Cookie Policy
- Version
- 2026-08-03
- Effective
- 3 August 2026
- Last updated
- 3 August 2026
This page lists the cookies and similar storage technologies actually used by Cyber Crisis Desk, taken from the current implementation rather than a template. It should be read with our Privacy Policy.
What cookies and similar technologies are
A cookie is a small text file a website asks your browser to store and send back on later requests. Websites also use other client-side storage that is technically not a cookie but serves a similar purpose:
- localStorage — values kept in your browser for this website until they are removed. Not sent automatically with requests.
- sessionStorage — the same idea, but cleared when you close the browser tab.
We describe all three below because they can all affect your privacy, even though only the first is genuinely a cookie.
What we actually use
| Name or key | Technology | Provider | Purpose | Category | Duration | Party |
|---|---|---|---|---|---|---|
sb-<project-ref>-auth-token | localStorage | Supabase, used by us | Stores your sign-in session so you stay authenticated while you work on a case. Without it you cannot use the signed-in application. | Strictly necessary | Until you sign out or the session expires | First-party |
crd:triage-draft:v1 | sessionStorage | Cyber Crisis Desk | Keeps your emergency-triage answers while you complete the wizard and sign in, so you do not lose them. | Strictly necessary | Until the browser tab is closed | First-party |
crd:cookie-consent:v1 | localStorage | Cyber Crisis Desk | Records your cookie choices: consent version, the categories you allowed, and the timestamp. Storing it is what lets us respect a rejection. | Strictly necessary | Until you withdraw consent or clear browser storage | First-party |
sidebar_state | Cookie | Cyber Crisis Desk | Remembers whether the navigation sidebar in the signed-in workspace is expanded or collapsed. Purely a convenience. | Preferences / functionality (optional) | 7 days | First-party |
_gcl_au | Cookie set by the Google tag | Google Ireland Limited / Google LLC | Google Ads measurement: recognises that a visit came from one of our adverts so we can count how many enquiries our advertising produces. Only written after you turn Marketing on; until then the Google tag runs with advertising storage denied (Google Consent Mode v2) and writes nothing. | Marketing (optional) | Up to 90 days | Third-party (Google), set on our domain |
Categories and consent
Strictly necessary
Necessary storage operates without asking for optional consent, because the service you have asked for cannot work without it: authentication, session continuity, security, keeping your triage answers during the wizard, completing a payment you initiated, and remembering your cookie choice. We still identify and explain it, which is what this page does.
Optional categories
Optional categories are off by default. Nothing optional is loaded or written before you turn it on.
- Preferences / functionality — currently only the
sidebar_statecookie in the signed-in workspace. - Analytics — none in use today.
- Marketing — the Google tag for our Google Ads account (
AW-16875498826), used only to measure whether our own adverts lead to enquiries. It is loaded with Google Consent Mode v2 in a fully denied state, so no advertising or analytics storage is written and no advertising identifiers are used until you turn Marketing on below.
Google Consent Mode v2
Your choices are passed to Google as a consent signal: ad_storage, ad_user_data and ad_personalization are controlled by the Marketing category, and analytics_storage by the Analytics category. All four start as denied, and they are set back to denied the moment you reject non-essential storage or withdraw consent. Google Ads measurement never affects sign-in, payments, the Emergency Check, case workflows or evidence uploads.
Payments and redirects
When you start a subscription or buy an Emergency Pass, you are redirected to a Stripe-hosted checkout or billing page. Stripe sets its own cookies on its own domain to process the payment and prevent fraud, under its own cookie and privacy notices. We do not embed Stripe scripts or Stripe cookies into our own pages, and rejecting our optional categories does not prevent checkout from working.
What we do not use
- no advertising cookies or advertising identifiers unless you accept the Marketing category — the Google tag is present but denied by default, and we do not use it to build advertising audiences or to personalise adverts;
- no tracking pixels or web beacons from any other provider;
- no analytics or product-measurement scripts;
- no social media embeds, fonts or videos loaded from third-party domains;
- no fingerprinting technology;
- no incident details, evidence, case content or account data are ever sent to Google.
The application does contain a neutral analytics helper that would send billing funnel events to a measurement tool if one were installed. No such tool is installed or loaded, so no events leave your browser.
Manage your preferences
Change your choices here at any time. The same controls are available from the Cookie settings link in the footer of every public page.
Strictly necessary — always on
Required to sign you in and keep you signed in (Supabase authentication storage), to keep your emergency-triage answers while you complete the wizard, and to complete a payment you have asked for. These cannot be switched off because the service would not work without them.
Remembers interface choices inside the signed-in workspace, such as whether the navigation sidebar is expanded (sidebar_state cookie). Turning this off does not affect any incident-response feature.
Not in use. Cyber Crisis Desk does not currently load any analytics or measurement script. This control stays available so that any future analytics would require your explicit opt-in first.
Lets us measure whether our own Google adverts lead to enquiries (Google tag AW-16875498826, _gcl_au cookie). Until you turn this on, the Google tag runs with advertising storage and advertising identifiers denied. No incident details, evidence or account data are ever sent to Google, and turning it off does not affect sign-in, payments or any incident-response feature.
Your current choice was recorded on 9/13/2026, 11:54:50 PM (consent version 2026-08-03).
Browser-level controls
You can also block or delete cookies and clear site storage in your browser settings, and use private browsing. Blocking strictly necessary storage will prevent you from signing in and using the incident workspace.
Changes and contact
We will update this page whenever the storage technologies we use change, and we will bump the consent version if a change means your previous choice can no longer be relied on.
Cyber Crisis Desk is operated by Miro Global Services LTD, registered in England and Wales under company number 14466196. Registered office: 7 The Colliery, Donnington Wood, Telford, England, TF2 7FQ.
Questions: privacy@cybercrisisdesk.com