Cookie Policy
01What are cookies?
Cookies are small text files placed on your device when you visit a website. They help websites remember information about your visit — like your login state, your preferences, and how you use the site — so that the experience works correctly on your next visit.
Some cookies are set by CarryMate directly. Others are set by third-party services we use (such as our analytics or payment providers). This policy covers both.
02The cookies we use
| Cookie name | Type | Purpose | Duration |
|---|---|---|---|
| sb-access-token | Essential | Supabase authentication session token. Required to keep you logged in. | Session |
| sb-refresh-token | Essential | Supabase session refresh token. Keeps your session alive without requiring re-login. | 7 days |
| carrymate-pref | Essential | Stores your cookie consent preference and UI preferences (currency, language). | 1 year |
| _vercel_jwt | Essential | Set by Vercel for deployment authentication on staging environments. | Session |
| _ga, _ga_* | Analytics | Google Analytics 4. Collects anonymised data on how visitors use the site — pages visited, time on site, device type. Used to improve the product. | 13 months |
| ph_* | Analytics | PostHog product analytics. Tracks feature usage and user flows within the authenticated portal to help us identify what is working and what is not. | 1 year |
| stripe-mid, __stripe_sid | Essential | Set by Stripe to prevent fraud during payment processing. Required for checkout to function. | Session / 1 year |
03Essential cookies
Essential cookies are required for CarryMate to function. They include your authentication session, your cookie preference, and the fraud prevention cookies set by our payment processor (Stripe). You cannot opt out of essential cookies while continuing to use CarryMate — without them, login, checkout, and session management will not work.
04Analytics cookies
We use Google Analytics 4 and PostHog to understand how people use CarryMate. The data we collect is anonymised — we cannot identify you personally from analytics data. We use it to understand which features people use most, where users encounter problems, and how to prioritise improvements.
You can opt out of analytics cookies at any time using the cookie preference centre (accessible via the "Cookie settings" link in the footer). Opting out will not affect your ability to use CarryMate.
05Managing your cookie preferences
You can manage your cookie preferences in several ways:
- Cookie preference centre: Click "Cookie settings" in the footer of any page on carrymate.io to update your preferences at any time.
- Browser settings: Most browsers allow you to block or delete cookies through their settings. Note that blocking essential cookies will prevent CarryMate from functioning correctly.
- Google Analytics opt-out: You can install the Google Analytics opt-out browser add-on to prevent your data from being used by Google Analytics across all websites you visit.
06Mobile app
The CarryMate mobile app (iOS and Android) does not use browser cookies. Instead, we use AsyncStorage (a local device storage mechanism) to persist your session token. We also use your device's unique push notification token (if you have granted permission) to send delivery alerts. You can revoke push notification permission at any time in your device settings.
07Changes to this policy
We may update this Cookie Policy from time to time. Material changes will be communicated via a notice on the website and, where appropriate, by email. The current version is always available at carrymate.io/legal/cookies.
Questions about cookies
For any questions about how we use cookies or your privacy rights:
Data Protection Officer: dpo@carrymate.io · CarryMate Ltd · London, United Kingdom