Legal

Cookie policy

We use as few cookies as we can. Two of them are our own. This page lists every cookie and every item of browser storage the software creates, generated from the code rather than written from memory, so it does not describe a set of cookies we do not have.

Last updated 21 August 2026

Cookies are not the whole story, so this page is not only about cookies

The law here covers storing information on your device, not the word "cookie". So this page lists local storage, session storage and the offline database too, and says which each one is. The distinction matters: our cookie consent record, for instance, is local storage and not a cookie, and the previous version of this page called it one.

Two cookies are set by us, both in the first table and both strictly necessary. One keeps you signed in. The other is set when somebody signs in at a site gate, and it is what lets them sign back out again from any browser rather than only from the one they arrived on. Everything else in the strictly necessary group is storage on your own device, or a cookie set by a third party we name.

Everything we store, and where

Each table is one category. Strictly necessary items cannot be switched off; the rest are yours to decide about.

Strictly necessary: Required for the service to work at all: signing in, keeping you signed in, remembering your cookie choice, holding work offline so a site visit does not lose data, and letting somebody who signed in at a site gate sign back out again. These cannot be switched off and, under the Privacy and Electronic Communications Regulations, do not require consent.

NameTypeWhereSet byLastsWhat it is for
refresh_tokenCookie (httpOnly; Secure (in production); SameSite=Lax; Path=/api/v1/auth/refresh)Estimark applicationUs30 daysKeeps you signed in. It is httpOnly, so scripts on the page cannot read it, it is marked Secure in production, and its path is scoped to the sign-in refresh endpoint alone, so it is not sent on ordinary requests.
estimark_gate_visitCookie (httpOnly; Secure (in production); SameSite=Lax; Path=/api/v1/qr/gate/<this site's code>)Site gate sign-in pageUs12 hours, or until you sign outSet when you sign in at a site gate, and it is what lets you sign back out again. Without it, signing out would only work in the browser you signed in with, so anybody who scanned the sign on a borrowed phone, in a private window, or on a device that had cleared its data would be left on the site's fire register after they had gone home. It holds a reference to that one visit and nothing else: no name, no account, and no way to see who else is on the site. Signing out expires it, and it expires on its own after twelve hours in any case.
__stripe_mid, __stripe_sidCookieEstimark applicationStripe__stripe_mid: 1 year. __stripe_sid: 30 minutes.Fraud prevention, set by Stripe's own script. Two things about them stated plainly rather than implied. They are set when the application loads, which is before you have made any cookie choice, and they are present on pages where you are not paying for anything. We rely on them being strictly necessary: they are how Stripe tells a genuine payment from a fraudulent one, and gating them behind a banner would mean refusing the banner broke paying. They carry no analytics or advertising purpose and we do not read them.
est_cookie_consentlocalStorageMarketing site and Estimark applicationUsUntil you clear your site dataYour cookie choice, so the banner does not ask again. Stored in localStorage, not in a cookie.
est_session_idlocalStorageEstimark applicationUsUntil you clear your site dataA random identifier generated on your device and sent with your cookie choice, so that the record of that choice can be found again. It is not linked to your account and is not used for analytics.
estimark-authlocalStorageEstimark applicationUsUntil you sign out or clear your site dataYour name and role, so the interface can render before the first request returns. The access token is not stored here at all; it is held in memory only.
estimark-adminlocalStorageOperator administration portalUsUntil sign-out or site data is clearedThe operator's profile. The admin token is held in memory only.
estimark-partner-authlocalStoragePartner portalUsUntil sign-out or site data is clearedA partner's profile and access token. Unlike the main application, the token is stored on the device here.
estijob-authlocalStorageEstiJobUsUntil sign-out or site data is clearedAn EstiJob user's profile and access token.
estidesign_token, estiplan_token, estisearch_token (and the matching _user keys)localStorageEstiDesign, EstiPlan and EstiSearchUsUntil sign-out or site data is clearedSign-in state for the sibling EstiSuite products, each on its own domain.
estimark_offlineindexedDBEstimark applicationUsUntil synchronised, then clearedQueues work you do with no signal and caches what you need to see on site, so a site visit in a basement does not lose a morning's records. It can therefore contain personal data about the job you are on, on your device.
estimark.sitehub.deviceToken, estimark.sitehub.siteFile, estimark.sitehub.siteFileAtlocalStorageSite Hub terminalUsUntil the terminal is unpairedIdentifies a site terminal to the service and caches the site's own file so the terminal keeps working when the connection drops.
dd_pending_mandate_rowsessionStorageEstimark applicationUsUntil the browser tab is closedRemembers which client you were setting up a Direct Debit for, so returning from the provider lands you back in the right place.
am_referral_code, am_tracking_tokensessionStorageSign-upUsUntil the browser tab is closedIf you arrive from one of our sales partners' links, this records which partner, so they are credited if you sign up. It lasts as long as the browser tab and no longer There is no long-lived referral cookie.

