This Cookie and Similar Technologies Policy explains how CertFlow LTD (company number 17056886), a company registered in England and Wales whose registered office is 20 Wenlock Road, London, N1 7GU (CertFlow, we, us or our) stores information on, or accesses information from, a browser, phone, tablet or other device when you visit https://www.certflow.co.uk, use the CertFlow platform or mobile application, open a Customer mini-site, or choose to load an embedded service.
It should be read with our Privacy Policy, which explains how we use personal data, our lawful bases, recipients, international transfers, retention and your rights. Where a CertFlow Customer controls a mini-site or uses the platform to process personal data, that Customer's own notice may also apply.
1. Scope and responsibility
This Policy covers HTTP cookies, local storage, session storage, software development kits, tags, pixels, embedded frames, device preferences and comparable technologies that store or read information on a device. We call them storage and access technologies. The rules can apply even where the information is not personal data and even where a script or tag does not set a conventional cookie.
CertFlow LTD is responsible for the storage and access technologies that we select for the public CertFlow website and platform. A named third party may also be responsible for its own technology and any personal-data processing it determines. Customer mini-sites are published for the relevant Customer; CertFlow provides the technology, while the Customer remains responsible for its own content, purposes and any additional technology it introduces.
Native mobile operating systems may use an application preferences store or secure device storage instead of browser local storage. The function and choices described below are the same even if the technical container differs.
2. How the UK rules apply
Regulation 6 of the Privacy and Electronic Communications Regulations 2003 (PECR), as amended by the Data (Use and Access) Act 2025 (DUAA), generally prohibits storing information on or accessing information from a device unless the user has clear and comprehensive information and has consented, or a statutory exception applies. The UK GDPR and Data Protection Act 2018 apply separately where the activity involves personal data.
The applicable exception depends on the technology's purpose and configuration, not its name or whether it is first-party. If one technology has an exempt purpose and a non-exempt purpose, we obtain consent for the non-exempt use rather than treating the whole technology as exempt.
| PECR route | When it can apply | How CertFlow uses it |
|---|---|---|
| Consent | You receive clear information and make a freely given, specific, informed and unambiguous choice before non-exempt storage or access begins. | Optional Google Analytics and the separately chosen Calendly embed use affirmative choice controls. Refusing them does not prevent ordinary access to the website or platform. |
| Communication | The sole purpose is carrying out or facilitating transmission of a communication over an electronic communications network. | May apply to short-lived technical operations needed to transmit a request. We do not use this exception to justify analytics or advertising. |
| Strictly necessary | The technology is essential to provide an information-society service that you expressly request. | Authentication, session security, tenant/workspace selection, active time tracking, consent-choice memory and essential recovery controls. |
| Statistical purposes | The sole purpose is collecting statistics about use of the service to improve it; the information is not used to make decisions about a person, sharing is restricted, clear information is provided, and a simple free objection is available. | May apply to limited first-party, aggregate Customer mini-site statistics where all conditions are met. It is not used for Google Analytics or advertising. |
| Appearance or functionality | The technology adapts or enhances how the service appears or functions in line with a user's preference; clear information and a simple free objection are provided. | Theme, mobile/desktop view, navigation layout and comparable interface choices that can be reset or removed. |
| Emergency assistance | The sole purpose is determining device location to provide assistance in response to the user's emergency communication. | CertFlow does not currently rely on this exception. Ordinary site mapping or location features are not treated as emergency assistance. |
3. Your choices at a glance
| Class | Default | How to control it |
|---|---|---|
| Necessary website and platform functions | On when the relevant requested function is used. | These cannot be switched off in our choice panel. You can block or clear them in your browser/device, but sign-in, security, offline work or selected features may stop working. |
| Appearance and functionality preferences | Set only when the interface stores a choice or state. | Reset the relevant preference in the Service or clear site/application data. The Service then returns to its default behaviour. |
| Public-site Google Analytics | Off. Neither Google Tag Manager nor Google Analytics loads before analytics consent. | Accept or refuse in the consent panel and change the choice at any time using “Review cookie choices” below. |
| Calendly booking calendar | Off. The third-party frame is replaced by a static placeholder. | Choose “Load booking calendar” to load it. Reload or leave the page to stop the active embed; use browser controls to remove third-party data already stored. |
| Limited first-party mini-site statistics | Used only where configured for the statistical-purpose exception or after any required consent. | Use the choice or objection control shown on the relevant mini-site, or contact us. Browser session-storage controls also remove the local session identifier. |
Withdrawing consent stops future optional storage and access from that choice on that browser and origin. It does not make earlier consented processing unlawful, and it may not remove information already received by a third party. Section 8 explains how to delete existing browser data.
