Skip to content

Cookie Policy

Last updated: 2026-06-25

This policy explains the cookies and similar storage that CalProof uses, why we use them, and how you can control them. CalProof is a trading name of Crocker Digital Ltd, registered in England and Wales under Company No. 17008789.

CalProof is a working tool for calibration teams, not a marketing site, so we keep our cookie use to a minimum. We do not use third-party advertising cookies and we do not use cookies to build a profile of your browsing across other websites.

1. What cookies we use

A cookie is a small text file that a website saves on your device. For simplicity, this policy uses "cookies" to cover cookies and any similar first-party browser storage we may use.

We group the cookies and storage we use into two categories: strictly necessary, and functional. We have no analytics cookies, no advertising cookies, and no third-party tracking cookies.

2. Strictly necessary cookies

Strictly necessary cookies are required for the service to function. You cannot opt out of these without breaking the service. They are set when you sign in. CalProof does not use a CSRF cookie — state-changing requests are protected by verifying the request's Origin and Referer headers.

Cookie Purpose Provider Lifetime
Supabase authentication cookies — one or more whose names start with sb- and end with -auth-token Hold your authenticated Supabase session (access + refresh tokens). The session may be split across a small number of these cookies. They let the app keep you signed in and refresh your session without asking you to sign in on every page load. Supabase (first-party) Refresh window, sliding; cleared when you sign out

These cookies are first-party, set with the Secure and SameSite=Lax flags (and HttpOnly where applicable), and are cleared when you sign out.

3. Analytics — no cookies

We measure aggregate page-view counts using GoatCounter, a privacy-respecting analytics service. GoatCounter is configured in cookieless mode: it does not set any cookie, does not retain IP addresses beyond 24 hours, and does not allow individual users to be re-identified across sessions.

Because GoatCounter does not store anything on your device, no consent banner is needed for analytics. We chose this approach deliberately so that we can measure how the service is used without weighing the experience down with consent prompts.

4. Functional cookies

Functional cookies remember small UI choices so the app behaves the way you expect. None of them carry personal data beyond the minimum needed for the feature.

Cookie Purpose Provider Lifetime
current_org_id Remembers which organisation (workspace) you are currently viewing, so the app shows the right data when you belong to more than one. Carries only the organisation's identifier, no other personal data. Cleared on sign-out. CalProof (first-party) Session

You can clear functional cookies at any time from your browser settings, or by signing out of CalProof; the app will recreate the entry with its default the next time you sign in.

5. No third-party advertising cookies

We do not run advertising campaigns that depend on cookies, retargeting, or cross-site tracking. We do not embed advertising tags from Google, Meta, LinkedIn, or any other ad network on the authenticated parts of the service. The only third-party services that the application talks to in normal use are listed on our Sub-processors page.

6. Browser controls

Most browsers let you control cookies and similar storage through their settings. You can usually:

  • block all cookies, although this will prevent CalProof from working because authentication cookies are required;
  • block third-party cookies only, which CalProof tolerates because we do not rely on third-party cookies;
  • delete cookies for individual sites, including CalProof;
  • ask the browser to clear cookies and site data when you close it.

For step-by-step instructions, see your browser's help pages:

If you visit calproof.co.uk from inside the EU or UK and we ever introduce a cookie that is not strictly necessary or first-party functional, we will ask for your consent through a banner before the cookie is set, in line with PECR and UK GDPR.

7. Why we keep cookies minimal

We are aware that the average web app sets dozens of cookies the moment a page loads, often before any consent is given. We have chosen the opposite path on CalProof for two reasons.

First, calibration teams typically work inside a quality system that frowns on data leaving the organisation without a clear purpose. Every cookie we set is one more thing for an internal IT or compliance review to assess. Keeping the list short and obvious makes those reviews quick.

Second, most analytics and advertising cookies do not actually help us run a better B2B tool. We measure aggregate page views in cookieless mode, and we ask people directly when we want feedback. That gives us better signal than a behavioural funnel ever would, and it leaves your browser cleaner.

If we ever change our mind on this — for example, to add a session-replay tool that helps us debug a specific problem — we will say so on this page, ask for consent if the law requires it, and tell active customers by email before the change takes effect.

8. Contact

For any question about cookies on CalProof, email privacy@calproof.co.uk. The wider rules on how we handle personal data are in our Privacy Policy.