Cookies
This is a translation provided for your convenience. The Italian version is the legally binding one: read it here.
In short
There is almost nothing to declare here, and that's good news.
No profiling cookies. No advertising. No third-party analytics tools: no Google Analytics, no Hotjar, no Meta, LinkedIn or TikTok pixels. The public pages write a single one, technical, and only if you press the language button yourself. Inside the software there are five, all technical: one you meet at every login, the other four only in specific situations. You'll find them listed below, one by one, with name and duration.
That's why no banner comes up asking for your consent: everything that ends up on your device is technical and is there to run something you asked for. For this kind of thing the law asks for information, not consent, and the information is this page, which is part of our privacy notice: there you'll find your rights and the rest of the picture.
What a cookie is
A cookie is a small piece of text that a site stores in your browser and has sent back with every page you open. It's there to be recognized, for example to remember that you have already logged in, so it doesn't ask you for the password at every click.
There are technical cookies, which are there to make things work, and profiling cookies, which are there to follow you around the web and sell you advertising. We use only the first kind.
A site can store something on your device without cookies too, for example in the browser's local memory, the localStorage. The tool changes, the rule doesn't: art. 122(1) of the Italian Privacy Code (Legislative Decree 196/2003) covers every form of storing information on your device, not only cookies, and the guidelines of the Italian data protection authority of 10 June 2021 say so in plain words. So below we tell you everything we store, cookie or not.
Two different things: the pages and the software
- The public pages. These are the pages that present Muffin Staff on muffin-suite.com/muffin-staff/, plus turnipizzeria.it, turniristorante.com, turnibar.it and turnigelateria.it, with their aliases and www variants, which do nothing but point back here. The rest of muffin-suite.com has a cookie page of its own.
- The software. It's muffin-staff.it. There is no shop window there: that domain is the application, from the first page to the last. Before you log in it writes neither cookies nor local storage lines on your device.
The public pages
These pages set one cookie only, ours, technical, and only if you ask for it by pressing IT or EN at the top of the page. There are no third-party ones. The other thing that stays in your browser is your acknowledgement of the notice at the bottom of the page, stored in localStorage under a different name for each domain.
| What gets stored | Where | What it's for | How long |
|---|---|---|---|
| lingua (a real cookie) | muffin-suite.com, including these Muffin Staff pages | remembering whether you chose to read in Italian or in English. It holds a single word, "it" or "en". If you don't press that button it never gets written, and whoever doesn't press it carries no cookie at all | one year, or until you clear the site data from your browser |
| muffin_staff_cookie_note | the Muffin Staff pages on muffin-suite.com/muffin-staff/ | remembering that you have already pressed "Got it" on the notice at the bottom of the page, so it isn't shown to you again | until you clear the site data from your browser |
| pizzeria_cookie_note | turnipizzeria.it | same thing | until you clear the site data from your browser |
| ristorante_cookie_note | turniristorante.com | same thing | until you clear the site data from your browser |
| bar_cookie_note | turnibar.it | same thing | until you clear the site data from your browser |
| gelateria_cookie_note | turnigelateria.it | same thing | until you clear the site data from your browser |
The lingua cookie holds neither your name nor an identifier: it holds the language you chose, and nothing else. It reaches our server with every page, and that is its whole purpose — it's the server that decides which language to answer you in. No consent is needed, because it is strictly necessary to give you something you asked for by pressing that button (art. 122(1) of the Italian Privacy Code, which exempts technical cookies).
The value stored by the notice is the word "seen". It holds no name of yours and no identifier. It never reaches us: the only thing that reads it is the page script, on your device, and only to decide whether to show you the notice again. It is never sent to our server, at any point. No consent is needed here either, because that line is strictly necessary to give you something you asked for, namely not seeing again a notice you have already closed; the legal basis is our legitimate interest in not repeating it on every page (art. 6(1)(f) GDPR).
The security rule on the pages
The fonts and the images of the site are hosted on our own domain, not taken from outside servers. The pages also carry a security rule, the Content-Security-Policy, which starts from default-src 'self', that is our domain only, and allows a single exception: an address of ours on api.muffin-suite.com, unused today.
Be careful about what that really means: the rule allows that connection, it's the code of the pages that never starts it. Here is the fact you can check: when you open a page your browser downloads only files from this domain, and on its own it contacts nobody else.
The security rule of the software on muffin-staff.it authorizes no outside destination at all. The only door to the outside is the "Message us on WhatsApp" button on the Support page, and it's a link, not an automatic call: nothing starts until you press it yourself. If you press it, WhatsApp opens with a message already written, carrying your name and the name of your venue, and from that moment WhatsApp's own notice applies too, WhatsApp being run by Meta Platforms Ireland.