Preferences: Remembers how you have set the interface up: dark mode, which panels are collapsed, which banners you have dismissed. Stored on your own device and never sent to us as a profile. Clearing them costs you nothing but your layout.

NameTypeWhereSet byLastsWhat it is for
qr_worker_namelocalStorageSite clock-in pageUsUntil clearedRemembers the name last typed on a shared site clock-in device so an operative does not retype it every morning.
estimark-dark, estimark-admin-darklocalStorageEstimark application and administration portalUsUntil clearedWhether you have chosen dark mode.
sidebar-collapsed, sidebar-<section>localStorageEstimark applicationUsUntil clearedWhether the sidebar and each of its sections are collapsed.
estimark-dashboard-config, estijob-dashboard-widgetslocalStorageEstimark application and EstiJobUsUntil clearedWhich dashboard widgets you have chosen and in what order.
estimark-onboarding-dismissed, estimark-tour-complete, dismissed-announcements, dismiss_annual_upselllocalStorageEstimark applicationUsUntil clearedWhich prompts, tours, announcements and offers you have dismissed, so they stay dismissed.

Analytics: Helps us see which pages are used and where people get stuck. Not set until you accept.

NameTypeWhereSet byLastsWhat it is for
_ga, _ga_<stream id>CookieMarketing site and Estimark applicationGoogle (Google Analytics 4)2 yearsDistinguishes visitors and sessions so we can count usage.

Advertising: Used on the public EstiJob site only. Not used anywhere in the Estimark application or on the Estimark marketing site.

NameTypeWhereSet byLastsWhat it is for
__gads, __gpi, IDE, DSIDCookieEstiJob onlyGoogle (AdSense and DoubleClick)Up to 2 yearsContextual advertising on the public EstiJob site.

How consent works, and two things about it that are true today

Nothing non-essential loads until you have said yes to it. The gate is the script tag itself: with no decision recorded, the analytics library is never fetched, so no request reaches Google at all. Every toggle starts switched off, and accepting and refusing are offered with equal weight. You can change your mind at any time from the Cookie choices control in the footer, or from Settings inside the application; withdrawing removes the tag from the page and expires the cookies it set while it was allowed. Your choice is kept on your own device and is also recorded on our servers with the date, your IP address and your browser's user agent, so there is a record that a choice was made, and against your account where you are signed in. One thing to be plain about rather than leave implied: Stripe's fraud-prevention cookies are set when the application loads, before you have made any cookie choice, because they are how a fraudulent payment is spotted and gating them would break paying. They are the only non-essential-looking cookies that behave that way, and they carry no analytics or advertising purpose. The site gate pages carry no cookie banner at all, and that is deliberate rather than an omission: the only cookie set there is the one that lets a visitor sign out again, it is set at the moment they sign in and not before, and a consent dialogue on a phone at a barrier would stand between somebody and a safety briefing to ask about a cookie the law does not require us to ask about.

What we do not do

We do not use advertising cookies on this site or in the Estimark application, we do not sell data to advertising networks, and we do not track you across other websites. The one place in the Estimark group where advertising cookies are used is the public EstiJob site, which is named as such in the table above.

Controlling cookies and storage

You can clear or block cookies and site data in your browser settings, and doing so clears our consent record along with everything else, so you will be asked again. Blocking strictly necessary items will stop you being able to sign in, and clearing site data on a mobile device with unsynced offline work will lose that work.

Analytics and advertising storage is denied until you accept it, and declining changes nothing about how the service works for you.

Build on a solid foundation.

Run the whole business without an implementation project and without legacy baggage. Every plan starts with 14 days free.

Estimating · Jobs · Invoicing · CIS · H&S · Reactive maintenance