Skip to main content
Legal

Cookie policy

The complete list. Costrix sets two cookies, both of them needed to sign you in, and nothing that follows you anywhere.

Last updated 6 September 2026

1. The short version

Costrix sets two cookies, and both exist for one reason: to keep you signed in. There is no analytics, no advertising, no tag manager, no pixel and no third-party cookie of any kind — not on this website and not inside the app.

That is why there is no cookie banner to click through. Cookies that are strictly necessary to provide the service you asked for do not need consent, and every cookie on this list is one of those. If we ever set a cookie that is not, we will ask you first.

2. What a cookie is

A cookie is a small piece of text a website asks your browser to keep and send back on your next visit. Ours hold nothing but a random string of characters — no name, no email address and nothing that can be read by looking at it.

Some sites also use two other kinds of browser storage, local storage and session storage. Costrix uses a little of both inside the app, and section 5 lists exactly what.

3. The cookies we set

Both are first-party cookies — set by costrix.app, sent only to costrix.app. Both are HttpOnly, so no JavaScript can read them, and both are sent over HTTPS only. Both are SameSite=Strict, which means your browser will not attach them to a request that started on somebody else’s website.

  • costrix_session — strictly necessary. The random token that says which signed-in session this browser is. It is the whole of how Costrix knows who you are; it holds no personal data itself, only a reference to a session stored on our server. Lasts seven days, and renews for another seven whenever you use Costrix after the halfway point, so an active user is not signed out mid-week. Deleted when you sign out.
  • costrix_session_exp — strictly necessary. Holds the date the session above runs out, so we can work out whether to renew it without asking the database on every page you open. It is a copy of a date, nothing more, and it is never trusted on its own — the server checks the real session before renewing anything. Same seven-day life, deleted at the same time.

Signing out deletes both immediately. Clearing cookies in your browser does the same thing, and the only consequence is that you have to sign in again.

4. Two more cookies you will never receive

For completeness, because a list that leaves things out is not worth reading: our own internal administration area sets two further cookies of exactly the same kind — costrix_system_admin, which lasts twelve hours, and costrix_impersonation, which lasts two hours and is set only when a member of Costrix support is looking at the app as one of your users to solve a problem you have raised.

Neither is ever set on a customer’s browser. They are listed here because they exist in the same codebase, and because a support session being visible is better than a support session being quiet — every one of them is written to your company’s audit log with the name of the person who started it.

5. Local storage and session storage

These two are used inside the app only, once you are signed in. Neither is ever set on this public website, neither is sent to us or to anybody else, and both stay in your own browser.

  • costrix:lastPaymentMethod (local storage) — remembers whether you last entered an expense as cash or on a company card, so the next one starts on the same setting. Only used by people who enter both kinds. It holds one word — “CASH” or “CREDIT_CARD” — and it stays until you clear your browser storage.
  • costrix-banner-dismissed:… (session storage) — remembers that you closed a notice we showed at the top of the app, so it does not come straight back on the next page. It disappears when you close the browser, and a new notice shows again regardless.

We treat both as part of the app your company has asked us to provide rather than as anything that needs consent — they hold no personal data and cannot be used to recognise you anywhere else. [TODO: confirm with a data protection adviser that the remembered cash-or-card preference counts as strictly necessary; if it does not, it needs a consent control inside the app before launch]

6. Third parties

There are none on our pages. To be specific about the things that usually put third-party cookies on a website:

  • No analytics or tag manager. We do not measure your visit with Google Analytics or anything like it.
  • No advertising or social pixels, and no share buttons that phone home.
  • No embedded video player. The demo film on our front page is a file served from this site, not a YouTube or Vimeo embed.
  • No web fonts fetched from Google. Our typefaces are downloaded when the site is built and served from our own domain, so your browser never makes a request to a font provider.
  • No chat widget, no support pop-up, no cookie-consent vendor.

Paying is the one exception, and it happens somewhere else. When you enter card details you are on Stripe’s own checkout page, and when you manage your billing you are in Stripe’s own billing portal. Those are Stripe’s pages on Stripe’s domain: Stripe sets its own cookies there, for its own fraud prevention and session handling, under its own cookie notice at stripe.com. We cannot set or read anything on them.

7. Why there is no cookie banner

The rules that apply here are the Privacy and Electronic Communications Regulations 2003. Regulation 6 says that storing information on somebody’s device needs their consent — with an exception, in regulation 6(4), for storage that is strictly necessary to provide a service the person has actually asked for.

Signing in is exactly that. Both our cookies exist only to keep you signed in and to do it without hammering the database, so both sit inside that exception, and asking you to consent to them would be a box you cannot meaningfully say no to.

A banner is not free either: it is one more thing between you and the page, and the honest version of it here would say “we use two cookies to sign you in, is that all right? (you cannot use Costrix if not)”. So we have written this page instead.

The moment that stops being true, we will ask. If Costrix ever sets a cookie or uses browser storage for anything that is not strictly necessary — analytics, a third-party tool, anything that measures you — a proper consent banner goes in first, with a real refuse option and a way to change your mind afterwards, and this page changes with it.

8. Controlling cookies yourself

Every browser lets you see the cookies a site has set, delete them, and block them. It is usually under privacy or site settings. Blocking ours does not put you at any risk — it simply means Costrix cannot keep you signed in, so you will not get past the login page.

9. Getting in touch

Questions about anything on this page go to hello@costrix.app. What we do with the data itself, rather than how it is stored on your device, is in the privacy policy. If you are unhappy with our answer you can complain to the Information Commissioner’s Office at ico.org.uk.