Cookie and Browser Storage Policy
Version 2.0 · In force from 9 August 2026
1. Current approach
CareGist uses strictly necessary cookies and local browser storage for sign-in, security, requested navigation, and user-selected preferences. CareGist does not use advertising, remarketing, social-media tracking, or cross-site tracking cookies.
2. Storage used
| Item | Purpose | Typical duration |
|---|---|---|
| Authentication session cookie | Keeps an authenticated session and protects gated routes. | Session or configured expiry. |
| Signed-in user and displayed tier | Renders the current navigation and fail-closed entitlement state. No password, API key, or signing secret is intentionally stored. | Until logout or browser data is cleared. |
| Provider comparison list | Remembers providers the user explicitly selected for comparison. | Until the list or browser data is cleared. |
| Post-verification path | Returns a user to an approved CareGist route after email verification. | Removed after use or when browser data is cleared. |
| Storage-notice choice | Prevents the informational storage notice from being shown repeatedly. | Until browser data is cleared. |
3. Operational telemetry
CareGist records first-party request, security, feature-use, delivery, and error telemetry needed to operate and improve the service. This may include timestamps, requested routes, browser information, security identifiers, and account or organisation identifiers when signed in. CareGist does not use this telemetry for third-party advertising or cross-site profiling.
4. Stripe-hosted checkout
When an approved paid checkout is enabled, Stripe may set cookies on its hosted checkout or billing-management pages. Stripe controls those cookies under its own cookie policy.
5. Managing storage
Browser settings can remove or block cookies and local storage. Blocking strictly necessary storage may prevent sign-in, account management, comparison, or verified checkout from working. If CareGist introduces non-essential browser storage, this policy and the consent mechanism will be updated before it is used.
Questions may be sent to privacy@caregist.co.uk.