Administration and security

Keep every account secure, without extra friction.

Verify signups by email or phone, let customers and your team manage their own sessions, limit sign-in attempts, configure sign-in by channel, and show a cookie-consent notice, all configured from the Ordering.co Dashboard.

Account security

What you can do

  • Email and phone verification

    Require customers to verify their email address, their phone number, or both after signup, configured from Dashboard Security settings.

  • Customer session management

    Customers review their active sessions on the website or customer app and close one, all, or all except the current one.

  • Dashboard session management

    Review your own recent Dashboard sessions and close one, all, or all except the current one.

  • One session per account

    Block a new sign-in for an account that already has an active session elsewhere.

  • Staff app sessions

    Business App and Driver App list active sessions with the same Current marker and close controls.

  • Channel-specific sign-in settings

    Set sign-up and login configuration separately for channels such as the website, kiosk, and call center.

  • Staff sign-in options

    Business App and Driver App accept password or one-time-code sign-in, with reCAPTCHA and password recovery by email.

  • Sign-in limits and bot protection

    Limit login attempts and code generation by email, phone, and IP address, and protect signup and login with reCAPTCHA.

  • Cookie consent

    Show customers a cookie-consent notice with links to your Terms of Use and Privacy Policy.

Website and customer app

Verify an email address, a phone number, or both.

Customer App and Website can require a customer to verify an email address, a phone number, or both before some signed-in screens unlock, with the requirement set from Dashboard Security settings.

  • Require email verification, phone verification, or both after signup, configured from Dashboard Security settings.
  • When both are required, Customer App and Website verify email first, then phone.
  • Customers request a code by email or phone and enter it on the same screen; a resend option becomes available after a countdown.
  • Website shows the account's current email or phone as read-only before sending the code.
  • Required profile fields, such as name, are completed first; that screen is covered in Customer records.

Dashboard, website, and customer app

Let customers and your team manage their own sessions.

Customers, and you in the Dashboard, can review active sessions and close the ones no longer needed, while an account-wide setting keeps a customer to one active session at a time.

  • Customers review active sessions for the website or customer app, each row showing when it was created and how long it stays valid, with the current one marked Current.
  • Close one session, close all sessions, or close all except the current one.
  • Closing the current session, or closing all sessions, signs the customer out.
  • If tracked sessions are not yet enabled for a customer's account, the screen instead offers to turn them on.
  • From Profile, review your own recent Dashboard sessions the same way, once your account uses the session-based sign-in strategy.
  • An Enable Login: Block mono session user setting can limit an account to one active session by blocking a new sign-in while another session is already active.

Dashboard

Limit sign-in attempts and block bots.

Dashboard Security settings limit repeated login and verification-code attempts, and reCAPTCHA adds a bot challenge to signup and login.

  • Login-attempt limits set a maximum number of attempts and a penalty duration for email, phone, and IP address.
  • Code Generation Limit sets a maximum count and a time window, with its own penalty, for a receiver, IP address, email address, or the whole project.
  • reCAPTCHA is configured as a Security setting, with your own credentials, and can also appear during customer and staff app sign-in.
  • See Google reCAPTCHA for the versions, keys, and surfaces it protects.

Dashboard

Configure sign-up and login by channel.

Channel-specific settings let you configure sign-up and login separately for channels such as the website, kiosk, and call center.

  • Each channel has its own configuration fields; a setting saved for one channel does not apply to another.
  • Changes to a text, select, or password field save immediately for the selected channel.
  • The selector lists Website, Kiosk, and Call Center as example channels.

Business App and Driver App

Sign in safely to the Business App and Driver App.

Business App and Driver App support password or one-time-code sign-in, with reCAPTCHA, password recovery by email, and their own session list.

  • Business App accepts email or mobile phone plus password, or a one-time code by email or phone, for a confirmed Business App account.
  • Driver App accepts email or cellphone plus password, or a one-time code by email or cellphone, only for an account with the Driver role.
  • Both apps can require Verify reCAPTCHA before a password sign-in.
  • Both apps offer password recovery by email link from the sign-in screen.
  • From Profile, Business App and Driver App list active sessions with the same Current marker and close-one, close-all, and close-all-except-current actions.
  • If tracked sessions are not yet enabled for an account, the same screen offers to turn them on.

How it works

From setup to the next order.

  1. 01Turn on verification and limits

    Enable email or phone verification after signup, and set login-attempt and code-generation limits in Dashboard Security settings.

  2. 02Configure channels and apps

    Set channel-specific sign-in rules, and confirm the sign-in options available in Business App and Driver App.

  3. 03Let people manage their own sessions

    Customers, your team, and you review active sessions and close the ones no longer needed.

Good to know

  • Verification, session, and sign-in limit settings are configured by an administrator; each project decides which channels require them.
  • Closing a session signs that device out, but cleanup of push notifications and cached data on that device can take longer to finish.

Related

See all features

See how it fits your operation.

Start a free trial, or walk through your setup with the Ordering.co team.

Product guide: Manage account sessions