Cookies
One cookie. It keeps you signed in.
Last updated LAST UPDATED
This page would normally be long. It is short because there is almost nothing on this site to describe.
1 value is still blank. This page cannot be published until each one is filled in and a solicitor has read the result. Every blank is drawn like THIS so it cannot be missed in a proof read. Nothing here has had a legal review.
01The one cookie
- sid
- Keeps you signed in, and carries the token that protects forms against cross-site request forgery. Set when you sign in, cleared when you sign out. It holds a random identifier and nothing about you. Marked HttpOnly, Secure and SameSite, so a script cannot read it and another site cannot send it.
That is the complete list. There is no second cookie for the form protection because the token is derived from this one.
02Why there is no banner
A cookie that is strictly necessary for a service you asked for does not require consent under the Privacy and Electronic Communications Regulations. The sign-in cookie is that, and it is the only one, so there is nothing to ask you about.
Consent banners exist because sites set cookies people would refuse if asked. We would rather not set those cookies than build the machinery for asking.
03What we do not set
- No analytics of any kind. We do not know which pages you read.
- No advertising or remarketing cookies, and no advertising anywhere.
- No session recording or heatmaps.
- No social media pixels, and no share buttons that call home.
- No fonts, scripts, images or stylesheets loaded from another company's servers on the signed-in application.
The last one has a caveat we would rather state than hide: the public pages currently load two typefaces from Google Fonts, which means Google sees the address of the page and your IP address on your first visit. We intend to serve those files ourselves before launch, which removes it. It is recorded as an open item rather than left for somebody to discover.
04Other storage on your device
The offline companion keeps your records on the device itself, so that you can write down what you did in a field with no signal. That is storage on your own hardware rather than a cookie, it is never sent anywhere except to sync with your own account, and clearing the app's data removes it.
Your unit and language preferences are held against your account rather than in a cookie, so they follow you to another device.
05If this ever changes
If we later add analytics, it will be off until you turn it on, it will never load on a signed-in page, and this page and the privacy notice will say exactly what it sets before it is switched on for anybody.
The reason for the signed-in exclusion is worth spelling out: a page inside the application can show a horse's health history, its microchip number and the yard it lives at. That is not something we are willing to hand to a third party in order to find out which button is popular.