The server logs
Like any site, our server notes in a log file the IP address a request comes from, the date and time, the page asked for and the type of browser. It isn't a cookie and it has nothing to do with your device, but it happens on every visit, so we tell you. The logs are there to run the service and to defend it from abuse: the legal basis is legitimate interest (art. 6(1)(f) GDPR). We don't use them to profile you and we don't cross them with anything else. We keep them for 90 days, then they are deleted: it's the same term for the web server logs, for the software's own logs and for the activity log.
The site and the software are hosted on servers of OVH SAS, in France, so inside the European Union. OVH processes the data as a data processor on our behalf and makes available to its customers a data processing agreement under art. 28 GDPR, attached to the contract and available on request, which includes the standard contractual clauses of Implementing Decision (EU) 2021/914 for any transfers. It is the only supplier that processes personal data on our behalf: no data leaves the European Union.
How you write to us
On these pages there is no form to fill in. To talk to us there are the direct contacts: WhatsApp, the phone 352 012 5997 and the email info@muffin-suite.com. They are links: until you press them yourself nothing starts, and nothing stays on your device.
If you write to us you do it with your own tools, your phone or your mail program, and what you write arrives straight in our mailbox or on our phone. If you press the WhatsApp button you go into WhatsApp, and from there Meta's notice applies too.
The software, once you're logged in
Inside Muffin Staff there are five cookies, all technical. None of them is there to profile you or to measure how much you use the software.
The one you meet at every login
| Name | What it's for | How long | Attributes |
|---|---|---|---|
| sessione_muffin | keeping you logged in after you have entered email and password, so it doesn't ask for them again on every page | 12 hours, that is a whole shift. It becomes 30 days if you tick "Remember me on this device" | signed, HttpOnly, SameSite=Lax, Secure when you're on HTTPS |
The other four, only in specific situations
| Name | When it shows up and what it's for | How long | Attributes |
|---|---|---|---|
| azienda_gestita | when the Muffin Suite administrator goes into the management of a venue: it remembers which venue they are looking at. It never reaches owners or employees, and for anyone who isn't an administrator it is ignored anyway | 30 days | signed, HttpOnly, SameSite=Lax, Secure when you're on HTTPS |
| schermo_timbrature | when the owner enables a tablet or a monitor on the wall to show the clock-in QR codes without keeping their own session open. There is no user inside it: only the venue and the name of the station. It's built that way on purpose, because whoever picks up that tablet must not be able to reach wages and employee records | 6 months. It isn't removed with "Log out": it's removed with "Turn off screen", from the same device | signed, HttpOnly, SameSite=Lax, Secure when you're on HTTPS |
| muffin_password_iniziale | showing once only, to whoever is creating a person's account, the initial password just generated. It sits in a cookie and not in the page address, because in the address it would end up in the server logs and in the browser history. It holds that password in the clear, and for that reason it lasts a very short time: it is deleted as soon as the screen has shown it to you. The employee never sees it | 120 seconds, that is two minutes, then it expires on its own | HttpOnly, SameSite=Lax, Secure when you're on HTTPS, valid only inside the Employee records section |
| muffin_password_titolare | same thing, for the initial password of an owner created by the Muffin Suite administrator | 120 seconds, that is two minutes, then it expires on its own | HttpOnly, SameSite=Lax, Secure when you're on HTTPS, valid only inside the Administration section |
On support it's worth being precise: the administrator goes into the management of a venue when it's needed for support or for a technical job, is authorized personnel bound to confidentiality, and every entry stays written in the venue's activity log, with date, time and the name of whoever went in. The cookie is only there to remember which venue they are looking at.
What those words mean
Signed: the content carries the signature of a key of ours, so nobody can change it without the server noticing and throwing it away. It doesn't mean encrypted: what keeps it unreadable to the scripts of the page is HttpOnly, here below. HttpOnly: no script of the page can read it, only the server handles it. SameSite=Lax: if another site tries to start an operation on your account without your knowing, the cookie isn't attached; it does still count when it's you following a link and landing on the page. It's the defense against the attacks where a third-party site acts in your place. Secure: it only travels over an encrypted connection.
If you leave with "Log out", the session cookie is deleted and the session is invalidated on the server side as well: a copy of the cookie that has ended up somewhere else stops working anyway. The same happens when you change your password.
On what legal basis
The session cookie holds up a login you asked for: the basis is the performance of the contract and of the service requested, art. 6(1)(b) GDPR. When the one logging in is an employee, the data controller is the venue that hired them and we process that data as a processor, on the controller's documented instructions (art. 28(3)(a) GDPR). On the same basis stand the cookie for the clock-in screen, which the owner switches on whenever they want, and the cookie for the initial password of a person in the employee records: they are there to hand over a credential the owner asked for. The cookie for an owner's password, which the Muffin Suite administrator generates, rests instead on the contractual relationship between you and us (art. 6(1)(b) GDPR). The support cookie answers our legitimate interest in being able to help you and to work on the service (art. 6(1)(f) GDPR), always within the perimeter of art. 28.
