Cookie and browser storage policy.
We do not use advertising cookies or cross-site behavioural tracking. The limited browser storage below is used only to provide requested tools, secure a purchase and retain a chosen local output.
Last updated 31 August 2026
What we use
- Purchase session
bct_guest_session_v1keeps a signed, anonymous purchase session on that device. It is created when you start a purchase and reconnects the payment to the correct entitlement.- Complaints pack session draft
bct:complaints-pack:draft:v2keeps the case draft in session storage while secure checkout opens and returns. The draft stays in the browser and is not sent with the checkout request.- Tool purchase state
bct:tool-access:*,bct:tool-recovery:*andbct:tool-output-locks:*hold limited purchase-state, recovery and output-authorisation records. They are used only for the requested tool and its download controls.- Checkout return record
bct:pending-purchase-recovery:v1keeps the attempt, transaction and product identifiers needed to reconnect the browser after checkout. After fulfilment, recovery codes are generated on the server, stored only as irreversible hashes and shown once in the browser.- Private output archive
business-compliance-tools-private-outputsis an IndexedDB database used to keep the exact generated ZIP on the browser that created it. The record includes the ZIP, filename, size, integrity hash, authorised export identifier and saved date. When you choose Account recovery, the same ZIP is also uploaded to a private 30-day archive.- Hosted checkout storage
- Paddle may set cookies or similar technologies in secure checkout for payment, fraud prevention, security and session continuity. Paddle controls that checkout.
Why there is no consent banner
We use storage only where it is strictly necessary to provide a service you request, protect payment, return a local draft to the same tab, preserve a checkout return record or make the exact generated ZIP available again on that browser. We do not set advertising, analytics or social-media tracking technologies.
If we add non-essential storage or tracking, we will update this page and ask for valid consent before it runs.
How to control it
Use My account to download or delete an individual private ZIP. A saved ZIP remains on that browser until you delete it, clear site data or the browser removes local storage. Clearing site storage may also remove a local draft and the browser-bound purchase identity. Deleting a local ZIP does not delete the commercial purchase record, and recovery codes cannot recreate the private files. A refund or payment reversal can stop new server authorisations, but it cannot remotely delete a ZIP already delivered to the browser.
Questions
For privacy questions, use the details in our privacy notice.