← Back to platform

Cookie Policy (UK / PECR)

Effective date: 28 July 2026
Compliance: Privacy and Electronic Communications Regulations 2003 (PECR), as amended, and UK GDPR

1. What are cookies and similar technologies?

Cookies are small files stored on your device. We also use browser local storage for some preference state (this is not an HTTP cookie).

2. Cookies we use

NamePurposeDurationCategory
vetro_jwtAuthentication (JWT)72 hoursStrictly necessary
vetro_sessionSession management72 hoursStrictly necessary
vetro_csrfCSRF protection (admin)72 hoursStrictly necessary
__cf_bm / cf_clearanceCloudflare bot / DDoS protectionup to 30 daysStrictly necessary
__stripe_sid / __stripe_midStripe Checkout (payment only)Session / 1 yearStrictly necessary (payment)
`__Host-GAPS` / Google Auth cookiesGoogle (accounts.google.com) — Authentication via Google Sign-InSessionStrictly necessary

3. Local storage (not a cookie)

KeyPurposeDurationCategory
vetro_cookie_consentStores your cookie / preference banner choice in the browser’s local storageuntil cleared (or up to about 1 year of recorded preference metadata)Preference (local storage)

4. Legal basis (PECR)

Strictly necessary cookies are set without consent because they are essential for a service you request (secure login, session integrity, payment security). Non-essential cookies (analytics, advertising) are not currently enabled on the UK deployment and will only be set after clear opt-in consent.

5. Managing cookies and preferences

You can clear the `vetro_cookie_consent` key in your browser’s local storage and revisit the banner, or control cookies in your browser settings. Blocking strictly necessary cookies may prevent sign-in.

6. More information

See our Privacy Policy. ICO cookie guidance: https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guide-to-pecr/cookies-and-similar-technologies/