Legal
Cookie policy
We use as few cookies as we can. Two of them are our own. This page lists every cookie and every item of browser storage the software creates, generated from the code rather than written from memory, so it does not describe a set of cookies we do not have.
Last updated 21 August 2026
Cookies are not the whole story, so this page is not only about cookies
The law here covers storing information on your device, not the word "cookie". So this page lists local storage, session storage and the offline database too, and says which each one is. The distinction matters: our cookie consent record, for instance, is local storage and not a cookie, and the previous version of this page called it one.
Two cookies are set by us, both in the first table and both strictly necessary. One keeps you signed in. The other is set when somebody signs in at a site gate, and it is what lets them sign back out again from any browser rather than only from the one they arrived on. Everything else in the strictly necessary group is storage on your own device, or a cookie set by a third party we name.
Everything we store, and where
Each table is one category. Strictly necessary items cannot be switched off; the rest are yours to decide about.
Strictly necessary: Required for the service to work at all: signing in, keeping you signed in, remembering your cookie choice, holding work offline so a site visit does not lose data, and letting somebody who signed in at a site gate sign back out again. These cannot be switched off and, under the Privacy and Electronic Communications Regulations, do not require consent.
| Name | Type | Where | Set by | Lasts | What it is for |
|---|---|---|---|---|---|
| refresh_token | Cookie (httpOnly; Secure (in production); SameSite=Lax; Path=/api/v1/auth/refresh) | Estimark application | Us | 30 days | Keeps you signed in. It is httpOnly, so scripts on the page cannot read it, it is marked Secure in production, and its path is scoped to the sign-in refresh endpoint alone, so it is not sent on ordinary requests. |
| estimark_gate_visit | Cookie (httpOnly; Secure (in production); SameSite=Lax; Path=/api/v1/qr/gate/<this site's code>) | Site gate sign-in page | Us | 12 hours, or until you sign out | Set when you sign in at a site gate, and it is what lets you sign back out again. Without it, signing out would only work in the browser you signed in with, so anybody who scanned the sign on a borrowed phone, in a private window, or on a device that had cleared its data would be left on the site's fire register after they had gone home. It holds a reference to that one visit and nothing else: no name, no account, and no way to see who else is on the site. Signing out expires it, and it expires on its own after twelve hours in any case. |
| __stripe_mid, __stripe_sid | Cookie | Estimark application | Stripe | __stripe_mid: 1 year. __stripe_sid: 30 minutes. | Fraud prevention, set by Stripe's own script. Two things about them stated plainly rather than implied. They are set when the application loads, which is before you have made any cookie choice, and they are present on pages where you are not paying for anything. We rely on them being strictly necessary: they are how Stripe tells a genuine payment from a fraudulent one, and gating them behind a banner would mean refusing the banner broke paying. They carry no analytics or advertising purpose and we do not read them. |
| est_cookie_consent | localStorage | Marketing site and Estimark application | Us | Until you clear your site data | Your cookie choice, so the banner does not ask again. Stored in localStorage, not in a cookie. |
| est_session_id | localStorage | Estimark application | Us | Until you clear your site data | A random identifier generated on your device and sent with your cookie choice, so that the record of that choice can be found again. It is not linked to your account and is not used for analytics. |
| estimark-auth | localStorage | Estimark application | Us | Until you sign out or clear your site data | Your name and role, so the interface can render before the first request returns. The access token is not stored here at all; it is held in memory only. |
| estimark-admin | localStorage | Operator administration portal | Us | Until sign-out or site data is cleared | The operator's profile. The admin token is held in memory only. |
| estimark-partner-auth | localStorage | Partner portal | Us | Until sign-out or site data is cleared | A partner's profile and access token. Unlike the main application, the token is stored on the device here. |
| estijob-auth | localStorage | EstiJob | Us | Until sign-out or site data is cleared | An EstiJob user's profile and access token. |
| estidesign_token, estiplan_token, estisearch_token (and the matching _user keys) | localStorage | EstiDesign, EstiPlan and EstiSearch | Us | Until sign-out or site data is cleared | Sign-in state for the sibling EstiSuite products, each on its own domain. |
| estimark_offline | indexedDB | Estimark application | Us | Until synchronised, then cleared | Queues work you do with no signal and caches what you need to see on site, so a site visit in a basement does not lose a morning's records. It can therefore contain personal data about the job you are on, on your device. |
| estimark.sitehub.deviceToken, estimark.sitehub.siteFile, estimark.sitehub.siteFileAt | localStorage | Site Hub terminal | Us | Until the terminal is unpaired | Identifies a site terminal to the service and caches the site's own file so the terminal keeps working when the connection drops. |
| dd_pending_mandate_row | sessionStorage | Estimark application | Us | Until the browser tab is closed | Remembers which client you were setting up a Direct Debit for, so returning from the provider lands you back in the right place. |
| am_referral_code, am_tracking_token | sessionStorage | Sign-up | Us | Until the browser tab is closed | If you arrive from one of our sales partners' links, this records which partner, so they are credited if you sign up. It lasts as long as the browser tab and no longer There is no long-lived referral cookie. |
Preferences: Remembers how you have set the interface up: dark mode, which panels are collapsed, which banners you have dismissed. Stored on your own device and never sent to us as a profile. Clearing them costs you nothing but your layout.