4. Public website inventory
4.1 Necessary consent preference
| Technology | Type and provider | Purpose and information | Duration | Choice / PECR route |
|---|---|---|---|---|
cf-consent (versioned record) | First-party local storage; CertFlow LTD. | Remembers whether analytics was accepted or refused, the consent-policy version and the choice/expiry time. Versioning lets us ask again after a material change rather than silently extending an old choice. | Recognised for up to 180 days (approximately six months). An expired record is removed when a CertFlow page next loads, unless it is cleared or replaced earlier. | Strictly necessary to remember and give effect to the consent choice. Clearing it makes the panel appear again. |
4.2 Google Analytics after consent
We use Google Analytics 4 to understand aggregate public-site use, such as pages viewed, broad device/browser characteristics, approximate geography derived by Google, referrer/campaign information and interactions we configure as events. We use Google Tag Manager only to deliver the configured analytics tag. The current container is GTM-NC42WLXK and the analytics measurement ID is G-6M11W2CE8F.
Neither Google Tag Manager nor Google Analytics is requested before analytics consent. Refusal leaves analytics storage denied. We also keep ad_storage, ad_user_data and ad_personalization denied; this choice does not enable behavioural advertising, remarketing or advertising-personalisation storage for CertFlow.
| Technology | Type and provider | Purpose and information | Usual duration | Choice / PECR route |
|---|---|---|---|---|
Google Tag Manager (GTM-NC42WLXK) | Consent-gated script/tag manager; Google Ireland Limited / Google group. | Loads and manages the configured Google Analytics tag after consent. CertFlow keeps advertising consent signals denied, so the site choice does not authorise advertising tags or advertising storage. Tag Manager does not require a separate CertFlow cookie name. | Requested for the page after consent; configuration and network logs are provider-controlled. | Consent. Blocked until analytics is accepted; disabled again for future page loads when consent is withdrawn. |
_ga | First-party cookie set for Google Analytics. | Assigns a pseudonymous browser identifier so visits can be distinguished and counted. It does not contain your name or CertFlow Account password. | About 400 days, subject to browser limits, earlier deletion and Google configuration. | Consent. Not set until analytics is accepted. |
_ga_6M11W2CE8F | First-party cookie set for the CertFlow Google Analytics property. | Maintains GA4 session and engagement state for the measurement property. | About 400 days, subject to browser limits, earlier deletion and Google configuration. | Consent. Not set until analytics is accepted. |
5. Calendly and its downstream services
The demo page initially displays a CertFlow-hosted placeholder. Calendly and its frame are not contacted merely because you open the page or accept Google Analytics. If you choose the calendar button, you expressly request that the Calendly booking experience load and information including your IP address, browser/device details, referring page and booking interactions can be disclosed to Calendly and services it uses. Information you enter into the calendar is sent to Calendly when you interact with or submit the booking flow.
A clean-browser audit of the current Calendly embed observed the technologies below. They operate on Calendly, Cloudflare or Stripe domains, and their exact duration/configuration is controlled by those providers. Calendly can change its downstream service chain without changing CertFlow code, so this inventory is reviewed but may vary by browser, location and provider configuration.
| Technology | Provider/domain | Purpose and information | Observed or provider duration | Choice |
|---|---|---|---|---|
| Calendly booking frame and scripts | Calendly LLC; calendly.com and assets.calendly.com. | Displays availability, protects and operates the booking workflow, and processes contact, appointment, device and interaction information supplied through it. | The frame lasts for the page visit; Calendly controls its account, booking and service records under its notice. | Loads only after the explicit calendar button. You can instead book by contacting us directly. |
__cf_bm | Cloudflare security cookie on the Calendly domain. | Bot management and protection of the embedded booking service; may use request and device signals. | Approximately 30 minutes. | Appears only after Calendly is loaded; treated by the embedded provider as necessary for security. |
_cfuvid | Cloudflare/Calendly cookie on the Calendly domain. | Distinguishes sessions or devices for rate limiting, security and reliable service delivery. | Provider/session controlled; no fixed CertFlow duration. | Appears only after Calendly is loaded; treated by the embedded provider as necessary for security/service delivery. |
m | Stripe cookie on m.stripe.com, loaded within the Calendly experience. | Fraud prevention and risk/device signals used by Stripe within Calendly's service chain. | Up to about 400 days; provider controlled and browser limits may shorten it. | Can appear only after Calendly is loaded. Remove it through browser controls or use email/phone instead of the embed. |
Calendly's own privacy and cookie information applies to its processing. If you do not want those third parties contacted, do not load the calendar; email info@certflow.co.uk or call us using the details on the Contact page.
