Cookie Policy

Version
2026-08-03
Effective
3 August 2026
Last updated
3 August 2026

This page lists the cookies and similar storage technologies actually used by Cyber Crisis Desk, taken from the current implementation rather than a template. It should be read with our Privacy Policy.

What cookies and similar technologies are

A cookie is a small text file a website asks your browser to store and send back on later requests. Websites also use other client-side storage that is technically not a cookie but serves a similar purpose:

  • localStorage — values kept in your browser for this website until they are removed. Not sent automatically with requests.
  • sessionStorage — the same idea, but cleared when you close the browser tab.

We describe all three below because they can all affect your privacy, even though only the first is genuinely a cookie.

What we actually use

Verified against the current application code. Only the sidebar preference and the Google Ads measurement cookie are optional.
Name or keyTechnologyProviderPurposeCategoryDurationParty
sb-<project-ref>-auth-tokenlocalStorageSupabase, used by usStores your sign-in session so you stay authenticated while you work on a case. Without it you cannot use the signed-in application.Strictly necessaryUntil you sign out or the session expiresFirst-party
crd:triage-draft:v1sessionStorageCyber Crisis DeskKeeps your emergency-triage answers while you complete the wizard and sign in, so you do not lose them.Strictly necessaryUntil the browser tab is closedFirst-party
crd:cookie-consent:v1localStorageCyber Crisis DeskRecords your cookie choices: consent version, the categories you allowed, and the timestamp. Storing it is what lets us respect a rejection.Strictly necessaryUntil you withdraw consent or clear browser storageFirst-party
sidebar_stateCookieCyber Crisis DeskRemembers whether the navigation sidebar in the signed-in workspace is expanded or collapsed. Purely a convenience.Preferences / functionality (optional)7 daysFirst-party
_gcl_auCookie set by the Google tagGoogle Ireland Limited / Google LLCGoogle Ads measurement: recognises that a visit came from one of our adverts so we can count how many enquiries our advertising produces. Only written after you turn Marketing on; until then the Google tag runs with advertising storage denied (Google Consent Mode v2) and writes nothing.Marketing (optional)Up to 90 daysThird-party (Google), set on our domain

Categories and consent

Strictly necessary

Necessary storage operates without asking for optional consent, because the service you have asked for cannot work without it: authentication, session continuity, security, keeping your triage answers during the wizard, completing a payment you initiated, and remembering your cookie choice. We still identify and explain it, which is what this page does.

Optional categories

Optional categories are off by default. Nothing optional is loaded or written before you turn it on.

  • Preferences / functionality — currently only the sidebar_state cookie in the signed-in workspace.
  • Analytics — none in use today.
  • Marketing — the Google tag for our Google Ads account (AW-16875498826), used only to measure whether our own adverts lead to enquiries. It is loaded with Google Consent Mode v2 in a fully denied state, so no advertising or analytics storage is written and no advertising identifiers are used until you turn Marketing on below.

Google Consent Mode v2

Your choices are passed to Google as a consent signal: ad_storage, ad_user_data and ad_personalization are controlled by the Marketing category, and analytics_storage by the Analytics category. All four start as denied, and they are set back to denied the moment you reject non-essential storage or withdraw consent. Google Ads measurement never affects sign-in, payments, the Emergency Check, case workflows or evidence uploads.

Payments and redirects

When you start a subscription or buy an Emergency Pass, you are redirected to a Stripe-hosted checkout or billing page. Stripe sets its own cookies on its own domain to process the payment and prevent fraud, under its own cookie and privacy notices. We do not embed Stripe scripts or Stripe cookies into our own pages, and rejecting our optional categories does not prevent checkout from working.

What we do not use

  • no advertising cookies or advertising identifiers unless you accept the Marketing category — the Google tag is present but denied by default, and we do not use it to build advertising audiences or to personalise adverts;
  • no tracking pixels or web beacons from any other provider;
  • no analytics or product-measurement scripts;
  • no social media embeds, fonts or videos loaded from third-party domains;
  • no fingerprinting technology;
  • no incident details, evidence, case content or account data are ever sent to Google.

The application does contain a neutral analytics helper that would send billing funnel events to a measurement tool if one were installed. No such tool is installed or loaded, so no events leave your browser.

Manage your preferences

Change your choices here at any time. The same controls are available from the Cookie settings link in the footer of every public page.

Strictly necessary — always on

Required to sign you in and keep you signed in (Supabase authentication storage), to keep your emergency-triage answers while you complete the wizard, and to complete a payment you have asked for. These cannot be switched off because the service would not work without them.

Remembers interface choices inside the signed-in workspace, such as whether the navigation sidebar is expanded (sidebar_state cookie). Turning this off does not affect any incident-response feature.

Not in use. Cyber Crisis Desk does not currently load any analytics or measurement script. This control stays available so that any future analytics would require your explicit opt-in first.

Lets us measure whether our own Google adverts lead to enquiries (Google tag AW-16875498826, _gcl_au cookie). Until you turn this on, the Google tag runs with advertising storage and advertising identifiers denied. No incident details, evidence or account data are ever sent to Google, and turning it off does not affect sign-in, payments or any incident-response feature.

Your current choice was recorded on 9/13/2026, 11:54:50 PM (consent version 2026-08-03).

Browser-level controls

You can also block or delete cookies and clear site storage in your browser settings, and use private browsing. Blocking strictly necessary storage will prevent you from signing in and using the incident workspace.

Changes and contact

We will update this page whenever the storage technologies we use change, and we will bump the consent version if a change means your previous choice can no longer be relied on.

Cyber Crisis Desk is operated by Miro Global Services LTD, registered in England and Wales under company number 14466196. Registered office: 7 The Colliery, Donnington Wood, Telford, England, TF2 7FQ.

Questions: privacy@cybercrisisdesk.com