Cookie Policy
Last updated: 6 September 2026
1. The short version
CuraFlow Compliance sets only strictly necessary cookies. We do not use analytics, advertising, profiling or cross-site tracking cookies in this app, and we do not share cookie data with third parties for their own purposes.
Under regulation 6(4) of PECR, strictly necessary cookies — those without which a service you have asked for cannot be provided — do not require your consent. That is why this app does not ask you to opt in: there is nothing optional to opt in to.
2. The cookies we set
| Cookie | Provider | Purpose | Expiry |
|---|---|---|---|
| sb-<project>-auth-token | Supabase (via CuraFlow) | Keeps you signed in. Set on .curaflow.net so a single sign-in covers the CuraFlow suite. | Session / until sign-out |
| cf_consent | CuraFlow | Remembers that you have seen the cookie notice, so we do not show it on every page. | 6 months |
3. If that ever changes
If we introduce analytics or any other non-essential cookie, we will ask for your consent first, that cookie will not load until you give it, and this page will be updated before the change takes effect. Refusing will always be as easy as accepting.
4. Managing cookies in your browser
You can block or delete cookies through your browser settings. Note that blocking the necessary cookies above will stop the app keeping you signed in.
5. Complaints
If you are unhappy with how we handle cookies or personal data you can complain to the Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to put things right first — contact us at info@curacompliance.co.uk.