Cookie Policy

Version 3

Last updated: 3 July 2026

1. Introduction

This Cookie Policy explains how CompsPilot, operated by Ginger Squid Ltd ("we", "us", "our"), uses cookies and similar technologies when you visit our website and use our services. It should be read alongside our Privacy Policy, which explains how we collect and use your personal data.

We use cookies and similar technologies to run the service and, where you allow it, to understand how the site is used. Strictly necessary cookies are always active because the service cannot work without them. Non-essential cookies and similar technologies, such as analytics cookies, analytics scripts, session recordings and heatmaps, are used only after you have given consent through our cookie banner. We do not set analytics cookies or start analytics recording beforehand. You can change or withdraw your choice at any time, and rejecting non-essential cookies is as easy as accepting them.

2. What are cookies?

Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work more efficiently and to provide information to website owners. Cookies can be "persistent", remaining until deleted or expired, or "session", deleted when you close your browser. They can also be "first-party", set by the site you are visiting, or "third-party", set by other domains.

Similar technologies include local storage, pixels, software development kits and other tools that store information on, or access information from, your device.

3. Why we use cookies

We use cookies and similar technologies to:

  • keep you signed in;
  • remember your preferences and settings;
  • keep the service secure and prevent fraud;
  • support checkout and billing;
  • monitor performance and technical reliability; and
  • where you consent, understand how you use the platform so we can improve it.

4. Types of cookies and similar technologies we use

4.1 Strictly necessary cookies

These cookies are essential for the platform to function and cannot be switched off through our cookie banner. They support authentication and session management, security and bot protection, fraud prevention during payment, and recording your cookie choice. They are exempt from consent under PECR because they are strictly necessary to provide the service you have requested.

4.2 Functional preference storage

These technologies support features you actively use, for example remembering your selected household-member view. They are not used for advertising. Where the law treats a functional preference as exempt from cookie consent, we still explain it clearly and let you change or clear the preference through your account or browser settings.

4.3 Analytics cookies and similar technologies

We use Microsoft Clarity and PostHog to understand how people use CompsPilot. These tools help us identify usability problems, understand feature use, and improve the product. They may collect pseudonymised usage data, including page views, clicks, scrolling, device and browser information, approximate location, heatmaps, and session recordings where enabled. Sensitive areas are masked where technically available.

Analytics cookies and analytics scripts are used only after you choose "Allow analytics". Until then, no analytics cookies are set and no session data is recorded, and the analytics code included in our site stays inactive. You can withdraw consent at any time. We do not use analytics for advertising, and we do not treat this data as fully anonymous.

Depending on your browser, region, consent mode and provider configuration, Microsoft may also set its own third-party cookies, including but not limited to CLID, ANONCHK, MR, MUID and SM. PostHog may use cookies or local storage such as ph_phc_*_posthog or equivalent project-specific identifiers, depending on the way the PostHog JavaScript library is configured.

4.4 Marketing and advertising cookies

We do not currently use marketing or advertising cookies. If we decide to use them in future, we will update this policy and obtain your explicit consent first.

5. The cookies and similar technologies we use

The table below lists the cookies and similar technologies we expect to be set. Exact names and durations may vary as our providers update their services or depending on browser behaviour.

Cookie / storage itemSet byPurposeDurationCategory
cp_cookie_consentCompsPilotRecords your analytics-cookie choice and when you made it12 monthsStrictly necessary
cp_active_memberCompsPilotRemembers your selected household-member view when signed in12 months or until clearedFunctional preference
__session, __client_uat, __client, __refresh, clerk_active_contextClerkAuthentication and session managementSession, up to about 7 daysStrictly necessary
_clckMicrosoft ClarityAnalytics - stores a pseudonymous Clarity user ID and preferencesUp to about 12 monthsAnalytics, consent required
_clskMicrosoft ClarityAnalytics - connects page views into a single Clarity session recordingUp to about 1 dayAnalytics, consent required
CLID, ANONCHK, MR, MUID, SM and similar Microsoft cookiesMicrosoftAnalytics and operational Microsoft identifiers that may be set depending on Clarity configuration, region and browserVaries by Microsoft configurationAnalytics, consent required
ph_phc_*_posthog or equivalent PostHog identifierPostHogAnalytics - identifies sessions or users for product analytics and feature-usage analysisVaries by PostHog configuration, commonly up to about 12 months unless configured otherwiseAnalytics, consent required
PostHog local storage entriesPostHogAnalytics - supports product analytics persistence depending on configurationUntil cleared or as configuredAnalytics, consent required
__cf_bm, _cfuvidCloudflareSecurity and bot protection, where traffic is served via CloudflareMinutes / sessionStrictly necessary
__stripe_*StripeFraud prevention during checkout and billing, set on Stripe's hosted checkout pagesPer Stripe configurationStrictly necessary

Cloudflare security cookies are set only where traffic is served through Cloudflare. Stripe cookies are set only in payment-related flows.