6. CertFlow platform and mobile storage
The signed-in platform uses first-party browser or application storage for authentication, offline continuity, workspace state, requested tools and interface preferences. Key names can contain a project, user or organisation identifier and can change safely between releases, so the inventory groups unstable or dynamic keys by function while naming stable examples.
Platform storage is not used for third-party behavioural advertising. Server-side copies of Account, security, audit and operational telemetry records are not browser cookies; their purposes, lawful bases and retention—including ordinary event-level telemetry retention of up to 180 days—are explained in the Privacy Policy.
| Class / examples | Storage and information | Purpose | Device duration | Choice / PECR route |
|---|---|---|---|---|
Authentication and sessionsb-…-auth-token pattern | Local storage on web or the native secure/preferences equivalent; access/refresh token, expiry and limited session/user metadata managed by Supabase Auth. | Sign-in, session renewal, authorised API requests, offline authentication continuity and account security. | For the authenticated session and token lifecycle; removed or invalidated on sign-out, expiry, account/security action or when application data is cleared. | Strictly necessary for the signed-in service. Blocking it prevents or repeatedly interrupts sign-in. |
Workspace and offline contextcertflow.currentOrgIdcertflow.orgContextCache.v2 | Local storage; selected organisation ID plus a user-scoped cache of authorised organisations, roles and current context. | Keeps the correct workspace selected, supports tenant-aware navigation and permits supported offline startup. Server authorisation remains authoritative. | Until the organisation changes, the user signs out, a cache version is replaced or application data is cleared. | Strictly necessary for requested multi-organisation and offline platform functions. |
| Active timesheet timer | Local storage; timer start time and associated user, organisation and optional job references. | Keeps a user-started timer running consistently across reloads and tabs. | Until the timer is stopped/discarded, the user signs out where cleanup applies, or application data is cleared. | Strictly necessary once the user requests the timer function. The user can stop or discard it in the platform. |
| Appearance and navigation preferences theme, mobile/desktop mode, sidebar state | Local storage; interface choices such as light/dark theme, preferred shell and expanded/collapsed navigation state. | Adapts and improves the interface on that device. | Until reset, superseded by a new preference or application data is cleared. | Appearance/functionality exception. Reset the control or clear application data to object; the default interface will be used. |
| Onboarding, recent-item and prompt state | Local storage; flags showing a tour/checklist or organisation prompt was completed/dismissed and a short list of recently selected equipment types. Dynamic keys may be scoped to a user or organisation. | Avoids repeating prompts and makes frequently used in-product choices easier to reach. | Until the feature is reset, its version changes or application data is cleared. | Appearance/functionality exception. Clearing the record can make the prompt reappear or remove recent-item convenience. |
Operational telemetry session and offline queuecertflow.telemetrySessioncertflow.telemetryQueue | Per-tab session storage identifier and a bounded local-storage queue of up to 200 first-party events, including time, organisation context, platform/app version, normalised route, event properties and limited error details. | Diagnoses failures, protects and operates the Service, monitors reliability/performance and delivers operational events after an offline period. It is sent only to CertFlow's authenticated first-party ingestion service, not an advertising platform. | Session identifier: until the tab/session ends. Queue: until successfully sent, displaced by the bounded limit or application data is cleared; stale server submissions are constrained. | Used as necessary operational/security storage for the subscribed platform. Contact us to object to separate product-improvement use; we will assess the objection under data-protection law without disabling essential security records. |
| Short-lived recovery state | Session storage; timestamps/flags such as a one-time application chunk-reload guard. | Recovers safely from an application update or loading error without entering a reload loop. | Until the tab/session ends or the value is cleared. | Strictly necessary for reliable delivery and error recovery. |
7. Customer mini-sites and first-party statistics
A Customer may publish a CertFlow-powered mini-site and lead form. The mini-site can use a per-tab ms_session_id in session storage to de-duplicate page views and interactions and produce aggregate counts for that Customer, such as views, calls, link clicks and lead submissions. The identifier is a random value; the event sent to CertFlow can also include the event type, Customer organisation, time, referrer, user-agent and limited event metadata. Form information is separate from the session identifier and is covered by the Privacy Policy and the Customer's notice.
