Cookie Policy

We use very few cookies, and none for advertising. This page explains what we use, why, and how to control it.

Effective from 19 September 2026. Version 1.1.


The short version #


1. What cookies are #

A cookie is a small file a website puts on your device so it can recognise you next time. Similar technologies — local storage, session storage, software development kits in mobile apps, and pixels in emails — do comparable things, and everything in this policy applies to them too.

2. The law we are applying #

Cookies in the UK are governed by the Privacy and Electronic Communications Regulations 2003 (PECR) as well as UK GDPR. The rule is simple: we may set a cookie without asking only where it is strictly necessary to provide a service you have asked for. Everything else needs your consent, freely given, before it is set.

Analytics cookies are not strictly necessary, whatever the industry says, so we ask.

3. What we use #

run a full cookie scan of ourpath.app, the web portal and the mobile apps, and replace every row below with what is actually set, including the real names, providers, durations and purposes. A cookie table that does not match the site is an ICO complaint waiting to happen, and it is the single easiest thing for anyone to check.

These make the site and the app work. Without them you could not log in or stay logged in.

Cookie / item Provider Purpose Duration
sb-access-token OurPath (Supabase) Keeps you signed in {{SESSION_COOKIE_DURATION}}
sb-refresh-token OurPath (Supabase) Renews your session securely {{REFRESH_COOKIE_DURATION}}
{{CSRF_COOKIE_NAME}} OurPath Protects against cross-site request forgery Session
ourpath-cookie-consent OurPath Remembers your cookie choices — ironically, necessary 12 months
{{ROUTING_COOKIE_NAME}} Netlify Routes your request to the right server Session
cf_clearance (only if a challenge is shown) Cloudflare (Turnstile) Confirms you are a person, not a bot, on our forms {{TURNSTILE_COOKIE_DURATION}}

We use privacy-first analytics to understand whether the product works: whether people finish onboarding, whether plans get accepted, where people get stuck.

Cookie / item Provider Purpose Duration
{{ANALYTICS_COOKIE_NAME}} {{ANALYTICS_VENDOR}} Counts visits and measures funnels {{ANALYTICS_COOKIE_DURATION}}

What our analytics never see: message content, expense descriptions, Info Bank content, children's names, or any personal data about a child. We measure whether someone completed a step, not what they wrote in it.

Cookie / item Provider Purpose Duration
{{PREFERENCE_COOKIE_NAME}} OurPath Remembers preferences such as your chosen view or local authority 12 months

3.4 Advertising — none #

We set no advertising or marketing cookies, and we do not embed third-party advertising trackers. There is no row in this table and we do not expect there to be one.

4. Cookies set by other people #

Where we embed something from another company — a video, a map, a payment form — that company may set its own cookies.

Where Whose What for
Checkout and payment pages Stripe Fraud prevention and payment processing. Stripe classifies these as strictly necessary for taking a payment securely. stripe.com/cookie-settings
Embedded video, where used {{EMBEDDED_VIDEO_VENDOR}} Video playback. We load these only after consent, using a click-to-load placeholder

We do not embed social media buttons, share widgets or comment systems, all of which track people across sites.

A note on the bot check #

Our forms are protected by Cloudflare Turnstile rather than Google reCAPTCHA. This is deliberate. reCAPTCHA would place Google advertising infrastructure on the first page a separating parent visits and feed an advertising profile; Turnstile is cookieless in normal operation and does not. It is a small choice, and it is the kind of small choice this product should keep making.

5. In the mobile apps #

The OurPath mobile apps do not use browser cookies, but they do store things on your device:

Apple and Google may collect their own data about app installation and use, under their own policies. We do not use Apple's advertising identifier (IDFA) or Google's advertising ID, and we do not ask for App Tracking Transparency permission, because we do not track you across other companies' apps and websites.

6. Emails #

Service emails — a new message, a swap request, a renewal reminder — contain no tracking pixels. We do not need to know whether you opened them and we do not look.

Marketing emails, if you have opted in, may contain a tracking pixel so we can see whether the email was opened and whether links were clicked. Every marketing email has a one-click unsubscribe, and unsubscribing stops both the emails and the measurement.

7. Controlling cookies #

Change your choices at any time: Cookie settings (link to the preference centre), or the cookie settings screen in the app.

Withdrawing consent is as easy as giving it. If you withdraw it, we stop setting the relevant cookies and delete those we can.

Your browser #

Every browser lets you block or delete cookies:

Blocking strictly necessary cookies will stop you being able to sign in. That is not us being awkward; it is how sessions work.

Do Not Track and Global Privacy Control #

We honour the Global Privacy Control signal where your browser sends one, and treat it as a withdrawal of consent for analytics and functional cookies.

8. Our banner #

Our cookie banner:

We are writing this down because it is the standard the ICO expects, and because a banner that behaves any other way is an admission that the analytics matter more than the person.

9. Changes #

We will update this policy when what we use changes, and we will re-ask for consent if we add anything materially new.

Version history #

Version Date Change
1.1 19 September 2026 First published

10. Questions #

hello@ourpath.app. For anything wider than cookies, see our Privacy Policy.


Our Path Digital Ltd · Registered in England and Wales, company number 17406043 · ICO registration ZC250261