⚠️ DRAFT for legal review. Assembled by engineering from a direct audit of what the Verifab application sets and stores in the browser. It is not legal advice. The "no consent banner required" conclusion reflects the mainstream UK PECR / EU ePrivacy interpretation for strictly-necessary cookies plus cookieless analytics, but the final call — especially for specific EU markets whose regulators take stricter views on analytics — must be confirmed by a qualified lawyer. This conclusion holds only while the inventory below stays true (see "What would change this").
Cookie Notice
Summary
Verifab sets only strictly-necessary cookies and uses cookieless analytics. We do not
set any advertising, marketing, or cross-site tracking cookies, and we do not use browser
localStorage or sessionStorage to store data about you. Because nothing non-essential is stored
on your device, we do not show a cookie consent banner — none is legally required. You can still
object to analytics (see below).
1. Strictly-necessary cookies we set (on verifab.io)
These are required for the service to function — chiefly to keep you securely logged in. Under UK PECR reg. 6(4) (and the equivalent ePrivacy exemption), strictly-necessary cookies do not require consent.
| Cookie | Purpose | Type / duration |
|---|---|---|
sb-* (Supabase auth) |
Keeps you signed in; holds your authenticated session | Strictly necessary; session/refresh token, expires per session lifetime |
ob-done |
Remembers that account onboarding is complete, to avoid an extra database lookup on every page | Strictly necessary / functional; HTTP-only; up to 1 year |
Blocking these will break sign-in and core functionality.
2. Analytics — cookieless (Plausible)
We measure aggregate usage (e.g. page views, visitor counts) using Plausible, a privacy-friendly analytics tool that:
- sets no cookies and stores nothing on your device;
- collects no personal data and does not track you across other websites;
- is served first-party from
verifab.io(via a proxy) purely so that ad-blockers don't under-count aggregate traffic — this does not change what is collected.
Because this processing is cookieless and non-identifying, it falls outside the consent requirement for storing information on your device, and we rely on legitimate interests for statistical/measurement purposes to run it. [Under UK PECR, statistical-purposes measurement of this kind is treated as low-risk; legal to confirm framing.]
Object to analytics: although no personal data is involved, you can opt out at any time by enabling "Do Not Track" or a content/ad-blocker in your browser, which will prevent the analytics script from loading. [If you later add a self-service opt-out link, reference it here.]
3. Error monitoring — no cookies (Sentry)
We use Sentry to detect and diagnose errors so we can keep the service reliable. The Sentry
browser SDK does not set cookies, and we have disabled the sending of personal identifiers
(sendDefaultPii is off). We do not use Sentry Session Replay, which would record user sessions.
4. Payments — cookies on Stripe's domain (Stripe)
When you subscribe, checkout is handled on Stripe's own hosted checkout page. Any cookies Stripe
sets for fraud prevention and to operate checkout (e.g. __stripe_mid, __stripe_sid) are set on
Stripe's domain, not on verifab.io, and are strictly necessary to process your payment securely.
See Stripe's own privacy and cookie notices for detail. We do not embed Stripe card fields on our
own pages.
5. What we do NOT use
- ❌ No advertising or marketing cookies
- ❌ No cross-site / third-party tracking cookies
- ❌ No
localStorageorsessionStoragefor tracking (the application uses neither) - ❌ No social-media pixels or tag managers
6. Managing cookies
You can view, block, or delete cookies through your browser settings. Blocking strictly-necessary cookies will prevent you from logging in and using the platform. Blocking the analytics script has no effect on functionality.
7. What would change this conclusion
The "no banner required" position depends on the inventory above. It would need to be revisited — and a consent mechanism likely added — if Verifab ever:
- enables Sentry Session Replay (records user sessions);
- embeds client-side Stripe.js / card Elements (sets Stripe cookies on verifab.io); or
- adds any non-cookieless analytics or marketing pixel (e.g. Google Analytics, Meta, LinkedIn).
8. Contact
Questions about this notice: [privacy@verifab.io]. See also our Privacy Policy.