AssetWRX Cookie Policy

Last updated: 1 June 2026 Effective: 1 June 2026 Version: 1.0.0

This Cookie Policy explains how AssetWRX uses cookies and similar local-storage technologies on our website (assetwrx.com), the web application (app.assetwrx.com), and any embedded checkout flows. The mobile apps do not use HTTP cookies but use equivalent device storage as described below. This policy supplements our Privacy Policy.

1. What are cookies

Cookies are small text files stored on your device by a website you visit. They allow the site to recognise your device on subsequent visits and to remember your preferences and authenticated session. “Similar technologies” include localStorage, sessionStorage, and mobile-app device storage (AsyncStorage, expo-secure-store).

2. Categories of cookies we use

2.1 Strictly necessary (always on)

Required for the Service to function. You cannot disable these; they do not require consent under the ePrivacy Directive / UK PECR because they are essential.

Name Provider Purpose Lifetime
sb-<ref>-auth-token Supabase Authenticated session token Until sign-out or expiry
assetwrx_cookie_consent_v1 AssetWRX Records your cookie banner choices 12 months
Stripe Checkout cookies Stripe Fraud prevention during checkout Session
CSRF / session protection AssetWRX Security Session

Off until you grant consent via the cookie banner or in Profile → Privacy & Data → Communication preferences. Used to understand which features are used and where they break.

Name Provider Purpose Lifetime
ph_<key>_posthog PostHog Anonymous user / session identification for product analytics 12 months
Internal performance counters AssetWRX Aggregate page-load timing 30 days

Off until you grant consent. Used to measure marketing-campaign attribution. We do not use cookies for cross-context behavioural advertising and we do not sell any personal data.

Name Provider Purpose Lifetime
Future-reserved (none currently active) n/a n/a

The first time you visit a web surface, a non-blocking banner asks you to accept or reject each non-essential category. You can:

  • Accept all — grant all categories.
  • Reject all — only strictly-necessary cookies are set.
  • Manage preferences — toggle each category individually.

Your choice is persisted in assetwrx_cookie_consent_v1 and an audit row is written to cookie_consent_log. You can change your choice at any time from the cookie-preferences link in the website footer or from Profile → Privacy & Data → Communication preferences.

Withdrawal takes effect immediately: we revoke the relevant tracker and (where the tracker exposes a clear identifier) reset it.

4. Mobile-app storage

The mobile apps use:

  • expo-secure-store — encrypted at-rest storage for the authenticated session token.
  • AsyncStorage — unencrypted storage for non-sensitive preferences (theme, language, feature flags).
  • Crash and analytics SDKs — Sentry (always on, PII-scrubbed) and, with consent, PostHog.

The apps do not use the iOS Advertising Identifier (IDFA) or the Android Advertising ID and we do not request the iOS App Tracking Transparency prompt.

5. Managing browser cookies

You can also manage cookies via your browser’s settings. Blocking strictly-necessary cookies will prevent you from signing in. Browser instructions:

  • Chrome: chrome://settings/cookies
  • Firefox: about:preferences#privacy
  • Safari: Preferences → Privacy
  • Edge: edge://settings/content/cookies

6. Changes

We may update this policy when we add or remove a category, vendor, or tracker. Material changes are surfaced through the cookie banner and dated above. The previous version remains available on request from privacy@assetwrx.com.

7. Contact

privacy@assetwrx.com | Cogniforma Ltd, 17 Quaves Road, Slough, SL3 7NX, UK