Cookie Policy
We use very few cookies, and none for advertising. This page explains what we use, why, and how to control it.
Effective from 19 September 2026. Version 1.1.
The short version #
- We do not use advertising cookies. No ad networks, no retargeting, no tracking pixels for advertisers, no data brokers.
- We do not sell or share what we learn to anyone for their own purposes.
- Only strictly necessary cookies are set before you choose. Everything else waits for your consent.
- Rejecting is exactly as easy as accepting — same number of clicks, same prominence. Our banner does not cover the page or block you from reading it.
- You can change your mind at any time at ourpath.app/legal/cookies#settings.
1. What cookies are #
A cookie is a small file a website puts on your device so it can recognise you next time. Similar technologies — local storage, session storage, software development kits in mobile apps, and pixels in emails — do comparable things, and everything in this policy applies to them too.
2. The law we are applying #
Cookies in the UK are governed by the Privacy and Electronic Communications Regulations 2003 (PECR) as well as UK GDPR. The rule is simple: we may set a cookie without asking only where it is strictly necessary to provide a service you have asked for. Everything else needs your consent, freely given, before it is set.
Analytics cookies are not strictly necessary, whatever the industry says, so we ask.
3. What we use #
run a full cookie scan of ourpath.app, the web portal and the mobile apps, and replace every row below with what is actually set, including the real names, providers, durations and purposes. A cookie table that does not match the site is an ICO complaint waiting to happen, and it is the single easiest thing for anyone to check.
3.1 Strictly necessary — always on, no consent needed #
These make the site and the app work. Without them you could not log in or stay logged in.
| Cookie / item | Provider | Purpose | Duration |
|---|---|---|---|
sb-access-token |
OurPath (Supabase) | Keeps you signed in | {{SESSION_COOKIE_DURATION}} |
sb-refresh-token |
OurPath (Supabase) | Renews your session securely | {{REFRESH_COOKIE_DURATION}} |
| {{CSRF_COOKIE_NAME}} | OurPath | Protects against cross-site request forgery | Session |
ourpath-cookie-consent |
OurPath | Remembers your cookie choices — ironically, necessary | 12 months |
| {{ROUTING_COOKIE_NAME}} | Netlify | Routes your request to the right server | Session |
cf_clearance (only if a challenge is shown) |
Cloudflare (Turnstile) | Confirms you are a person, not a bot, on our forms | {{TURNSTILE_COOKIE_DURATION}} |
3.2 Analytics — only with your consent #
We use privacy-first analytics to understand whether the product works: whether people finish onboarding, whether plans get accepted, where people get stuck.
| Cookie / item | Provider | Purpose | Duration |
|---|---|---|---|
| {{ANALYTICS_COOKIE_NAME}} | {{ANALYTICS_VENDOR}} | Counts visits and measures funnels | {{ANALYTICS_COOKIE_DURATION}} |
What our analytics never see: message content, expense descriptions, Info Bank content, children's names, or any personal data about a child. We measure whether someone completed a step, not what they wrote in it.
3.3 Functional — only with your consent #
| Cookie / item | Provider | Purpose | Duration |
|---|---|---|---|
| {{PREFERENCE_COOKIE_NAME}} | OurPath | Remembers preferences such as your chosen view or local authority | 12 months |
3.4 Advertising — none #
We set no advertising or marketing cookies, and we do not embed third-party advertising trackers. There is no row in this table and we do not expect there to be one.
4. Cookies set by other people #
Where we embed something from another company — a video, a map, a payment form — that company may set its own cookies.
| Where | Whose | What for |
|---|---|---|
| Checkout and payment pages | Stripe | Fraud prevention and payment processing. Stripe classifies these as strictly necessary for taking a payment securely. stripe.com/cookie-settings |
| Embedded video, where used | {{EMBEDDED_VIDEO_VENDOR}} | Video playback. We load these only after consent, using a click-to-load placeholder |
We do not embed social media buttons, share widgets or comment systems, all of which track people across sites.
A note on the bot check #
Our forms are protected by Cloudflare Turnstile rather than Google reCAPTCHA. This is deliberate. reCAPTCHA would place Google advertising infrastructure on the first page a separating parent visits and feed an advertising profile; Turnstile is cookieless in normal operation and does not. It is a small choice, and it is the kind of small choice this product should keep making.
5. In the mobile apps #
The OurPath mobile apps do not use browser cookies, but they do store things on your device:
- Secure token storage for keeping you signed in (strictly necessary).
- Local preferences — your chosen view, filters, whether you dismissed a tip.
- A push notification token, if you allow notifications.
- Analytics and crash reporting, only if you have consented in the app's privacy settings.
Apple and Google may collect their own data about app installation and use, under their own policies. We do not use Apple's advertising identifier (IDFA) or Google's advertising ID, and we do not ask for App Tracking Transparency permission, because we do not track you across other companies' apps and websites.
6. Emails #
Service emails — a new message, a swap request, a renewal reminder — contain no tracking pixels. We do not need to know whether you opened them and we do not look.
Marketing emails, if you have opted in, may contain a tracking pixel so we can see whether the email was opened and whether links were clicked. Every marketing email has a one-click unsubscribe, and unsubscribing stops both the emails and the measurement.
7. Controlling cookies #
Our cookie settings #
Change your choices at any time: Cookie settings (link to the preference centre), or the cookie settings screen in the app.
Withdrawing consent is as easy as giving it. If you withdraw it, we stop setting the relevant cookies and delete those we can.
Your browser #
Every browser lets you block or delete cookies:
- Chrome — Settings → Privacy and security → Third-party cookies
- Safari — Settings → Safari → Privacy & Security
- Firefox — Settings → Privacy & Security
- Edge — Settings → Cookies and site permissions
Blocking strictly necessary cookies will stop you being able to sign in. That is not us being awkward; it is how sessions work.
Do Not Track and Global Privacy Control #
We honour the Global Privacy Control signal where your browser sends one, and treat it as a withdrawal of consent for analytics and functional cookies.
8. Our banner #
Our cookie banner:
- does not cover the content of the page, and does not stop you reading before you choose;
- offers Reject all with the same prominence and the same number of clicks as Accept all;
- does not use pre-ticked boxes, and sets nothing beyond the strictly necessary until you choose;
- does not nag you again for at least 6 months if you reject, and does not reduce functionality as a punishment for rejecting.
We are writing this down because it is the standard the ICO expects, and because a banner that behaves any other way is an admission that the analytics matter more than the person.
9. Changes #
We will update this policy when what we use changes, and we will re-ask for consent if we add anything materially new.
Version history #
| Version | Date | Change |
|---|---|---|
| 1.1 | 19 September 2026 | First published |
10. Questions #
hello@ourpath.app. For anything wider than cookies, see our Privacy Policy.
Our Path Digital Ltd · Registered in England and Wales, company number 17406043 · ICO registration ZC250261