Cookie policy
Last updated 2026
1. The short version
We set one cookie, and only once you sign in. It exists to keep you signed in. We do not run advertising cookies, we do not run third-party analytics, and we do not sell or share what you do here with anyone. That is why you are not being asked to dismiss a consent banner.
2. What we set
| Name | Purpose | Lasts |
|---|---|---|
session |
Keeps you signed in to your portal and protects forms against cross-site request forgery. It is cryptographically signed, and it holds an account reference, not your documents or your credit data. | Until you sign out or the session expires |
It is a strictly necessary cookie: sign-in cannot work without it, so it does not require consent under the ePrivacy rules or their state equivalents.
3. What we do not set
- No advertising or retargeting cookies, and no ad-network pixels.
- No third-party analytics or session-recording tools.
- No social media trackers or embedded like buttons.
- No cross-site profiling of any kind.
4. Other browser storage
We do not use local storage, session storage or fingerprinting. Your browser will cache our stylesheet, script and images, which is ordinary caching and holds nothing about you.
5. Fonts
Our typeface is served by Google Fonts, so loading a page makes a request to Google that includes your IP address and browser details. Google does not set cookies on that request. If that matters to you, a content blocker will stop it and the site will fall back to a system font.
6. Turning cookies off
Every browser lets you block or delete cookies in its privacy settings. Blocking ours means you will not be able to sign in to your portal, since there is nothing left to remember you by. The public pages will work normally.
7. Do Not Track
There is nothing for us to honour or ignore: we do not track you across sites in the first place.
How we handle the information you give us is covered in the privacy policy.