Cookie Policy
ETAPA LTD
Published 13 July 2026 · Last updated 13 July 2026
Please read this cookie policy carefully as it contains important information on who we are and how we use cookies on our Services. This policy should be read together with our Privacy Policy which sets out who we are, how to contact us, what data is collected, how and why we collect, store, use and share personal information generally, as well as your rights in relation to your personal information and details of how to contact us and supervisory authorities if you have a complaint.
Cookies
A cookie is a small text file which is placed onto your device (e.g. your smartphone or other electronic device) when you use our Services. When we use cookies on our Services, you will always be informed by a pop-up within the Services.
Cookies help us to recognise you and your device and allow us to store some information about your preferences or past actions, including your location data (for more information, please see our Privacy Policy).
For example, we may monitor how many times you use our Services, which parts of the Services you go to, and location data. This information helps us to understand use of the Services by our users. Some of this data will be aggregated or statistical, which means that we will not be able to identify you individually.
For further information on our use of cookies, including a detailed list of your information which we and others may collect through cookies, please see below.
For further information on cookies generally, including how to control and manage them, visit the guidance on cookies published by the UK Information Commissioner's Office, www.aboutcookies.org or www.allaboutcookies.org.
Consent to use cookies and changing settings
We will ask for your consent to place cookies or other similar technologies on your device, except where they are essential for us to provide you with a service that you have requested (e.g. to allow you to remain logged-in to the Services as you navigate within the Services and use the Services functionalities).
You can withdraw any consent to the use of cookies or manage any other cookie preferences by using the tool made available to you within the Services itself — the “Cookie settings” link in the footer of this website reopens the cookie banner. You can then adjust sliders or untick boxes as appropriate to reflect your choice. It may be necessary to refresh or restart the Services for the updated settings to take effect.
Our use of cookies
The table below provides more information about the cookies we use and why:
| The cookies we use | Name | Purpose | Whether cookie is essential for us to provide you with a service that you have requested and whether we will seek your consent before we place the cookie |
|---|---|---|---|
| Strictly necessary — browser storage (first-party) | etapa_cookie_consent_v1 |
Technically a localStorage entry rather than a cookie. Records the visitor's consent choice (granted or denied) for analytics cookies, so that we can honour it. Duration: persists until you change your preference or clear your browser storage. |
Yes, essential — this is exempt from consent, as it is required to record and honour your cookie preference. |
| Analytics — PostHog (first-party) | ph_<project-key>_posthog, and additional ph_* cookies |
Session replay and product analytics. The main cookie stores a distinct ID and session information; the additional ph_* cookies store session-replay state.Only set after you give consent via our cookie banner. |
No — we will request your consent before placing these cookies. If you decline, the PostHog script is never loaded and none of these cookies are set. |
| Analytics — Google Analytics 4 (Google) | _ga, _ga_0EEE2GL83C |
_ga stores a client ID used to distinguish visitors (2-year expiry). _ga_0EEE2GL83C stores GA4 session state for property G-0EEE2GL83C.Read Google's guidance on how it uses cookies and the data generated by them: policies.google.com/technologies/cookies. |
No — we will request your consent before placing these cookies. If you decline, the GA4 script is never loaded and none of these cookies are set. |
| Authentication — Supabase (first-party) | sb-<project-ref>-auth-token (may be split across multiple cookies where the token is large) |
Session cookie(s) set when an administrator signs in with Google via OAuth, used to keep them signed in to the Admin Dashboard. The Admin Dashboard is only accessible to our administrators and sets no other cookies (for example, no analytics or performance-monitoring cookies). |
Yes, essential — this is a strictly necessary login/session cookie required to provide the Admin Dashboard service requested by our administrators, so we do not request consent before placing it. |
API server
Our API server sets no cookies at all. Authentication is handled entirely by way of Bearer tokens sent in the Authorization header of each request. We do not use cookie-parser, express-session, or any Set-Cookie headers.
iOS App
Our iOS App does not set any web cookies, as it is a native application. PostHog is used within the App for analytics, but relies on device-level identifiers rather than cookies. Authentication tokens for the App are stored using native secure storage on your device, not cookies.
How to turn off all cookies and consequences of doing so
If you do not want to accept any cookies, you may be able to change your device settings so that cookies (including those which are essential to the services requested) are not accepted. If you do this, please be aware that you may lose some of the functionality of our Services and of other services you use on your device. For further information about cookies and how to disable them please go to the guidance on cookies published by the UK Information Commissioner's Office, www.aboutcookies.org or www.allaboutcookies.org.
Changes to this policy
This policy was published on 13 July 2026 and last updated on 13 July 2026. We may change this cookies policy from time to time; when we do we will inform you via the Services or by sending an email to the email address you provided when you signed up to the Services.