Cookie Policy
Policy version 3.0 · in force from 15 August 2026
1. The position in short
Working a verification file leaves a trace in two places: on Verifit's systems, which the Privacy Policy accounts for, and on the device in front of whoever is doing the work. This page is the complete inventory of the second. On the public site the inventory runs to two security cookies placed by the infrastructure the site sits on, both of them strictly necessary and therefore outside the consent requirement — which is why no consent banner interrupts the page. Nothing here measures a reader, profiles them, or follows them anywhere else. Section 5 names every entry.
2. What this policy covers
Two surfaces are described. The first is the public website at verifit.uk, which anyone can read. The second is the signed-in workspace and the mobile apps, where files are actually worked and where a small amount of storage is unavoidable (section 6).
This page sits beside the Privacy Policy, which deals with personal data generally, and the Terms of Use. The three are meant to agree with one another; a discrepancy is a mistake worth reporting to support@verifit.uk rather than a subtlety worth parsing.
3. What counts as writing to a device
A cookie is a short text entry a site asks the browser to keep and return on later requests. A first-party entry belongs to the site being read; a third-party entry belongs to some other domain whose content the page pulls in. A session entry disappears when the browser closes; a persistent one survives until it expires or is cleared.
The law reaches further than cookies. It covers anything that puts information on a device, or reads information already there. That includes local and session storage, which hold values in the browser without sending them on every request; larger structured stores such as IndexedDB and the Cache API; pixels and beacons, being minute images or fragments of script whose loading registers that a page or a message was opened; the storage and software development kits inside a mobile app, including its secure key store; and device fingerprinting, which derives a near-unique signature from the characteristics of a browser and machine. Fingerprinting is not done here, by Verifit or by anyone acting for it.
4. The two rules that apply
Regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 says that putting information on a device, or reading what is already stored there, obliges the operator to explain plainly what it is for and to obtain that person's consent — unless the step is strictly necessary for delivering something they expressly asked for. That exemption is read narrowly, and mere convenience never satisfies it.
Where consent is required, the UK GDPR sets its standard: freely given, specific, informed, unambiguous, and expressed by a clear affirmative act. Reading on is not consent. A pre-ticked box is not consent. An interface that makes refusal harder than acceptance is not consent. And where an entry leads on to processing of personal data, a lawful basis is needed for that processing as well.
Everything catalogued in sections 5 and 6 falls inside the strictly necessary exemption, so no consent is asked for and none is implied. Section 10 sets out what happens if that ever stops being true.
5. The entries verifit.uk writes
This is the whole list for the public site. Cloudflare, which serves and protects the site, may place the following; the second appears only where a security challenge was actually put to the visitor.
| Name | Placed by | What it does | Kind | Lifespan | Consent |
|---|---|---|---|---|---|
__cf_bm |
Cloudflare, on the verifit.uk domain | Bot management — separates human traffic from automated traffic so that hostile bots can be turned away without challenging ordinary readers | HTTP cookie, strictly necessary | Up to 30 minutes, refreshed while browsing continues | Not required — PECR reg. 6(4) |
cf_clearance |
Cloudflare, on the verifit.uk domain | Records that a security challenge was passed, so the same challenge is not repeated on every subsequent page | HTTP cookie, strictly necessary; written only where a challenge was issued | Up to 1 year | Not required — PECR reg. 6(4) |
Past those two, the public pages write nothing at all: no first-party measurement entry, no local storage, no session storage, no IndexedDB record, no pixel, no beacon. The pages do ask Google's font service for the typefaces they display. That is not storage on the device, but it does mean the browser sends Google a request carrying its address and user agent, which is accounted for at section 18 of the Privacy Policy.
