Cookie Policy (UK / PECR)
Effective date: 28 July 2026
Compliance: Privacy and Electronic Communications Regulations 2003 (PECR), as amended, and UK GDPR
1. What are cookies and similar technologies?
Cookies are small files stored on your device. We also use browser local storage for some preference state (this is not an HTTP cookie).
2. Cookies we use
| Name | Purpose | Duration | Category |
|---|---|---|---|
| vetro_jwt | Authentication (JWT) | 72 hours | Strictly necessary |
| vetro_session | Session management | 72 hours | Strictly necessary |
| vetro_csrf | CSRF protection (admin) | 72 hours | Strictly necessary |
| __cf_bm / cf_clearance | Cloudflare bot / DDoS protection | up to 30 days | Strictly necessary |
| __stripe_sid / __stripe_mid | Stripe Checkout (payment only) | Session / 1 year | Strictly necessary (payment) |
| `__Host-GAPS` / Google Auth cookies | Google (accounts.google.com) — Authentication via Google Sign-In | Session | Strictly necessary |
3. Local storage (not a cookie)
| Key | Purpose | Duration | Category |
|---|---|---|---|
| vetro_cookie_consent | Stores your cookie / preference banner choice in the browser’s local storage | until cleared (or up to about 1 year of recorded preference metadata) | Preference (local storage) |
4. Legal basis (PECR)
Strictly necessary cookies are set without consent because they are essential for a service you request (secure login, session integrity, payment security). Non-essential cookies (analytics, advertising) are not currently enabled on the UK deployment and will only be set after clear opt-in consent.
5. Managing cookies and preferences
You can clear the `vetro_cookie_consent` key in your browser’s local storage and revisit the banner, or control cookies in your browser settings. Blocking strictly necessary cookies may prevent sign-in.
6. More information
See our Privacy Policy. ICO cookie guidance: https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guide-to-pecr/cookies-and-similar-technologies/