Legal

Cookie and storage notice

t-api uses no analytics or marketing cookies. This page documents the technically necessary cookies and local browser preferences used by the different t-api interfaces.

Information site

The public information site uses no analytics or marketing cookies. When the contact form is loaded, t-api sets the technically necessary host-bound __Host-portal_csrf cookie to protect submission.

Language and display are stored locally as t-api.portal-language and t-api.theme. Cloudflare Turnstile processes technical browser and request signals to prevent abuse; pre-clearance is not enabled.

Customer portal

Customer portals use __Host-portal_csrf to protect write requests and, after successful sign-in, __Host-portal_session for the host-bound session. Both cookies are technically necessary, transferred securely and inaccessible to JavaScript.

The portal session ends after no more than 12 hours or after 2 hours of inactivity. Invalid session records are deleted after no more than 30 days.

Operator admin

The operator admin, which is not linked publicly, uses separate cookies for the sign-in flow, CSRF protection and operator session.

The sign-in flow is valid for no more than 5 minutes; the operator session ends after 30 minutes of inactivity or no later than 8 hours.

PWA and Cache Storage

If the optional PWA shell is enabled for a customer portal, the browser may cache only versioned static application files and a neutral offline page.

API responses, identities, sessions, grades, attendance and other Tocco data are not persisted offline. These caches are not cookies.

Changing settings

Because no optional analytics, personalisation or marketing technologies are currently used, there is no consent category and no cookie banner with ineffective switches.

You can delete cookies, Local Storage and website data at any time in your browser settings. Technically necessary portal cookies are then set again when required.