This policy explains the cookies and similar browser storage used on kitcompliance.com and in the KitCompliance app. It sits alongside our privacy policy.
The short version
We only use storage that is strictly necessary to sign you in, keep your session secure and remember settings you choose. We do not use analytics, tracking or advertising cookies, and we do not let third parties set them on our site. Because of that, UK law (the Privacy and Electronic Communications Regulations) does not require us to ask for consent, so you won't see a cookie banner. If we ever add optional cookies, we will ask first and update this page.
What we set
| Name | Type | Purpose | Lasts |
|---|---|---|---|
kc_session |
Cookie (HttpOnly, first-party) | Keeps you signed in. JavaScript cannot read it, which protects it from cross-site scripting. | 7 days, or until you log out |
token |
Local storage | Security token sent with each change you make, so other websites can't act on your behalf (CSRF protection). | Until you log out |
language |
Local storage | Remembers the language you picked. | Until you clear it |
setupGuideDismissed,
setupGuideComplianceVisited |
Local storage | Remembers whether you hid the setup guide. | Until you clear it |
Third parties you may visit
Some actions take you to another provider, which sets its own cookies on its own website under its own policy:
- Stripe — when you pay for a plan, checkout runs on stripe.com. Stripe uses cookies there for fraud prevention. See Stripe's cookie policy.
- Google — only if you choose "Sign in with Google". See Google's cookie policy.
Managing cookies
You can block or delete cookies in your browser settings. If you
block kc_session you won't be able to sign in to the
app; the public website, docs and blog work without any cookies.
Logging out removes the session cookie and the security token.
Contact
Questions about this policy: privacy@kitcompliance.com