Cookies notice.
What we set on your device, why, and how to switch the optional ones off. Written under the UK Privacy and Electronic Communications Regulations (PECR).
The short version.
Right now this site sets only strictly necessary cookies, the ones needed to log you into the client portal and to stop forms being submitted by bots. We don't run analytics or marketing cookies today. When that changes we'll ask for your consent first, and this page will be updated.
Strictly necessary cookies.
These don't require consent because the site can't work without them.
- Session cookie, keeps you signed in to the client portal during a visit. Expires when you close the browser or after a short period of inactivity.
- CSRF token, a small random value that stops a different website tricking your browser into submitting forms on this one. Set per session.
- Consent state, once a cookie banner is in place, a small cookie will record your choices so we don't ask on every page. Set only when you make a choice.
Analytics and marketing, what's coming.
We don't run any analytics today. At launch we plan to add Meta's advertising pixel (sometimes called the Facebook Pixel) so we can measure which ads result in a real enquiry, and so we can stop running the ones that don't. These cookies are optional and they will not load until you give consent through the cookie banner. If you say no, you'll see the same site, just without us counting your visit.
Third-party cookies through Stripe.
When you pay an invoice, you're passed to Stripe's hosted checkout. Stripe sets its own cookies to keep the payment secure, run its fraud-prevention tools, and remember you between steps. Those cookies are governed by Stripe's own cookies policy. They're essential to processing the payment, without them, you can't check out.
How to control cookies.
You have two routes:
- The cookie banner, once shipped, it'll let you accept all, reject all, or pick categories, and it'll let you change your mind later from a link in the footer.
- Your browser settings - every modern browser lets you block or delete cookies, including for a specific site. The trade-off is that strictly-necessary cookies are, well, necessary. Block them and you won't be able to log in to the client portal.
Mobile devices have their own ad-tracking settings, on iOS, in Settings → Privacy & Security; on Android, in Settings → Privacy → Ads. These apply across apps, not just this site.
How this relates to your data.
Cookies are only one way data ends up with us. Everything we hold, including any data created when you accept cookies, is described in the privacy notice. Your rights (access, erasure, objection, the rest) apply there.
Changes.
We'll update this notice whenever we add or remove a cookie category. The date at the top of the page reflects the most recent change. This version was published on 19 May 2026.
Questions.
Email hello@theplancompany.co.uk and we'll come back to you.
