Cookie policy
Last updated · Nord Group UK Ltd, registered in England and Wales
This policy explains what FoxFace stores on your device, why, and what you can do about it. It applies to the foxface.io website and to the FoxFace application.
It is short because there is very little to describe, and that is the point.
1.The short version
FoxFace sets one cookie to keep you signed in, and stores one preference in your browser so the interface does not flash the wrong theme. That is the whole of it.
We set no advertising cookies. We set no third-party analytics cookies. We load no tracking pixel, no conversion tag and no session-recording script anywhere on this site or in the application.
Because we set no cookies that require consent, there is no consent banner. A banner that asks permission for cookies you were never going to set is theatre, and we would rather not.
2.What a cookie is, in this context
A cookie is a small file a website asks your browser to keep and send back on later requests. Related technologies do a similar job: local storage keeps a value in the browser without sending it anywhere, and session storage does the same until you close the tab.
UK law, specifically the Privacy and Electronic Communications Regulations, requires consent before storing or accessing information on your device, with an exception for anything strictly necessary to provide a service you asked for. Authentication is strictly necessary. Advertising is not.
3.The categories, and where we sit in them
Cookie policies conventionally use four categories. Ours are listed against each so you can see exactly what we do and do not use.
| Category | What it means | Do we use it? |
|---|---|---|
| Strictly necessary | Required to deliver a service you have asked for, such as staying signed in or protecting a form against cross-site request forgery. No consent required. | Yes. One session cookie, described below. |
| Functional or preference | Remembers a choice you made, such as light or dark mode. Not required for the service to work. | One value in local storage, not a cookie, and it never leaves your device. |
| Analytics or performance | Measures how a site is used, usually by assigning a visitor an identifier. | No cookies. Aggregate page counts only, with no identifier and no cross-site tracking. |
| Advertising or targeting | Builds a profile to target advertising, usually across multiple sites. | No. None, anywhere, on any page. |
4.The cookies we actually set
One cookie, on the application. It is set when you sign in and removed when you sign out.
| Name | Purpose | Type | Expires |
|---|---|---|---|
| foxface_session | Keeps you signed in and identifies your session. Contains a random token and nothing else: no name, no email, no organisation identifier. | First party, strictly necessary. HttpOnly, SameSite=Lax, Secure in production. | 30 days, or immediately on sign-out |
5.Other storage on your device
One value is kept in your browser’s local storage rather than in a cookie, which means it is never transmitted to us at all.
| Key | Purpose | Where it goes |
|---|---|---|
| foxface-theme | Remembers whether you chose the light or the dark interface. Stored per device deliberately, so your phone and your laptop are allowed to differ. | Stays in your browser. Never sent to our servers. |
6.No advertising or analytics on authenticated routes
This deserves its own clause because it is the commitment most likely to matter to you and to your own customers.
No third-party script of any kind is loaded on an authenticated application route. Once you have signed in, the only JavaScript running in the page is ours. Your customers’ names, addresses, telephone numbers and survey photographs are never in the presence of an advertising network, an analytics vendor or a session recorder.
The same applies to the token-addressed pages your own customers visit to sign a proposal or make a payment. Those pages carry no marketing tags at all. A homeowner signing a quotation on their sofa is not being profiled by anyone as a result.
The only exception is the payment provider’s own script on the card payment page, which is loaded by them, is necessary to take the payment securely, and is subject to their published policy. It is not used for advertising.
7.How we measure the marketing site
We count page views in aggregate, without cookies, without a device fingerprint and without any identifier that can be linked to an individual or followed across sites or sessions.
That means we can tell that the pricing page was viewed a certain number of times last week. We cannot tell that it was you, we cannot tell what you looked at before or afterwards, and we cannot build a profile. This is a deliberate trade: we accept coarser data in exchange for not tracking anybody.
8.Controlling cookies in your browser
You can block or delete cookies through your browser settings, and every major browser offers this under a privacy or security heading.
If you block the session cookie, you will not be able to sign in to FoxFace, because the browser will have no way to remember that you already did. That is the nature of a strictly necessary cookie rather than a design choice on our part.
Clearing local storage removes your theme preference and the interface will return to its default. Nothing else is affected.
9.Changes to this policy
If we ever add a cookie, this page will list it before it is set, and anything outside the strictly necessary category will be behind an explicit opt-in rather than a pre-ticked box or an implied consent banner.
The date at the top always reflects the current version.