This is the same text shown in the app. The app asks for your agreement to this version.
Last updated: 1 June 2026 Effective: 1 June 2026 Version: 1.0.0
This Cookie Policy explains how AssetWRX uses cookies and similar local-storage technologies on our website (assetwrx.com), the web application (app.assetwrx.com), and any embedded checkout flows. The mobile apps do not use HTTP cookies but use equivalent device storage as described below. This policy supplements our Privacy Policy.
1. What are cookies
Cookies are small text files stored on your device by a website you visit. They allow the
site to recognise your device on subsequent visits and to remember your preferences and
authenticated session. “Similar technologies” include localStorage, sessionStorage, and
mobile-app device storage (AsyncStorage, expo-secure-store).
2. Categories of cookies we use
2.1 Strictly necessary (always on)
Required for the Service to function. You cannot disable these; they do not require consent under the ePrivacy Directive / UK PECR because they are essential.
| Name | Provider | Purpose | Lifetime |
|---|---|---|---|
sb-<ref>-auth-token |
Supabase | Authenticated session token | Until sign-out or expiry |
assetwrx_cookie_consent_v1 |
AssetWRX | Records your cookie banner choices | 12 months |
| Stripe Checkout cookies | Stripe | Fraud prevention during checkout | Session |
| CSRF / session protection | AssetWRX | Security | Session |
2.2 Analytics (consent-gated)
Off until you grant consent via the cookie banner or in Profile → Privacy & Data → Communication preferences. Used to understand which features are used and where they break.
| Name | Provider | Purpose | Lifetime |
|---|---|---|---|
ph_<key>_posthog |
PostHog | Anonymous user / session identification for product analytics | 12 months |
| Internal performance counters | AssetWRX | Aggregate page-load timing | 30 days |
2.3 Marketing (consent-gated)
Off until you grant consent. Used to measure marketing-campaign attribution. We do not use cookies for cross-context behavioural advertising and we do not sell any personal data.
| Name | Provider | Purpose | Lifetime |
|---|---|---|---|
| Future-reserved | (none currently active) | n/a | n/a |
3. How we obtain consent
The first time you visit a web surface, a non-blocking banner asks you to accept or reject each non-essential category. You can:
- Accept all — grant all categories.
- Reject all — only strictly-necessary cookies are set.
- Manage preferences — toggle each category individually.
Your choice is persisted in assetwrx_cookie_consent_v1 and an audit row is written to
cookie_consent_log. You can change your choice at any time from the cookie-preferences link
in the website footer or from Profile → Privacy & Data → Communication preferences.
Withdrawal takes effect immediately: we revoke the relevant tracker and (where the tracker exposes a clear identifier) reset it.
4. Mobile-app storage
The mobile apps use:
expo-secure-store— encrypted at-rest storage for the authenticated session token.AsyncStorage— unencrypted storage for non-sensitive preferences (theme, language, feature flags).- Crash and analytics SDKs — Sentry (always on, PII-scrubbed) and, with consent, PostHog.
The apps do not use the iOS Advertising Identifier (IDFA) or the Android Advertising ID and we do not request the iOS App Tracking Transparency prompt.
5. Managing browser cookies
You can also manage cookies via your browser’s settings. Blocking strictly-necessary cookies will prevent you from signing in. Browser instructions:
- Chrome: chrome://settings/cookies
- Firefox: about:preferences#privacy
- Safari: Preferences → Privacy
- Edge: edge://settings/content/cookies
6. Changes
We may update this policy when we add or remove a category, vendor, or tracker. Material changes are surfaced through the cookie banner and dated above. The previous version remains available on request from privacy@assetwrx.com.
7. Contact
privacy@assetwrx.com | Cogniforma Ltd, 17 Quaves Road, Slough, SL3 7NX, UK