6. Third-party providers

6.1 Authentication - Clerk

We use Clerk for authentication and account management. Clerk sets cookies to keep you signed in securely, manage your session, and prevent unauthorised access. See Clerk's privacy policy for more information.

6.2 Payments - Stripe

Stripe may set cookies or similar technologies during checkout, billing or payment-related flows, including for fraud prevention and authentication. Depending on the integration, these are set on Stripe's own hosted checkout pages during payment. See Stripe's privacy policy for more information.

6.3 Security and infrastructure - Cloudflare

We use Cloudflare for DNS, security and content delivery. Where traffic is served through Cloudflare, it may set security cookies such as __cf_bm and _cfuvid. These are not set across the whole site unless the relevant traffic is served through Cloudflare's proxy.

6.4 Analytics - Microsoft Clarity

Microsoft Clarity provides consent-based analytics, including session recordings and heatmaps. Microsoft may act as an independent controller for some analytics processing. See the Microsoft Privacy Statement (https://www.microsoft.com/en-us/privacy/privacystatement) for more information.

6.5 Analytics - PostHog

PostHog provides consent-based product analytics and feature-usage analysis. Depending on our configuration, PostHog may use cookies, local storage, or both. See PostHog's privacy information for more detail.

7. How to manage cookies

When you first visit CompsPilot, a cookie banner lets you accept or reject non-essential analytics cookies and similar technologies. You can reopen your choices at any time using the "Manage cookie preferences" control in this policy, in the site footer, and in your account settings.

If you reject or later withdraw consent, we stop setting non-essential analytics cookies and stop loading analytics tools for future visits where technically possible. Strictly necessary cookies remain because they are required to run the service. Withdrawing consent does not affect the lawfulness of any use that took place before you withdrew it.

You can also control cookies and local storage through your browser.

7.1 Browser settings

Most browsers let you view and delete stored cookies, block all or third-party cookies, clear cookies when you close the browser, and set exceptions for specific sites.

7.2 Browser-specific instructions

  • Chrome: Settings -> Privacy and security -> Cookies and other site data.
  • Firefox: Settings -> Privacy & Security -> Cookies and Site Data.
  • Safari: Settings -> Privacy -> Manage Website Data.
  • Edge: Settings -> Cookies and site permissions -> Manage and delete cookies.

7.3 Impact of disabling cookies

If you disable or block cookies, some features of CompsPilot may not work properly. For example, you may be unable to log in or stay logged in, your preferences may not be saved, and some features may be unavailable or work incorrectly.

8. Other technologies

8.1 Local storage

We use browser local storage for certain functional settings, for example cp_last_pending_entry and compspilot_forwarding_setup_done. This data stays on your device until you clear it through your browser settings.

8.2 Web beacons and pixels

We do not currently use tracking pixels in marketing emails. We may use ordinary technical delivery information for transactional emails, such as whether an email was delivered or bounced. If we introduce email analytics for marketing emails, we will do so only where permitted by PECR and with appropriate consent or opt-out controls.

8.3 Server logs

Our servers automatically log certain information when you access CompsPilot, including your IP address, browser type, pages visited and timestamps. This helps us maintain security and improve performance.

9. Do Not Track signals

Some browsers offer a "Do Not Track" feature. There is currently no universal standard for how DNT signals should be interpreted, and we do not currently respond to them. We do, however, respect your privacy choices and provide the cookie controls described in this policy.

10. Your rights

Under UK GDPR and PECR you have the right to be informed about cookies and similar technologies, to refuse non-essential technologies, to withdraw consent at any time, to access data collected through cookies where it is personal data, and to request deletion of cookie data in appropriate circumstances. To exercise these rights, contact privacy@compspilot.co.uk or manage your browser cookie settings.

11. Changes to this policy

We may update this Cookie Policy from time to time to reflect changes in our practices or legal requirements. We will note the change by updating the "Last updated" date at the top and, where appropriate, by email or a notice on the platform.

12. Contact us

Ginger Squid Ltd, 86-90 Paul Street, London, EC2A 4NE, United Kingdom. Email: support@compspilot.co.uk. Privacy email: privacy@compspilot.co.uk.