---
title: "Account security"
description: "Verify signups by email or phone, manage customer and staff sessions, limit login attempts, and configure channel sign-in and cookie consent."
canonical: https://www.ordering.co/features/account-security/
---

[Administration and security](https://www.ordering.co/features/all-features/?category=admin#feature-catalog)

# Keep every account secure, without extra friction.

Verify signups by email or phone, let customers and your team manage their own sessions, limit sign-in attempts, configure sign-in by channel, and show a cookie-consent notice, all configured from the Ordering.co Dashboard.

[Start for free](https://accounts.ordering.co/)[Book a demo](https://www.ordering.co/contact/?meeting=demo#book)

Included in every plan

Restaurant, Marketplace, and Enterprise

Works in

- Dashboard

[See pricing](https://www.ordering.co/pricing/)

Account security

## What you can do

- ### Email and phone verification

  Require customers to verify their email address, their phone number, or both after signup, configured from Dashboard Security settings.

- ### Customer session management

  Customers review their active sessions on the website or customer app and close one, all, or all except the current one.

- ### Dashboard session management

  Review your own recent Dashboard sessions and close one, all, or all except the current one.

- ### One session per account

  Block a new sign-in for an account that already has an active session elsewhere.

- ### Staff app sessions

  Business App and Driver App list active sessions with the same Current marker and close controls.

- ### Channel-specific sign-in settings

  Set sign-up and login configuration separately for channels such as the website, kiosk, and call center.

- ### Staff sign-in options

  Business App and Driver App accept password or one-time-code sign-in, with reCAPTCHA and password recovery by email.

- ### Sign-in limits and bot protection

  Limit login attempts and code generation by email, phone, and IP address, and protect signup and login with reCAPTCHA.

- ### Cookie consent

  Show customers a cookie-consent notice with links to your Terms of Use and Privacy Policy.

Website and customer app

## Verify an email address, a phone number, or both.

Customer App and Website can require a customer to verify an email address, a phone number, or both before some signed-in screens unlock, with the requirement set from Dashboard Security settings.

- Require email verification, phone verification, or both after signup, configured from Dashboard Security settings.
- When both are required, Customer App and Website verify email first, then phone.
- Customers request a code by email or phone and enter it on the same screen; a resend option becomes available after a countdown.
- Website shows the account's current email or phone as read-only before sending the code.
- Required profile fields, such as name, are completed first; that screen is covered in Customer records.

Dashboard, website, and customer app

## Let customers and your team manage their own sessions.

Customers, and you in the Dashboard, can review active sessions and close the ones no longer needed, while an account-wide setting keeps a customer to one active session at a time.

- Customers review active sessions for the website or customer app, each row showing when it was created and how long it stays valid, with the current one marked Current.
- Close one session, close all sessions, or close all except the current one.
- Closing the current session, or closing all sessions, signs the customer out.
- If tracked sessions are not yet enabled for a customer's account, the screen instead offers to turn them on.
- From Profile, review your own recent Dashboard sessions the same way, once your account uses the session-based sign-in strategy.
- An Enable Login: Block mono session user setting can limit an account to one active session by blocking a new sign-in while another session is already active.

Dashboard

## Limit sign-in attempts and block bots.

Dashboard Security settings limit repeated login and verification-code attempts, and reCAPTCHA adds a bot challenge to signup and login.

- Login-attempt limits set a maximum number of attempts and a penalty duration for email, phone, and IP address.
- Code Generation Limit sets a maximum count and a time window, with its own penalty, for a receiver, IP address, email address, or the whole project.
- reCAPTCHA is configured as a Security setting, with your own credentials, and can also appear during customer and staff app sign-in.
- See Google reCAPTCHA for the versions, keys, and surfaces it protects.

Dashboard

## Configure sign-up and login by channel.

Channel-specific settings let you configure sign-up and login separately for channels such as the website, kiosk, and call center.

- Each channel has its own configuration fields; a setting saved for one channel does not apply to another.
- Changes to a text, select, or password field save immediately for the selected channel.
- The selector lists Website, Kiosk, and Call Center as example channels.

Business App and Driver App

## Sign in safely to the Business App and Driver App.

Business App and Driver App support password or one-time-code sign-in, with reCAPTCHA, password recovery by email, and their own session list.

- Business App accepts email or mobile phone plus password, or a one-time code by email or phone, for a confirmed Business App account.
- Driver App accepts email or cellphone plus password, or a one-time code by email or cellphone, only for an account with the Driver role.
- Both apps can require Verify reCAPTCHA before a password sign-in.
- Both apps offer password recovery by email link from the sign-in screen.
- From Profile, Business App and Driver App list active sessions with the same Current marker and close-one, close-all, and close-all-except-current actions.
- If tracked sessions are not yet enabled for an account, the same screen offers to turn them on.

Website and customer app

## Ask for cookie consent before optional features load.

Turn on a cookie-consent notice that lets customers accept or opt out of the optional features it covers, separate from promotional preferences and device permissions.

- Turn on Cookie Consent Enabled in Dashboard platform settings to show the notice on supported experiences.
- Website shows a dialog with Got it and Opt Out, plus links to Terms of Use and Privacy Policy.
- Got it lets Website initialize the optional features the notice covers; Opt Out applies the supported cleanup for those features.
- The preference covers only the integrations tied to this consent mechanism, not every cookie or external service.
- Customer App can show the same accept-or-opt-out choice for optional processing beyond what the app, account, or order needs.
- The consent choice is separate from promotional email, SMS, and push preferences, and from device permissions.

How it works

## From setup to the next order.

1. 01**Turn on verification and limits**

   Enable email or phone verification after signup, and set login-attempt and code-generation limits in Dashboard Security settings.

2. 02**Configure channels and apps**

   Set channel-specific sign-in rules, and confirm the sign-in options available in Business App and Driver App.

3. 03**Let people manage their own sessions**

   Customers, your team, and you review active sessions and close the ones no longer needed.

## Good to know

- Verification, session, and sign-in limit settings are configured by an administrator; each project decides which channels require them.
- Closing a session signs that device out, but cleanup of push notifications and cached data on that device can take longer to finish.

## Related

- [Account login and guest checkout](https://www.ordering.co/features/account-login-and-guest-checkout/)
- [Customer records](https://www.ordering.co/features/customer-records/)
- [Platform security](https://www.ordering.co/features/platform-security/)
- [User roles and permissions](https://www.ordering.co/features/user-roles-and-permissions/)
- [Google reCAPTCHA](https://www.ordering.co/integrations/google-recaptcha/)

[See all features](https://www.ordering.co/features/all-features/#feature-catalog)

## See how it fits your operation.

Start a free trial, or walk through your setup with the Ordering.co team.

Product guide: [Manage account sessions](https://docs.ordering.co/docs/products/website/account/sessions/)

[Start for free](https://accounts.ordering.co/)[Book a demo](https://www.ordering.co/contact/?meeting=demo#book)
