Cookies Policy
1. What Are Cookies
Cookies are small text files that are placed on your device (computer, tablet, or mobile phone) when you visit a website. They allow the website to recognise your device and store information about your preferences or past actions.
We use cookies and similar technologies on the GoFindPart Platform to ensure it functions correctly, to remember your preferences, and to understand how the Platform is used.
GoFindPart Ltd is the data controller for cookies set on the Platform. See our Privacy Policy for the broader data-protection context.
2. How We Use Cookies
We classify our cookies into three categories based on their purpose. You can manage your preferences for Functional and Analytics cookies through the consent controls on the Platform.
2.1 Necessary Cookies
These cookies are essential for the Platform to function and cannot be disabled. They enable core functionality such as user authentication, security features, and consent management.
| Cookie Name | Purpose | Duration | Type |
|---|---|---|---|
__Secure-refresh_token | Maintains your authenticated session by enabling secure token refresh. Sent only to the refresh endpoint (/api/auth/refresh), never to any other path | 7 days | HttpOnly, Secure, SameSite: Lax |
consent | Stores your cookie consent preferences. HMAC-signed to prevent tampering | 13 months | HttpOnly, Secure, SameSite: Lax |
2.2 Functional Cookies
These cookies enable enhanced functionality and personalisation, such as remembering your display preferences and your last active role. They require your explicit opt-in consent.
| Cookie Name | Purpose | Duration | Type |
|---|---|---|---|
prefs | Stores UI preferences (theme, locale, last role). HMAC-signed to prevent tampering | 1 year | HttpOnly, Secure, SameSite: Lax |
gfp-theme | Remembers light/dark choice so the page paints in the right theme before any script runs. HMAC-signed to prevent tampering. Readable by the page — it has to be, because the pre-paint script reads it | 1 year | Secure, SameSite: Lax |
gfp_sess | Records only THAT you are signed in, so the marketing site can show the right header without asking the API. Carries no name, email or token. HMAC-signed to prevent tampering. Readable by the page | 30 days | Secure, SameSite: Lax |
If you revoke consent for Functional cookies, the prefs cookie
will be cleared and your preferences will revert to defaults.
2.3 Analytics Cookies
These cookies help us understand how the Platform is used so that we
can improve it. They require your explicit opt-in consent. While you
are signed in, the analytics events we record — pages viewed, actions
taken and the search terms you enter in the Platform — are linked to
your account so that we can tell buyer journeys from seller journeys;
when you are not signed in they are linked only to the anonymous aid
identifier. Analytics events are deleted 26 months after they are
recorded, and are deleted with your account if you ask us to erase it.
| Cookie Name | Purpose | Duration | Type |
|---|---|---|---|
aid | Analytics identifier for the events recorded while you are not signed in (page views, navigation, interactions) | 13 months | HttpOnly, Secure, SameSite: Lax |
If you revoke consent for Analytics cookies, the aid cookie will
be cleared and no further analytics events will be tracked for your
session.
3. Cookie Security
All cookies used on the Platform are set with security-focused attributes:
- HttpOnly — every cookie that carries or protects your session is HttpOnly, meaning it cannot be accessed by JavaScript running in the browser. This protects against cross-site scripting (XSS) attacks.
- Secure — in production, all cookies are transmitted only over encrypted HTTPS connections.
- SameSite — our cookies use “Lax” mode. For the session cookie this is paired with a path restriction (it is only ever sent to the refresh endpoint) and a separate anti-forgery token on state-changing requests, which is what prevents another site from acting as you. Preference and consent cookies use “Lax” mode. Both settings help prevent cross-site request forgery (CSRF) attacks.
- HMAC signing — the
consentandprefscookies are cryptographically signed (HMAC-SHA256) to prevent tampering.
4. Third-Party Cookies
Stripe
We use Stripe for payment processing. GoFindPart Ltd is the merchant of record on Stripe Transactions — your card statement will show GoFindPart Ltd as the merchant, not the Fulfilling Supplier. Stripe may set its own cookies when you interact with payment forms on the Platform. Stripe’s use of cookies is governed by Stripe’s own privacy and cookie policies, available at stripe.com/privacy.
Crisp (support chat) — no cookies
Our in-Platform support chat is powered by Crisp (operated by Crisp IM SAS, France), but Crisp’s own software runs entirely on our servers — we do not load Crisp’s client widget in your browser, and no Crisp cookies are set on your device. The chat you see is a native part of the Platform; messages are relayed to Crisp by our backend so our support team can answer them. Crisp processes your support-conversation content as a data processor on our behalf (see our Privacy Policy). Because no Crisp cookies are set, Crisp does not appear in the cookie tables above.