| Name | Type | Where | Set by | Lasts | What it is for |
|---|---|---|---|---|---|
| qr_worker_name | localStorage | Site clock-in page | Us | Until cleared | Remembers the name last typed on a shared site clock-in device so an operative does not retype it every morning. |
| estimark-dark, estimark-admin-dark | localStorage | Estimark application and administration portal | Us | Until cleared | Whether you have chosen dark mode. |
| sidebar-collapsed, sidebar-<section> | localStorage | Estimark application | Us | Until cleared | Whether the sidebar and each of its sections are collapsed. |
| estimark-dashboard-config, estijob-dashboard-widgets | localStorage | Estimark application and EstiJob | Us | Until cleared | Which dashboard widgets you have chosen and in what order. |
| estimark-onboarding-dismissed, estimark-tour-complete, dismissed-announcements, dismiss_annual_upsell | localStorage | Estimark application | Us | Until cleared | Which prompts, tours, announcements and offers you have dismissed, so they stay dismissed. |
Analytics: Helps us see which pages are used and where people get stuck. Not set until you accept.
| Name | Type | Where | Set by | Lasts | What it is for |
|---|---|---|---|---|---|
| _ga, _ga_<stream id> | Cookie | Marketing site and Estimark application | Google (Google Analytics 4) | 2 years | Distinguishes visitors and sessions so we can count usage. |
Advertising: Used on the public EstiJob site only. Not used anywhere in the Estimark application or on the Estimark marketing site.
| Name | Type | Where | Set by | Lasts | What it is for |
|---|---|---|---|---|---|
| __gads, __gpi, IDE, DSID | Cookie | EstiJob only | Google (AdSense and DoubleClick) | Up to 2 years | Contextual advertising on the public EstiJob site. |
How consent works, and two things about it that are true today
Nothing non-essential loads until you have said yes to it. The gate is the script tag itself: with no decision recorded, the analytics library is never fetched, so no request reaches Google at all. Every toggle starts switched off, and accepting and refusing are offered with equal weight. You can change your mind at any time from the Cookie choices control in the footer, or from Settings inside the application; withdrawing removes the tag from the page and expires the cookies it set while it was allowed. Your choice is kept on your own device and is also recorded on our servers with the date, your IP address and your browser's user agent, so there is a record that a choice was made, and against your account where you are signed in. One thing to be plain about rather than leave implied: Stripe's fraud-prevention cookies are set when the application loads, before you have made any cookie choice, because they are how a fraudulent payment is spotted and gating them would break paying. They are the only non-essential-looking cookies that behave that way, and they carry no analytics or advertising purpose. The site gate pages carry no cookie banner at all, and that is deliberate rather than an omission: the only cookie set there is the one that lets a visitor sign out again, it is set at the moment they sign in and not before, and a consent dialogue on a phone at a barrier would stand between somebody and a safety briefing to ask about a cookie the law does not require us to ask about.
What we do not do
We do not use advertising cookies on this site or in the Estimark application, we do not sell data to advertising networks, and we do not track you across other websites. The one place in the Estimark group where advertising cookies are used is the public EstiJob site, which is named as such in the table above.
Controlling cookies and storage
You can clear or block cookies and site data in your browser settings, and doing so clears our consent record along with everything else, so you will be asked again. Blocking strictly necessary items will stop you being able to sign in, and clearing site data on a mobile device with unsynced offline work will lose that work.
Analytics and advertising storage is denied until you accept it, and declining changes nothing about how the service works for you.
Build on a solid foundation.
Run the whole business without an implementation project and without legacy baggage. Every plan starts with 14 days free.
Estimating · Jobs · Invoicing · CIS · H&S · Reactive maintenance