FleetVerified
Privacy & Legal Centre / Cookie and On-Device Storage Notice

Cookie and On-Device Storage Notice

Version 1.0.0 · In effect from 7 August 2026

What the platform stores on your device, why, and why there is no consent banner: nothing stored is used for analytics, advertising or tracking.

Contents

  1. 1. The short version
  2. 2. Cookies
  3. 3. What is stored on your device
  4. 4. Analytics and marketing
  5. 5. Signing in with Google — assessed separately
  6. 6. Your control

1. The short version

FleetVerified sets no advertising cookies, no third-party analytics and no cross-site tracking of any kind. It uses a small number of strictly necessary and functional storage items on your own device so that you can stay signed in, keep working when the signal drops, and not lose a half-finished inspection.

UK law (PECR regulation 6) requires consent before storing information on your device unless that storage is strictly necessary to provide the service you asked for. Every item below is either strictly necessary or a functional item without which the feature you deliberately used would not work. That is why there is no accept/reject banner: there is nothing to reject that would leave a working product behind.

2. Cookies

The application sets no cookies of its own. Authentication uses browser storage rather than cookies. If your network or hosting provider sets a load-balancing or security cookie in transit, it carries no identifying information about you and is not used for tracking.

3. What is stored on your device

Audited against the running application
ItemTechnologyPurposeClassificationLifetime
sb-…-auth-tokenLocal storageKeeps you signed in and refreshes your session. Without it you would be signed out on every page load.Strictly necessaryUntil sign-out or session expiry
fleetcomply.deviceTokenLocal storageRandom identifier for this device so a trusted device can be recognised and so two-step verification is not demanded on every sign-in.Strictly necessary (security)Persistent until cleared; the matching server-side trust expires after 30 days
fleetcomply.mfaSatisfiedSession storageRecords that two-step verification has been completed for this browser session.Strictly necessary (security)Cleared when the tab closes
fc:post-authSession storageRemembers the page you were heading to — for example an invitation link — so you land there after signing in.Strictly necessaryCleared immediately after use
fleetcomply.activeCompanyLocal storageRemembers which operator workspace you last had open, for people who belong to more than one.FunctionalPersistent until cleared
Walkaround check draftsLocal storageKeeps a part-completed inspection on your device so a dropped signal or a closed tab does not lose the work.FunctionalDeleted when the check is submitted
fleetcomply-offlineIndexedDBHolds queued work — checks, defects, photographs, labour entries — created while offline, until it can be synchronised.Strictly necessary (offline working)Deleted as each item synchronises; cleared on sign-out

Nothing in the table is shared with a third party, used to build a profile, or read across other websites. None of it is a cookie, so none of it is transmitted automatically with every request.

4. Analytics and marketing

None are in use. There is no Google Analytics, no advertising pixel, no session-recording tool, no heat-mapping and no marketing tag. Usage insight is derived from server-side counts that are not tied to an individual's browsing.

If we ever introduce a non-essential technology we will implement prior consent and a preference centre before it runs, not afterwards, and it will be off by default.

5. Signing in with Google — assessed separately

Google sign-in is an authentication mechanism, not a tracking technology, and it should not be confused with Google Analytics or advertising products. It runs only if you choose it.

  • It is strictly necessary for the sign-in you asked for, so it does not require a consent banner.
  • Choosing it takes you to Google's own domain, where Google sets its own cookies under its own privacy policy. That happens on Google's site, not ours.
  • We receive only your name, email address and Google account identifier — enough to identify your account. We receive no contacts, no calendar and no advertising data.
  • We do not embed Google fonts, tag managers, reCAPTCHA or any other Google resource that would load on a page before you make that choice.
  • You can use email and password instead if you would prefer not to involve Google at all.

6. Your control

Signing out clears the session items and the offline queue for that account. You can clear all site data at any time through your browser settings. Doing so signs you out, forgets the trusted device (so two-step verification will be requested again), and discards any unsynchronised offline work — so please synchronise first.

Questions about this notice: privacy@fleetverified.co.uk.

Other documents

  • Privacy Notice
  • Terms of Service
  • Data Processing Agreement
  • Sub-processors
  • Security Overview
  • Data Retention Overview