Smart Order Capture

Legal

Cookie Policy

Effective
Last updated

The short version: we use cookies to keep you signed in, to remember your theme, and to keep bots out of the sign-in form. Our analytics are cookieless and our payment cookies belong to Stripe. There are no advertising or tracking cookies anywhere on this site.

1.What this covers

This policy describes the cookies and similar technologies — browser local storage, and scripts that read device characteristics — used on smartordercapture.com. It supplements the Privacy Policy, which explains what we do with the information involved.

A cookie is a small file a site stores in your browser and reads back on later requests. Local storage is similar but is never sent to a server automatically. We use both sparingly.

2.What we do not use

We set no advertising cookies, no cross-site tracking cookies, and no third-party marketing pixels. We do not participate in ad networks or data brokerages, and nothing on this site builds a profile of you across other sites.

Our analytics tool is self-hosted and cookieless: it counts page views and a handful of product events without storing an identifier in your browser and without following you anywhere else. That is why you are not greeted by a consent banner — under EU and UK rules consent is required for storing or accessing information on your device that is not strictly necessary, and we do not do that.

3.What we do use

Cookies and storage keys set by the site
Name / kindSet byPurposeType and lifetime
Session cookiesmartordercapture.com (first party)Keeps you signed in and ties requests to your account. HttpOnly, Secure, SameSite.Strictly necessary — until expiry or sign-out
CSRF / state tokensmartordercapture.com (first party)Protects sign-in, sign-up and account forms against cross-site request forgery.Strictly necessary — session
themesmartordercapture.com (first party, local storage)Remembers your light or dark preference so the page does not flash on load.Preference — until you clear it
Turnstile challenge (cf_* / _cf*)CloudflareDistinguishes humans from automated abuse on sign-in, sign-up and password reset.Strictly necessary (security) — minutes to 30 days
Stripe Checkout cookiesStripeFraud prevention and session continuity during payment. Set on Stripe’s own domain when you are sent to Checkout, not on ours.Strictly necessary (payment) — per Stripe’s policy
Analytics eventsSelf-hosted analytics on our infrastructureCounts page views and product events. No cookie, no device identifier, no cross-site tracking.No storage on your device
Error reportsSelf-hosted error monitoring on our infrastructureSends a report when a page errors, so we can fix it. Uses no cookie.No storage on your device

Signed-in areas of the product may set additional strictly necessary first-party storage keys to remember interface state, such as a collapsed sidebar or a builder canvas position. These never leave your browser.

4.Controlling cookies

Every major browser lets you view, block and delete cookies and clear local storage, usually under Settings → Privacy. You can also browse in a private window, which discards everything at the end of the session.

Blocking our strictly necessary cookies will stop you signing in, and blocking Cloudflare Turnstile will stop the sign-in, sign-up and password-reset forms from submitting. Nothing else on the site depends on storage.

We honour the Global Privacy Control (GPC) signal. Because we neither sell nor share personal information for advertising, and set no advertising cookies, the signal does not change your experience — there is nothing for it to switch off.

5.The Android application

The Android application is not a browser and does not use cookies. It stores your workflows, credentials for your session, and its own settings in the application’s private storage on the device, which Android removes when you uninstall it. What the application collects is described in the Privacy Policy.

6.Changes

If we add a cookie or a similar technology, we will update the table above and the “Last updated” date before it goes live. If we ever add something that is not strictly necessary, we will ask for consent first where the law requires it. Questions go to privacy@smartordercapture.com.