Cookie Policy
Last updated: 17 July 2026
The short version: we set zero cookies of our own. Not for analytics, not for ads, not for consent banners. The one exception on this whole site: Stripe, our payment provider, sets two fraud-prevention cookies on the payment page — and only there. What we store in your browser is listed below, in full, and all of it exists so the product works, not to follow you around.
Cookies, and the other kinds of browser storage
"Cookie policy" is the familiar name, but cookies are only one way a website can keep things on your device. The UK's privacy rules (PECR) cover them all — anything stored on or read from your browser, including local storage, IndexedDB databases and offline caches. So this page lists everything we touch, not just cookies. BlueWave itself uses no cookies at all: signing in, themes and offline working all run on browser storage instead. The only cookies you can pick up here are Stripe's, on the payment page.
What this site stores
Everyone
| Key | What it does | How long |
|---|---|---|
bluewave-theme | Remembers your light/dark choice — only set if you use the theme toggle | Until you clear site data |
Signed-in office users
| Key | What it does | How long |
|---|---|---|
bw.access_token, bw.refresh_token, bw.token_expiry | Keeps you signed in | Until you sign out, or they expire |
bw.email | Pre-fills your email at sign-in | Until you clear site data |
bw.table, bw.dashboard.engineers | Remembers your column layout and dashboard filters | Until you clear site data |
Engineer app
| Storage | What it does | How long |
|---|---|---|
bw.pwa.* keys | Sign-in session, unsent draft notes, and a flag that you've seen the intro | Session until sign-out; drafts until they sync |
| IndexedDB database | Your assigned jobs, their forms, and an outbox of changes made offline — so the app keeps working with no signal | While you're signed in; cleared with site data |
| Service-worker cache | The app's own files (screens, styles) so it starts offline | Managed by the browser; replaced when the app updates |
Paying an invoice
| Cookie | What it does | How long |
|---|---|---|
__stripe_mid | Set by Stripe to recognise a device across payments, so the payment you're making can be screened for fraud | About 1 year |
__stripe_sid | Set by Stripe to tie together one payment session | About 30 minutes |
These two appear only when you open a payment page — the invoice payment screen, or the billing card in office settings. Stripe's scripts never load anywhere else on the site. Stripe acts as its own controller for fraud prevention; its privacy centre has the detail.
Everything above is strictly necessary — UK rules don't require consent for storage that exists purely to deliver the service you asked for, and fraud-screening a payment you're actively making falls on the same side of the line. Nothing in these tables tracks you across the web.
Analytics — none, for now
We don't measure you, because we don't measure anyone. No pageview counter runs on this site, no event tracking, no analytics provider. If we add one it will be cookieless, this page will name it, and it won't collect anything before we've said so here.
That's also why you see no consent banner. The consent rules bite on tools that store or read information on your device; everything in the tables above is strictly necessary to deliver what you asked for, and there's no analytics sitting on top of it. You get transparency instead, which is this page.
How to control browser storage
Your browser can list, block or delete everything described here — look for "site data" or "cookies and site data" in its settings. One honest warning for engineers: clearing site data for this origin while you have unsynced offline work will delete those drafts. Sync first.
If we ever add tracking
If we ever introduce a tool that does store something non-essential on your device — a marketing tag, say — we'll put a real opt-in banner in front of it first: granular choices, nothing pre-ticked, and "reject" as easy as "accept". This page will change at the same time. No silent additions.
Changes
When this policy changes, we'll update it here and change the date at the top. Material changes get flagged to account holders by email.