Keep every account secure, without extra friction.
Verify signups by email or phone, let customers and your team manage their own sessions, limit sign-in attempts, configure sign-in by channel, and show a cookie-consent notice, all configured from the Ordering.co Dashboard.
Account security
What you can do
Email and phone verification
Require customers to verify their email address, their phone number, or both after signup, configured from Dashboard Security settings.
Customer session management
Customers review their active sessions on the website or customer app and close one, all, or all except the current one.
Dashboard session management
Review your own recent Dashboard sessions and close one, all, or all except the current one.
One session per account
Block a new sign-in for an account that already has an active session elsewhere.
Staff app sessions
Business App and Driver App list active sessions with the same Current marker and close controls.
Channel-specific sign-in settings
Set sign-up and login configuration separately for channels such as the website, kiosk, and call center.
Staff sign-in options
Business App and Driver App accept password or one-time-code sign-in, with reCAPTCHA and password recovery by email.
Sign-in limits and bot protection
Limit login attempts and code generation by email, phone, and IP address, and protect signup and login with reCAPTCHA.
Cookie consent
Show customers a cookie-consent notice with links to your Terms of Use and Privacy Policy.
Website and customer app
Verify an email address, a phone number, or both.
Customer App and Website can require a customer to verify an email address, a phone number, or both before some signed-in screens unlock, with the requirement set from Dashboard Security settings.
- Require email verification, phone verification, or both after signup, configured from Dashboard Security settings.
- When both are required, Customer App and Website verify email first, then phone.
- Customers request a code by email or phone and enter it on the same screen; a resend option becomes available after a countdown.
- Website shows the account's current email or phone as read-only before sending the code.
- Required profile fields, such as name, are completed first; that screen is covered in Customer records.
Dashboard, website, and customer app
Let customers and your team manage their own sessions.
Customers, and you in the Dashboard, can review active sessions and close the ones no longer needed, while an account-wide setting keeps a customer to one active session at a time.
- Customers review active sessions for the website or customer app, each row showing when it was created and how long it stays valid, with the current one marked Current.
- Close one session, close all sessions, or close all except the current one.
- Closing the current session, or closing all sessions, signs the customer out.
- If tracked sessions are not yet enabled for a customer's account, the screen instead offers to turn them on.
- From Profile, review your own recent Dashboard sessions the same way, once your account uses the session-based sign-in strategy.
- An Enable Login: Block mono session user setting can limit an account to one active session by blocking a new sign-in while another session is already active.
Dashboard
Limit sign-in attempts and block bots.
Dashboard Security settings limit repeated login and verification-code attempts, and reCAPTCHA adds a bot challenge to signup and login.
- Login-attempt limits set a maximum number of attempts and a penalty duration for email, phone, and IP address.
- Code Generation Limit sets a maximum count and a time window, with its own penalty, for a receiver, IP address, email address, or the whole project.
- reCAPTCHA is configured as a Security setting, with your own credentials, and can also appear during customer and staff app sign-in.
- See Google reCAPTCHA for the versions, keys, and surfaces it protects.
Dashboard
Configure sign-up and login by channel.
Channel-specific settings let you configure sign-up and login separately for channels such as the website, kiosk, and call center.
- Each channel has its own configuration fields; a setting saved for one channel does not apply to another.
- Changes to a text, select, or password field save immediately for the selected channel.
- The selector lists Website, Kiosk, and Call Center as example channels.
Business App and Driver App
Sign in safely to the Business App and Driver App.
Business App and Driver App support password or one-time-code sign-in, with reCAPTCHA, password recovery by email, and their own session list.
- Business App accepts email or mobile phone plus password, or a one-time code by email or phone, for a confirmed Business App account.
- Driver App accepts email or cellphone plus password, or a one-time code by email or cellphone, only for an account with the Driver role.
- Both apps can require Verify reCAPTCHA before a password sign-in.
- Both apps offer password recovery by email link from the sign-in screen.
- From Profile, Business App and Driver App list active sessions with the same Current marker and close-one, close-all, and close-all-except-current actions.
- If tracked sessions are not yet enabled for an account, the same screen offers to turn them on.
Website and customer app
Ask for cookie consent before optional features load.
Turn on a cookie-consent notice that lets customers accept or opt out of the optional features it covers, separate from promotional preferences and device permissions.
- Turn on Cookie Consent Enabled in Dashboard platform settings to show the notice on supported experiences.
- Website shows a dialog with Got it and Opt Out, plus links to Terms of Use and Privacy Policy.
- Got it lets Website initialize the optional features the notice covers; Opt Out applies the supported cleanup for those features.
- The preference covers only the integrations tied to this consent mechanism, not every cookie or external service.
- Customer App can show the same accept-or-opt-out choice for optional processing beyond what the app, account, or order needs.
- The consent choice is separate from promotional email, SMS, and push preferences, and from device permissions.
How it works
From setup to the next order.
- 01Turn on verification and limits
Enable email or phone verification after signup, and set login-attempt and code-generation limits in Dashboard Security settings.
- 02Configure channels and apps
Set channel-specific sign-in rules, and confirm the sign-in options available in Business App and Driver App.
- 03Let people manage their own sessions
Customers, your team, and you review active sessions and close the ones no longer needed.
Good to know
- Verification, session, and sign-in limit settings are configured by an administrator; each project decides which channels require them.
- Closing a session signs that device out, but cleanup of push notifications and cached data on that device can take longer to finish.
Related
See all featuresSee how it fits your operation.
Start a free trial, or walk through your setup with the Ordering.co team.
Product guide: Manage account sessions