong account. It can contain the case information originally entered by the user. | Only when the application finds a legacy offline capture whose office and user cannot be verified | Kept on that device for manual recovery with help from SmartRep support. It is not submitted automatically. Clearing site data permanently removes it. |
smartrep_theme_v1 (first-party Local Storage) | Remembers whether the user selected the light or dark appearance. It contains only the word light or dark and is not used for tracking. | When a signed-in user changes the appearance | Kept until the user changes the appearance again or clears site data. |
smartrep_new_rep_draft_v1 with the signed-in office and user identifiers (first-party Session Storage) | Protects a partly completed Log a Rep form while the same user signs in again after their session expires. It can contain the case information entered by the user. | While an authorised user has started but not yet submitted a case | Scoped to the signed-in office and user. Removed after a successful submission or offline queue save, when the browser tab is closed, or when site data is cleared. |
| SmartRep app shell (service worker, Cache Storage and browser registration data) | Stores the application code, styles, icons and fonts needed for installation and reliable loading as a PWA. It does not cache API responses or customer casework. | When a user visits the SmartRep application routes | Updated automatically when a new application version is installed; otherwise retained until site data is cleared or the PWA is uninstalled. |
SmartRep does not read these items across other websites and does not use them to measure user behaviour. On a shared or managed device, the office should use device access controls and the user should log out when finished. A scoped unsent offline capture remains on that device until it syncs or site data is cleared. A quarantined legacy capture remains until it is manually recovered or site data is cleared.
Public forms and Cloudflare Turnstile
The /signup page and website contact form load a managed Cloudflare Turnstile widget from challenges.cloudflare.com. Turnstile examines browser and network signals needed to distinguish a person from an automated submission. Cloudflare states that Turnstile does not access, store or transmit the form entries or other communications entered on the page.
SmartRep uses the resulting short-lived token only to validate the relevant submission. Turnstile pre-clearance is not used, so SmartRep does not ask Cloudflare to place a cf_clearance cookie on the SmartRep domain. Any technical storage used within the Turnstile challenge is used only for this security purpose, not advertising or SmartRep product analytics.
Cloudflare's current information is available in its Turnstile documentation and privacy policy.
Cloudflare traffic security
Cloudflare sits in front of the SmartRep website and application as the HTTPS reverse proxy, content-delivery and security layer. It processes web requests and responses in transit and related traffic metadata. If Cloudflare presents a security challenge, it may use a strictly necessary security cookie on the SmartRep domain. SmartRep does not use that cookie for advertising or product analytics. Cloudflare documents its current cookies in its cookie documentation.
Map tiles from OpenStreetMap
When an authorised user opens the SmartRep map, the browser requests the visible map tiles directly from tile.openstreetmap.org. The OpenStreetMap Foundation can therefore receive technical request information including the user's IP address, browser and device type, operating system, referring page, request time and the map tiles requested. The requested tile coordinates necessarily indicate the general map area being viewed.
SmartRep does not put case records, constituent names, contact details, Eircodes or case notes into those requests. The map is not loaded on the marketing site or the public signup flow. OpenStreetMap handles its service records under its own privacy policy and tile usage policy.
Stripe Checkout
SmartRep does not embed Stripe's scripts on its own pages. After verification, the user may choose to continue to Stripe's separately hosted Checkout page. Stripe controls the cookies and storage on that page under its own Cookie Policy and cookie settings.
Managing device storage
Browser controls can show or clear the Local Storage, Cache Storage, service worker and cookies associated with smart-rep.org. Logging out removes the SmartRep session token. Clearing site data or uninstalling the PWA removes locally stored application data, but will also permanently discard any offline case capture that has not yet synced and any quarantined legacy capture that has not been manually recovered.
If SmartRep changes
Before adding analytics, advertising, cross-site tracking or another non-essential browser-storage purpose, SmartRep will:
- update this notice and the Privacy Policy;
- assess the new provider and any international transfer;
- prevent the technology from loading before a valid consent choice; and
- provide an equally easy way to refuse or withdraw consent.
Contact
Questions about cookies or device storage can be sent to [email protected].
The Irish Data Protection Commission publishes guidance on cookies and similar technologies.