Cookie Policy
Last Updated: 4 May 2026
1. About this policy
This Cookie Policy explains how Standard Tonnage Limited uses cookies and similar technologies on standardtonnage.com and on our application at app.standardtonnage.com. It should be read alongside our Privacy Policy.
2. What cookies are
Cookies are small text files placed on your device by a website. “Similar technologies” include local storage, session storage, and pixel tags. In this policy, “cookie” refers to all of these.
3. Three categories
We group cookies into three categories. Strictly necessary cookies are always on (we cannot deliver the service without them). Analytics and marketing cookies are off by default — we ask for your explicit consent before they are set.
- Strictly necessary — keep you signed in, prevent CSRF attacks, remember your cookie choices.
- Analytics — aggregate, non-advertising usage stats so we can see which features and pages are actually useful.
- Marketing — measure which acquisition channels bring people who sign up. Used by paid-channel attribution and remarketing.
4. Your choice — the consent banner
When you first visit either domain, a banner asks for your consent. Three options are equally easy to take:
- Accept all — analytics + marketing cookies are allowed.
- Reject all — only strictly necessary cookies are set. The Service still works.
- Customise — choose analytics and/or marketing independently.
We use Google Consent Mode v2 which means: until you explicitly opt in, all advertising and analytics cookies are set to “denied” at the platform level. Tags either run in cookieless ping mode or do not run at all.
You can change your choice at any time. From the marketing site, click the “Cookie settings” link in the footer. From inside the application, go to Settings → Cookies. Your decision is stored in a cookie called st-consent (set on .standardtonnage.com) for one year.
5. Strictly necessary cookies
| Name | Set by | Purpose | Lifetime |
|---|---|---|---|
| sb-*-auth-token | Supabase (app.standardtonnage.com) | Keeps you securely signed in to your account. | Session / up to 7 days |
| sb-refresh-token | Supabase (app.standardtonnage.com) | Refreshes your session without re-prompting for your password. | Up to 30 days |
| __stripe_* | Stripe (only on the billing surfaces in app.standardtonnage.com) | Fraud prevention and session integrity for the Stripe checkout flow. | Session / 1 year |
| next-* | Next.js framework (both domains) | Internal state needed to render the correct page content. | Session |
| __Host-csrf | Standard Tonnage | Protects against cross-site request forgery on authenticated actions. | Session |
| st-consent | Standard Tonnage (.standardtonnage.com) | Records your choice from the consent banner so we don't ask again. | 1 year |
6. Analytics cookies (consent required)
These cookies only set if you have opted in via the consent banner or the cookie preferences page.
| Name | Set by | Purpose | Lifetime |
|---|---|---|---|
| _ga | Google Analytics 4 | Distinguishes unique browsers for aggregate page-view stats. | 2 years |
| _ga_* | Google Analytics 4 | Per-property session state. | 2 years |
| ph_* | PostHog (eu.posthog.com) | Product-analytics anonymous identifier and session state. EU-region tenant. | 1 year |
| Vercel Analytics | Vercel (marketing site only) | Aggregate page-view counts. Operates without cookies or persistent identifiers — included here for completeness. | N/A (cookieless) |
7. Marketing cookies (consent required)
These cookies only set if you have opted in. They are used for paid-channel attribution and remarketing.
| Name | Set by | Purpose | Lifetime |
|---|---|---|---|
| _fbp | Meta Pixel (Facebook / Instagram) | Conversion tracking for Meta ad campaigns. | 3 months |
| _li_* / li_oatml / lidc | LinkedIn Insight Tag | Conversion and audience-build tracking for LinkedIn ad campaigns. | Up to 90 days |
| _gcl_* | Google Ads | Conversion tracking for Google Ads campaigns. | 90 days |
Cookie names shown with * may vary by version. The categories and purposes do not change.
8. Local and session storage
- Local storage: we cache a small amount of application data (dashboard preferences, last-viewed filters, your consent choice) to make the application responsive. None of this data is used for tracking and none of it leaves your browser without your action.
- Session storage: used for temporary, in-tab state that is discarded when you close the tab.
9. Blocking cookies in your browser
You can clear cookies for our domains from your browser settings at any time. Doing so will sign you out of the application; you will need to sign in again. If you block cookies entirely, the Service cannot keep you signed in.
Guidance for controlling cookies in major browsers is published by the ICO at ico.org.uk/your-data-matters/online/cookies.
10. Do Not Track and Global Privacy Control
Where the “Global Privacy Control” signal is present, we treat it as a rejection of analytics and marketing cookies — the consent banner still appears, but the “Reject all” choice is pre-selected.
11. Changes
We will update this Cookie Policy if our practice changes. If we add a new sub-processor that sets cookies, we will publish it on the sub-processors page first and refresh this list. Material changes are highlighted at the top of this page for at least 30 days.
12. Contact
Questions about this policy can be sent to info@standardtonnage.co.uk.
Standard Tonnage Limited, registered in England and Wales.
Questions about this document: info@standardtonnage.co.uk · Security: security@standardtonnage.com