Where this storage is used without consent, its sole purpose must be statistical measurement to improve the relevant mini-site or service, results must not be used to make decisions about an individual, onward sharing must be limited, and the mini-site must provide a simple, free means of objecting as required by the DUAA statistical-purpose exception. If those conditions are not met, the session identifier must remain disabled until any required consent is obtained.
| Technology | Provider | Purpose and information | Duration | Choice / PECR route |
|---|---|---|---|---|
ms_session_id | CertFlow LTD, for the Customer whose mini-site you visit. | Random per-tab identifier used to de-duplicate first-party mini-site events and calculate aggregate use/conversion statistics; not used for cross-site advertising. | Session storage, normally until the browser tab/session ends or it is cleared. | Statistical-purpose exception only where its conditions and a simple free objection are provided; otherwise consent. Use the mini-site choice/objection control, clear session storage or contact us. |
8. Managing, withdrawing and deleting storage
8.1 CertFlow choice panel
Use “Cookie settings” in the footer or the button below to review the public-site analytics choice on this browser. Rejecting must be as easy as accepting. A refusal is remembered for the same 180-day period as an acceptance. If we materially change the optional purposes or providers, we will invalidate the relevant version and ask again before the new optional use begins.
The Calendly choice is separate: analytics consent does not load the calendar. The calendar button gives just-in-time information before making the third-party connection.
8.2 Browser and device controls
- Use browser privacy/site-data settings to view, block or delete cookies for
certflow.co.uk,google.com,calendly.com,stripe.comand other provider domains. - Use browser developer or site-data controls to clear local storage and session storage. Session storage usually ends when the relevant tab/session closes; browser restoration features can extend it.
- Use the operating system's application settings to clear native app data. Sign out and confirm offline work has synchronized first; clearing app data can remove unsynchronized records and require a fresh login.
- Private-browsing modes, tracking protection, enterprise policy and browser lifetime caps may shorten or block the durations in this Policy.
Blocking necessary storage may prevent authentication, preference memory, offline work, timers, booking or other requested functions. You can use the ordinary public site without accepting Google Analytics or loading Calendly, and you can contact us directly instead of using an embedded form or calendar.
A browser control may not delete provider-side records already created. For personal-data rights or questions about provider-side retention, use the routes in our Privacy Policy or the provider's own notice.
9. Providers, personal data and international transfers
A cookie or storage identifier can be personal data when it identifies or can be linked to a person or device. Our Privacy Policy explains the corresponding controller/processor roles, UK GDPR lawful bases, provider categories, international-transfer safeguards, data-subject rights and complaints. Consent under PECR and a lawful basis under the UK GDPR are related but separate requirements.
The named providers relevant to this Policy include Supabase for platform authentication and data services, Google for consented public-site analytics, Calendly for optional booking, and the downstream security/payment services described in section 5. Provider legal entities, infrastructure and subprocessors can operate in the United Kingdom, EEA, United States and other locations. Where CertFlow makes a restricted transfer, the safeguards described in our Privacy Policy apply.
We do not sell cookie or storage data. We do not configure Google Analytics storage for third-party behavioural advertising or use platform local storage to build advertising profiles. A Customer controls its own lawful use of Customer Personal Data and must not add undisclosed third-party tags to a mini-site or shared content.
10. Audits and changes to this Policy
We audit the public website, consent manager, embedded services and representative platform storage periodically and when a material tag, provider or storage feature changes. This includes clean-browser checks before or after significant deployments, verifying that optional tags remain blocked before choice, checking cookie/storage names and durations, and reviewing whether an exception or consent route still fits each purpose.
Third-party inventories can change without notice and browsers can report different results. The durations above are therefore usual or maximum observed/provider periods, not a promise that a technology will remain for exactly that time. If an audit identifies a materially different non-exempt purpose, we will update the disclosure and obtain a fresh choice before enabling it where required.
We will publish Policy updates here with a revised “Last updated” date. A material change to optional purposes, providers or choice consequences will not be hidden behind an old consent record; the versioned record will be renewed and an appropriate notice shown.
11. Contact and complaints
For a question about storage and access technologies, to object where an exception requires a simple free objection, or to report an inventory mismatch, email info@certflow.co.uk with “Cookies” in the subject or write to CertFlow LTD, 20 Wenlock Road, London, N1 7GU.
You may also raise a concern with the Information Commissioner's Office, the UK regulator for PECR and data protection. Our Privacy Policy contains further contact, rights-request and complaint information.