Cookies and similar technologies on Grovabe
This Policy explains how Grovabe Ltd uses cookies and similar technologies, including software development kits (SDKs), local storage, pixels, scripts, tags and device identifiers. The specific technologies in use are recorded in Schedule 1 below.
On this page
1. Who we are
Grovabe Ltd, company number 17353027, registered office 66 Paul Street, London, EC2A 4NA. Contact: support@grovabe.com. ICO registration: ZC207423.
2. What these technologies do
Cookies and similar technologies store information on or access information from a browser, computer, phone or other device. They may keep a user signed in, secure the Service, remember choices, measure performance, diagnose faults, deliver communications or understand use. PECR can apply even where the information is not personal data; UK data protection law also applies where a person is identifiable.
3. Categories we may use
Strictly necessary: required to provide a service requested by you, authenticate sessions, maintain security, balance traffic, remember privacy choices or complete payments. Consent is not generally required where the statutory exception applies.
Communication: used solely to transmit a communication over an electronic communications network. Consent is not required where the exception applies.
Statistical purposes: Grovabe does not currently use any technology for statistical purposes or rely on this exception.
Appearance or functionality: Grovabe does not currently use appearance/functionality cookies.
Preferences: remember non-essential choices. Consent may be required unless a current exception applies.
Analytics and performance: measure use, journeys, faults and performance. We will seek consent unless a current exception clearly applies and all its conditions are met.
Advertising or cross-service tracking: Grovabe does not currently use advertising or cross-service tracking.
4. Consent and objections
Where consent is required, non-essential technologies will not be activated before you make a choice. Consent must be freely given, specific, informed and unambiguous, and refusing must be as easy as accepting. You can withdraw your consent through your app privacy settings at any time. Withdrawal does not affect earlier lawful processing. Technologies relying on a statutory no-consent exception may instead provide a simple and free means to object where required.
Browser or device settings may also block or delete technologies, but doing so may affect functionality. App permissions and advertising identifiers can be controlled through device settings. Grovabe must not use a cookie wall unless access remains genuinely optional or the arrangement is otherwise lawful.
5. Third parties
Some technologies are set or read by providers supporting authentication, hosting, payments, AI, error monitoring, security, email, notifications or analytics. Schedule 1 identifies the party, purpose, duration, information and applicable consent or exception. Third parties may process data under their own privacy notices where they act as independent controllers.
6. Duration
Session technologies expire when the browser or app session ends. Persistent technologies remain for the period in Schedule 1 unless deleted earlier. Durations must be no longer than necessary and reviewed at least every 6 months and after material releases.
7. Changes and contact
We may update this Policy and Schedule as technologies change. Where a new purpose requires consent, we will request it before use. Contact support@grovabe.com with questions. Further information about personal data and rights appears in the Privacy Policy.
Schedule 1 — Cookie and similar technology register
Recorded from a production website scan, iOS/Android SDK inventory, browser storage review and developer confirmation. Only technologies actually stored or accessed on a user's device are listed here — a provider is not included merely because it appears elsewhere in the architecture.
| Name / SDK | Provider | Platform | Purpose & data | Category / legal rule | Duration | Default / controls |
|---|---|---|---|---|---|---|
| Supabase Auth Token | Supabase / Grovabe | Web / app | Authentication and session security | Strictly necessary | Persistent until sign-out. The authentication token automatically refreshes approximately hourly. Sessions currently have no fixed maximum duration; 7-day and 30-day limits are planned. | On; logout/delete |
| Cookie Consent Platform (CMP) | Grovabe / provider to be selected | Web | Stores privacy choice | Strictly necessary if implemented | Not applicable while no CMP is deployed. | Not currently implemented — there is no cookie banner at present. |
| Cloudflare Turnstile | Cloudflare | Web / app | Bot protection and security | Strictly necessary | Transient or single-use for each authentication challenge. | Loads only on authentication screens. |
| Sentry | Sentry | Web / app | Error and performance diagnostics; currently inactive unless a DSN is configured | Consent or statistical exception — under assessment | Short-lived, session-scoped identifiers; diagnostic events are transmitted when an error or relevant event occurs. | Active; there is currently no user-facing control. |
| OneSignal | OneSignal | iOS / Android | Push notifications; not currently built | Device permission and applicable PECR assessment | A notification remains until it is removed. | Not currently active; it will remain disabled until the feature launches and the user grants permission. |
| Stripe Checkout Cookies | Stripe | Web checkout | Payment security and completion | Strictly necessary for requested purchase | Stripe-controlled (_mid ~1yr, _sid ~30min) | Provider controls; only during checkout |
| RevenueCat (IAP) | RevenueCat | iOS / Android | In-app subscription purchases | Strictly necessary for requested purchase | RevenueCat controlled | Provider controls; only during checkout |
Schedule 2 — Implementation checklist
- Scan production website after deployment and after material tag changes.
- Inventory iOS and Android SDKs, device identifiers, local storage, secure storage and permissions.
- Classify each purpose separately; one technology used for several purposes may require consent for the non-exempt purpose.
- Block consent-dependent technologies before consent and honour withdrawal promptly.
- Provide equally prominent accept/reject choices and granular settings.
- Test withdrawal, objection and consent logging.
- Reconcile this Schedule with the Privacy Policy and provider contracts.
- Repeat review at least every 6 months.