6. The entries the signed-in workspace writes
The workspace is an authenticated application, and it cannot function without keeping a little state on the device doing the work.
| Entry | Where it lives | What it does | Lifespan |
|---|---|---|---|
| Session and authentication token | A secure, HttpOnly first-party cookie in the browser; the Keychain on iOS; Keystore-backed storage on Android | Holds the sign-in and ties each request to the right account. Without it, every single request would demand the credentials again. | Until sign-out, expiry of the session, or removal of the app |
| Cross-site request forgery token | First-party cookie | Stops a hostile page submitting actions to the workspace in the signed-in user's name. | The session |
| Interface preferences | Browser local storage, or the preferences store on a mobile device | Remembers choices such as list density or which panel was left open, so the interface behaves consistently between visits. | Until site data is cleared or the app is removed |
| Capture in progress | The app's private sandbox on the device | Holds a document capture while quality checks run on the device itself, before anything is lodged on a file. | Removed once the capture is lodged or discarded |
Each of these is strictly necessary to a service the user asked for by signing in, so no consent is sought for them either. No advertising, attribution or data-broker software development kit is compiled into the apps, and no advertising identifier is read — section 21 of the Privacy Policy sets out the App Tracking Transparency and Play Data Safety position in full.
7. Measurement and advertising
No analytics product runs on verifit.uk. Not a hosted one, not a self-hosted one, not a cookieless script that claims to sidestep the question. Nor is there any advertising apparatus: no ad network, no remarketing tag, no conversion pixel from a social or search platform, no affiliate tracking, no data-broker integration, and no measurement that follows a reader between sites or devices. Personal data is neither sold nor shared for anyone else's purposes.
What does exist is server-side security logging by Cloudflare, described at section 18 of the Privacy Policy. It is not a cookie, it builds no profile of a visitor, and it is held for a short rolling window before it rolls off.
8. Clearing what a device holds
Cookies can be blocked or removed at any time from the browser's own privacy settings, and most browsers can also be told to clear everything on exit or to treat a particular site more strictly than the rest. Blocking the two entries in section 5 means Cloudflare's checks are likely to run more often, but the public pages will still be readable. Blocking the entries in section 6 makes signing in impossible, because the workspace has nowhere to keep the session.
On a mobile device, an app's storage is managed by the operating system rather than by the app: both iOS and Android expose a per-app storage screen from which an app's local data can be cleared, and removing the app clears it altogether. Neither action deletes an account or anything already lodged on a file — section 13 of the Privacy Policy covers that. Menu wording shifts between browser and operating-system releases, so the browser's own help is the reliable guide, and the Commissioner publishes independent guidance at ico.org.uk.
9. Signals a browser can send
Some browsers can send a Do Not Track header, asking sites not to follow the reader. It never became a binding standard and most vendors have retired it. A newer signal, Global Privacy Control, expresses an objection to personal data being sold or shared; it carries legal force in some jurisdictions and is not currently mandatory under UK law.
The answer to both is identical and does not depend on the signal arriving. Readers are not tracked, and personal data is not sold or shared with anyone for their own ends, so there is nothing either signal could switch off. A reader who sends one is treated exactly like a reader who does not, because both already receive the most private behaviour on offer. Were a non-essential technology introduced under section 10, Global Privacy Control would be honoured as an objection to optional processing, and no consent prompt would be allowed to override it.
10. If a non-essential entry is ever proposed
Suppose something not strictly necessary became worth having — privacy-respecting measurement, a support chat widget, an embedded video, a booking script. Before it loaded for the first time:
- consent would be asked for through a clear opt-in, with refusal presented as prominently and worked as easily as acceptance;
- nothing non-essential would be written unless and until agreement was actually given — no implied consent, no pre-ticked box, no consent inferred from continuing to read;
- consent once given could be withdrawn as easily as it was given, from a link in the footer of every page;
- the table at section 5 would be extended with the name, provider, purpose, kind and lifespan of each new entry, and the version line on this page would move with it; and
- refusing would never close off the site or the service.
11. Revision and contact
This page is revised whenever what is written to a device changes, and the revision lands before the new technology is used rather than after it. The version line at the top moves with each revision, and superseded versions are kept and supplied on request.
Questions, or a report that something on this page does not match what a browser actually shows, go to support@verifit.uk. See also the Privacy Policy and the Terms of Use.