Last updated 1 January 2024
Cookie policy
There are three, and one of them is optional. This is an accurate description of what the code sets; the consent mechanism you need depends on which optional integrations you switch on.
Draft — not yet reviewed by a solicitor
This document describes how the platform actually works, which is the part only we can write. It has not been checked by a qualified lawyer and it is not legal advice. Sections marked below need professional input before launch. See
src/config/legal.ts.Strictly necessary
- parade_session — your sign-in session. HttpOnly, expires after 30 days, and holds a random token rather than any information about you.
- parade_aid — a random identifier used to avoid counting the same browser twice in impression figures. Contains no personal data.
Attribution
- parade_attr — records the marketing source you first arrived from (for example, a Meta ad campaign name). It lets us tell which advertising is worth paying for. It contains no personal data and expires after 90 days.
Third-party advertising
Needs a solicitor’s review
If the Meta Pixel or Google Analytics is configured on this deployment, those services set their own cookies under their own policies. Neither is required for the site to work, and neither loads unless an ID is configured.
PLACEHOLDER. If you enable either, you need a consent banner that blocks them until the visitor agrees, and this section must list what they set.