If the software is installed on your company's PC
If you don't use the cloud version, these cookies are there all the same, but they are set by the software running on your own machine, inside your own network. They don't pass through us: we don't see them, we don't receive them and we have no access to anything on that computer.
A warning we want to give you. In local installations the Secure attribute only kicks in if the software is reached over HTTPS. Without HTTPS the session cookie, which is the credential your employees are recognized by, travels in the clear on the company network, and anyone connected to that network can read it. We advise you to turn on HTTPS on the internal network too, and in any case not to expose the software to the internet without encryption. The setup of the network belongs to the company, which is the controller of that data: it's a security measure that falls to you (art. 32 GDPR). We tell you here because it's our duty to warn you about the risks of a setup we put in your hands.
Who answers for what
There are three different situations and it's best not to mix them up.
- The public pages and the shift sites: the data controller is Antonio Fuccillo, sole trader, who publishes the site and whose full details are in the legal notice. This is where the notice's localStorage and the server logs belong.
- The cookies inside the cloud software: they are set by the software on behalf of your company, which is the data controller in its capacity as employer. We handle them as processors under art. 28 GDPR, following the instructions of the data processing agreement you sign together with the contract, which the terms talk about.
- The software installed by you: the controller is you and nobody else. We don't process that data, except for a support job you ask us for, and in that case we act as processors.
Why there's no banner
Consent is needed for what isn't indispensable: advertising cookies, third-party analytics tools, everything that follows you from one site to the next. We have none of it.
What we store is technical and is there to give you a service you asked for: getting into your account, keeping the clock-in screen on, not seeing again a notice you have already closed. For these cases art. 122(1) of the Italian Privacy Code (Legislative Decree 196/2003, which implements art. 5(3) of directive 2002/58/EC) asks for no consent, and the cookie guidelines of the Italian data protection authority of 10 June 2021 confirm it. What the law does ask for is information: you're reading it, and it's the reason this page exists.
Consent, in short, makes sense only where there is something to consent to. Here there isn't, and it seemed right to explain why instead of putting a useless button in front of you.
The clock-in QR code
The token inside the QR code isn't a cookie, so it isn't the subject of this page; we explain it here because we get asked often. The device that shows that code, on the other hand, has everything to do with it: it's the tablet or the monitor enabled with the schermo_timbrature cookie described above.
The code changes every 30 seconds (the server also accepts the one from the previous 30 seconds, to give you time to point your camera at it). There are three things inside it: the 30-second window, the name of the station (for example "till" or "kitchen") and the signature of the server. No name, no identifier of the person, no location. It doesn't pick up your location and it doesn't switch on the GPS. It's there to prove one thing only: that at that moment you were in front of that code, and that our server issued that code.
The clock-ins that come out of it are personal data of the workers, and their processing is described in the notice the company hands to its own employees, of which the company is the controller.
How to manage cookies from your browser
The control is yours, always. Every browser lets you see the cookies stored, delete them and block new ones. The item is usually in Settings, under "Privacy and security": on Chrome, Firefox, Safari and Edge the name changes, not the substance. In the same screen you can clear the site data, and with that goes the localStorage line described above: the notice at the bottom of the page will come back, that's all.
A practical warning. If you block technical cookies, or the ones from muffin-staff.it, the software stops working: you log in, the page reloads and you find yourself in front of the password prompt again, forever. It isn't a fault and it's the same for any business software. If it happens to you, check the browser extensions that block cookies as well, and private browsing with the strictest settings.
Your rights
The rights you can exercise over the data we are the controller of, their limits and the way to turn to the Garante are all described in the privacy notice: that's where you'll find them, so we don't tell you the same thing in two different places. To exercise them just write to info@muffin-suite.com.
If you're an employee and the data concerns your work inside the software, the rights are exercised towards your employer, who is the controller of it; we help them answer, but we can't decide in their place.
Who you can contact
Data controller for the site, the contract and invoicing: Antonio Fuccillo, sole trader, Via Molini 26, 36055 Nove (VI), Italy. P IVA 04650850243. Email info@muffin-suite.com, certified email antonio.fuccillo@pec.it, phone +39 352 012 5997, support Monday to Friday from 9:00 to 18:00. The other details of who publishes the site are in the legal notice.
We haven't appointed a data protection officer: why, and the criteria by which we review that choice, are in the privacy notice. Do write to the address above: a person answers.
On your employees' data inside the software the controller is you, being the employer, and we are the processor on your behalf under art. 28 GDPR. We talk about it in the privacy notice and in the data processing agreement you sign together with the contract, which the terms talk about.
If we change something
If one day we add a cookie, or anything else that gets stored on your device, we'll update this page first and change the date below. If we ever bring in something that isn't technical, then yes, we'll ask for your consent, before and not after. Nothing of the sort is planned right now.
Last updated: August 4, 2026