Cookie Policy
Effective 27 July 2026 · Version 2026-06
This policy explains how Chartping uses cookies and similar technologies — browser local storage, and tokens held by our apps — on the marketing website (chartping.com), the account and sign-in system, the web portal, and the Chartping mobile apps and desktop agent, which use locally stored tokens rather than browser cookies.
Where these involve personal data — for example recognising a signed-in account, or alerting you to a sign-in from an unrecognised device — that processing is described in our Privacy Notice, which also explains the legal bases we rely on, how long we keep data, your rights, and how to complain to the Information Commissioner's Office.
The short version
- Cookies needed to sign you in securely, protect your account, and remember choices you make in the app are set without asking, because the service cannot work without them.
- On the marketing website we also use Google Analytics — but only if you agree. No analytics cookie is set until you accept in the banner. If you decline, none is set, and we do not ask again.
- We use no advertising cookies, no social-media pixels and no cross-site tracking, anywhere — and no analytics of any kind inside the app (the portal, the mobile apps and the desktop agent).
Your choice
Analytics is off until you turn it on, and you can change your mind at any time — it is as easy to withdraw as to give:
Checking this browser's setting…
Turning analytics off also deletes the analytics cookies already in this browser.
Turning analytics off does two things: it stops any further measurement, and it deletes the analytics cookies already in this browser — withdrawing takes the same one click that giving did. Your choice is stored in this browser only. Clearing your browser storage clears it, and we will ask again.
Site measurement, which is a different thing
Alongside the cookie-based analytics above, this marketing website uses Cloudflare Web Analytics. It is worth explaining separately, because it works differently and we treat it differently.
- It writes nothing to your device — no cookie, no stored identifier. Nothing links one visit to another, or to you.
- It records the page you opened, the page that referred you, how quickly the page loaded, the device and browser characteristics your browser reports, and a country derived from your network address at our network edge.
- Because nothing is stored on your device, we do not ask for consent — we rely instead on the exception for statistical purposes, which requires us to give you a simple, free way to object. That is the switch below, and it is the only condition on which we run it.
- It runs on this marketing website only — not in the portal, the mobile apps or the desktop agent. Both of the measurement services on this page are confined to the marketing website; nothing measures what you do inside the product.
Checking this browser's setting…
This takes effect immediately and costs nothing. Nothing about it is stored on your device except the fact that you turned it off.
What we set, and why
On the account and sign-in system:
- Authentication session cookie — keeps you signed in while you use the service. A session cookie: you sign in again after closing the browser. Strictly necessary.
- Anti-forgery token — protects forms against cross-site request forgery. Strictly necessary.
cp_diddevice-recognition cookie — recognises a browser you have signed in from before, as part of our account-security checks; a sign-in from an unrecognised device may trigger a security notification. Lasts up to 730 days, refreshed on each sign-in. Strictly necessary (security).- Sign-in flow cookies — short-lived cookies that complete the sign-in handshake securely, including sign-in with Google or Apple and the two-factor step. Strictly necessary.
On the web portal:
- Encrypted session cookie — your portal session, held as an encrypted token container: page scripts cannot read it and the browser never holds a usable API token. Lasts up to 30 days. Strictly necessary.
- Sign-in correlation cookies — short-lived, to complete sign-in securely. Strictly necessary.
cp.onboarded— remembers that you completed or skipped first-run setup, so we do not show it again. Lasts 365 days. Preference.- Local storage — your theme choice, first-run flags and list-view preferences. Set only as a direct result of your own action in the app; never used for tracking. Preference.
- You can read this policy from inside the portal at any time: Settings → Legal, which also lists the documents you accepted and the version and date we hold for each.
On the marketing website: an anti-bot check protects the waitlist form from abuse; the provider may set a challenge cookie for that purpose. Strictly necessary (abuse prevention).
- Google Analytics (only with your consent) — cookies named
_gaand_ga_<id>, which measure how the site is used: pages viewed, roughly where visitors come from, and whether a page works on their device. Set only after you accept, and last up to 2 years. Your IP address is anonymised, we do not use Google Signals or advertising features, and we do not combine this with anything you do inside the app. Google acts as our processor and Google LLC is in the United States — see the Privacy Notice for the transfer safeguards. Analytics. Not strictly necessary, which is why it is consent-gated. - Your cookie choice itself is remembered in this browser's local storage, so we do not ask again on every page. Strictly necessary (it is the record of your decision).
In the mobile apps and desktop agent: locally stored tokens and preferences rather than cookies — these keep the app or agent signed in and remember app settings; the agent additionally holds a device key protected by your operating system.
The network edge for our account, API and portal hostnames is provided by Cloudflare, which may set its own cookies for security and bot mitigation on those hostnames; Cloudflare describes these in its own documentation.
What we do not use
- No advertising networks, remarketing tags or social-media pixels.
- No session-recording or heat-mapping tools.
- No third-party advertising cookies of any kind.
- No analytics at all inside the product — the portal, the mobile apps and the desktop agent carry no measurement service.
- No Google advertising features: Google Signals, remarketing and advertising-personalisation are switched off, and analytics data is not used to build advertising audiences.
Managing cookies
You can block or delete cookies in your browser settings. The cookies used for sign-in and security are essential: blocking them will prevent you from signing in or staying signed in. Deleting the preference items — cp.onboarded or your theme setting — is harmless: the app will simply ask again or revert to defaults.
Changes
If we start using any cookie or similar technology that requires consent, we will update this policy, update the Privacy Notice, and ask for your consent before setting it. The version and effective date above record the current text.
Contact
TrendSoft Ltd, Aa House 54, 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom. Company No. 16144241. Privacy contact: [email protected] (general: [email protected]).