Cookie Policy

Last updated: 16 September 2026

1. What this policy covers

Cookies are small text files stored by your browser. We also use similar technologies such as local storage. This page describes what The WERC App actually sets today.

2. Strictly necessary cookies and storage

We only set cookies and similar storage that are required to provide the service you asked for, to keep it secure, or to remember a choice you made on this device. We do not currently use third-party advertising cookies, and we do not currently use a third-party analytics cookie product (such as Google Analytics).

Because of that, we do not show a marketing-cookie consent banner.

Cookies

  • Session cookie (Auth.js / NextAuth) — keeps you signed in. HTTP-only.
  • csrf-token — helps prevent cross-site request forgery on signed-in actions. HTTP-only, SameSite=strict.

Cloudflare Turnstile

On signup we use Cloudflare Turnstile to reduce bot accounts. Cloudflare may set its own cookies or storage as part of that security check. That is strictly necessary for protecting registration.

First-party local storage

The product may store on this device (not as third-party tracking):

  • Theme / appearance preference
  • Staff layout or editor preferences you choose
  • Whether you dismissed a prompt (for example install or notification hints)

3. What we do not set today

  • Advertising or social-media tracking cookies
  • Third-party analytics cookies
  • Payment-processor cookies (we do not take card payments on this site)

If we later introduce non-essential cookies, we will update this policy and obtain opt-in consent before setting them, as UK PECR requires.

4. Your choices

You can delete or block cookies in your browser. Blocking the session or CSRF cookie will stop sign-in and most account actions from working.

5. More information

Personal data processed via these technologies is described in the Privacy Policy. Questions: support@werc.uk.