Skip to content
craftwebcare
PrivacyCookiesTerms
Contact us

Legal information

Cookie policy

Our public website does not use advertising or analytics cookies. The private client dashboard uses only the cookies needed to sign you in and keep the service secure.

Last updated: 19 July 2026

On this page
The short versionPublic websiteDashboard cookiesCookieless analyticsYour choicesChanges and contact

1. The short version

No cookie banner is needed on the CraftWebCare marketing site today. We do not set marketing, advertising, social-media or analytics cookies there. If that changes, we will update this policy and add a consent choice before any non-exempt technology runs.

A cookie is a small piece of information stored on your browser or device. Similar technologies can also store or access device information. UK privacy rules apply according to what the technology does, not only whether it is called a cookie.

2. The public CraftWebCare website

The public pages at craftwebcare.com currently do not set CraftWebCare cookies, use local storage, run advertising pixels or embed third-party tracking. Email links open your own email application; your email provider then handles that message under its own terms.

Normal network requests still reveal technical information such as an IP address and user-agent to the hosting infrastructure so it can deliver and protect the site. This is server-side processing and is explained in our privacy policy.

3. Strictly necessary dashboard cookies

The private dashboard at dash.craftwebcare.com uses the following first-party cookies. They are essential for the login and security service a client requests, so consent is not required. They are not used for advertising.

CookiePurposeTypical duration
laravel-sessionMaintains the signed-in session and links requests to the authenticated account. The cookie is protected with Secure, HttpOnly and SameSite controls in production.Up to 2 hours after the last activity, unless you sign out sooner. The exact expiry may be refreshed while the dashboard is in use.
XSRF-TOKENHelps prevent cross-site request forgery by confirming that state-changing requests came from the dashboard session.Up to 2 hours, normally refreshed with the session.

The session-cookie name may be changed for operational reasons without changing its purpose. Blocking either cookie will prevent sign-in or other secure dashboard actions from working.

4. Cookieless analytics on managed client websites

Some websites managed by CraftWebCare send limited first-party events to our dashboard: page views and interactions such as call, WhatsApp, email, map, download and form events. The integration is designed not to set cookies, read cookies, use local storage or create a persistent device identifier.

For visitor counting, the server creates a one-way daily value from the IP address and browser user-agent. Only the resulting value is saved with the analytics event, and it changes each day. Raw event records are normally deleted after 90 days. Form submissions are separate and may include attribution details; see our privacy policy and the client business’s own notice.

Because this tracking does not store information on, or access information stored on, your device, it is not a cookie or similar storage technology. It still involves limited personal-information processing, which is why we explain it clearly.

5. Your choices

You can delete or block cookies through your browser settings. If you block the dashboard’s essential cookies, you will not be able to remain signed in. There are currently no non-essential CraftWebCare cookies to accept or reject on the public site.

You may object to processing based on legitimate interests, including cookieless analytics, by emailing achraf.bouhadou@craftwebcare.co. If the activity relates to a client website, name that website so we can route the request to the correct controller.

6. Changes and contact

We will update this page if we add or change cookies, storage technologies or analytics. Material changes will be accompanied by an appropriate notice or consent control where the law requires one.

Questions about this policy can be sent to achraf.bouhadou@craftwebcare.co.

© 2026 craftwebcare
PrivacyCookiesTerms
achraf.bouhadou@craftwebcare.co