Other service providers
We use a small number of service providers for error monitoring and infrastructure operations. None of them sets a cookie on your device. The full list, with what each provider does and where it processes data, is published at gofindpart.com/legal/subprocessors.
Our public website (www.gofindpart.com)
Our public marketing site — the pages you can read without signing in — sets no cookies of its own. This is everything it loads or stores on your device:
| Script or storage | What it does | Stored on your device | How to object |
|---|---|---|---|
| Plausible (analytics) | Counts page views and clicks so we know which pages help. Cookieless: it receives your IP address and browser type to work out the country and device class of a visit and to count one person once, then discards them. It sets no cookie and builds no profile. Served from our own domain. | Nothing | Send the Global Privacy Control signal from your browser, or use the “Analytics on this device” control on this page |
| Sentry (error monitoring) | If a page breaks, sends us the error message, where in our code it happened, the page address and your browser type and version, so we can fix it. No session recordings are made, no form contents are sent, and your IP address is not stored with the report. | Nothing | The same signal and control turn error reporting off as well |
| Cloudflare Turnstile | Protects our contact and early-access forms from bots. Runs inside a Cloudflare frame on those pages only; it receives your IP address to tell a person from a bot and may use storage within that frame. | Nothing on our domain | Do not use the form; email us instead — the address is on the contact page |
gfp-theme | Remembers your light / dark choice, made with the theme switch | Browser local storage, until you clear it | Leave the switch at the default; nothing is stored until you use it |
gfp_sess | Set by the Platform when you sign in (see 2.2). The public site only reads it, to show “Go to dashboard” instead of “Sign in” | The cookie described in 2.2 | Sign out of the Platform |
plausible_ignore | Your “analytics off on this device” choice, so we do not have to ask each visit | Browser local storage, until you clear it or turn analytics back on | This is the objection control itself |
| Site search | Runs entirely in your browser from a downloaded index | Nothing | — |
| Video embeds (YouTube, Vimeo) | Only on pages that include a video, and only when you press play. YouTube is loaded from its privacy-enhanced (no-cookie) domain | Nothing until you press play; the video provider’s own policy applies after that | Do not play the video |
We do not use any advertising cookies or share cookie data with advertising networks.
5. Managing Your Cookie Preferences
You can manage your cookie preferences in the following ways:
- Platform consent controls — when you first visit the Platform, a consent banner will ask you to choose which optional cookie categories you wish to enable. You can change your preferences at any time through the consent settings in your account.
- Browser settings — most browsers allow you to block or delete cookies. However, blocking Necessary cookies may prevent the Platform from functioning correctly.
- On our public website — analytics and error reporting there are cookieless and need no banner, but you can still object. We honour the Global Privacy Control signal (a setting in your browser or a browser extension): when it is on, neither loads. You can also use the “Analytics on this device” control at the foot of this page or of the Privacy Policy, which turns both off for that browser.
Your choice is stored in the consent cookie for 13 months. We ask you
to confirm it again once it is 12 months old, or sooner if the
consent version of this policy changes. The cookie outlives the re-ask
by a month so that your previous choice can be shown back to you when
we ask.
6. Consent Renewal
In accordance with regulatory guidance, we ask you to renew your cookie consent in the following circumstances:
- your consent is older than 12 months;
- the Platform’s cookie policy version has changed since you last gave consent; or
- you have cleared your cookies and the consent cookie is no longer present.
7. Data Collected Through Cookies
Necessary cookies collect only the minimum data required for authentication and consent management. No personal data is stored in Necessary cookies beyond session identifiers and consent state.
Functional cookies store your display preferences only (theme, locale, and last active role). No sensitive personal data is stored.
Analytics cookies generate an anonymous identifier (UUID). Analytics events tracked include page views, button clicks, form submissions, navigation events, error occurrences and the search terms you enter in the Platform. While you are signed in these events also carry your account identifier. Events are rate-limited to 60 per minute.
8. Changes to This Policy
We may update this Cookies Policy from time to time to reflect changes in our cookie usage or applicable regulations. When we do so, the “Effective Date” at the top of this policy will be updated.
Where an update changes what you were actually asked to agree to — a new cookie, a new purpose, a new recipient — we ask you again. Your stored choice carries the consent version it was given under, and when that is older than the current one the consent banner reappears on your next visit so you can make the choice afresh. Corrections that do not change what we set or why (a clearer wording, a typo) do not reset your choice, because re-asking for no reason trains people to click through without reading.
9. Contact
If you have any questions about our use of cookies, please contact us at: privacy@gofindpart.com
Analytics on this device
This public site uses cookieless page analytics (Plausible) and error reporting (Sentry). Neither stores anything on your device. You can turn both off for this browser here; your choice is kept in this browser's local storage until you clear it or switch it back on.
Checking this browser's setting…