Cookie Policy

Last updated: 17 July 2026

The short version: we set zero cookies of our own. Not for analytics, not for ads, not for consent banners. The one exception on this whole site: Stripe, our payment provider, sets two fraud-prevention cookies on the payment page — and only there. What we store in your browser is listed below, in full, and all of it exists so the product works, not to follow you around.

Cookies, and the other kinds of browser storage

"Cookie policy" is the familiar name, but cookies are only one way a website can keep things on your device. The UK's privacy rules (PECR) cover them all — anything stored on or read from your browser, including local storage, IndexedDB databases and offline caches. So this page lists everything we touch, not just cookies. BlueWave itself uses no cookies at all: signing in, themes and offline working all run on browser storage instead. The only cookies you can pick up here are Stripe's, on the payment page.

What this site stores

Everyone

KeyWhat it doesHow long
bluewave-themeRemembers your light/dark choice — only set if you use the theme toggleUntil you clear site data

Signed-in office users

KeyWhat it doesHow long
bw.access_token, bw.refresh_token, bw.token_expiryKeeps you signed inUntil you sign out, or they expire
bw.emailPre-fills your email at sign-inUntil you clear site data
bw.table, bw.dashboard.engineersRemembers your column layout and dashboard filtersUntil you clear site data

Engineer app

StorageWhat it doesHow long
bw.pwa.* keysSign-in session, unsent draft notes, and a flag that you've seen the introSession until sign-out; drafts until they sync
IndexedDB databaseYour assigned jobs, their forms, and an outbox of changes made offline — so the app keeps working with no signalWhile you're signed in; cleared with site data
Service-worker cacheThe app's own files (screens, styles) so it starts offlineManaged by the browser; replaced when the app updates

Paying an invoice

CookieWhat it doesHow long
__stripe_midSet by Stripe to recognise a device across payments, so the payment you're making can be screened for fraudAbout 1 year
__stripe_sidSet by Stripe to tie together one payment sessionAbout 30 minutes

These two appear only when you open a payment page — the invoice payment screen, or the billing card in office settings. Stripe's scripts never load anywhere else on the site. Stripe acts as its own controller for fraud prevention; its privacy centre has the detail.

Everything above is strictly necessary — UK rules don't require consent for storage that exists purely to deliver the service you asked for, and fraud-screening a payment you're actively making falls on the same side of the line. Nothing in these tables tracks you across the web.

Analytics — none, for now

We don't measure you, because we don't measure anyone. No pageview counter runs on this site, no event tracking, no analytics provider. If we add one it will be cookieless, this page will name it, and it won't collect anything before we've said so here.

That's also why you see no consent banner. The consent rules bite on tools that store or read information on your device; everything in the tables above is strictly necessary to deliver what you asked for, and there's no analytics sitting on top of it. You get transparency instead, which is this page.

How to control browser storage

Your browser can list, block or delete everything described here — look for "site data" or "cookies and site data" in its settings. One honest warning for engineers: clearing site data for this origin while you have unsynced offline work will delete those drafts. Sync first.

If we ever add tracking

If we ever introduce a tool that does store something non-essential on your device — a marketing tag, say — we'll put a real opt-in banner in front of it first: granular choices, nothing pre-ticked, and "reject" as easy as "accept". This page will change at the same time. No silent additions.

Changes

When this policy changes, we'll update it here and change the date at the top. Material changes get flagged to account holders by email.

Cookie Policy | BlueWave