Full statutory disclosure for CrowAgent Ltd. UK GDPR and PECR aligned transparency.
Cookies are small files that websites place on your device. This website does not place any. The CrowMark platform you sign in to does, and every one of them is named below.
1. What cookies are, in plain English
A cookie is a small text file a website saves to your browser. Some are essential (for example, to remember that you are signed in). Others are optional (for example, to count how many people visit a help page). We also use similar tools such as “local storage”, which works the same way but lives inside your browser instead of being sent back to the server. This policy treats both the same.
We follow the Privacy and Electronic Communications Regulations (PECR) for storage on your device, and the UK GDPR for any personal data those cookies carry. Under PECR Regulation 6, we cannot place non-essential cookies on your device without your prior, freely-given, specific, and informed consent. This policy provides the necessary information for you to make that choice. You can read the rules yourself at ico.org.uk/guide-to-pecr and ico.org.uk/guide-to-gdpr.
2. Every cookie we use
This website, crowagent.ai, sets nothing. No cookies, no local storage, no session storage, and no requests to anyone else. There is no consent banner on it because there is nothing to ask you about, and no analytics because none is installed. You can confirm all of that yourself in about ten seconds; the cookie preferences page shows you how.
The table below is the CrowMark platform, the signed-in application you reach at a separate address. Items marked Consent-gated are not set unless you agree in the platform’s own consent banner. Where a row names no expiry, the item lasts for the browser session and is gone when you close it.
On a narrow screen, this table scrolls sideways.
| Name | Set by | Category | Purpose | Lifetime |
|---|---|---|---|---|
sb-<project>-auth-token | Supabase Auth | Essential | Keeps you signed in to the platform after login, and renews itself silently so you are not asked again on every page. Strictly necessary. | Your signed-in session |
ca_remember_me | CrowAgent | Essential | Remembers this device so you are not asked to sign in again on every visit. Only set where your organisation's security policy allows it. | 30 days |
ca_mfa_trust | CrowAgent | Essential | Records that this device has already passed multi-factor authentication, so you are not challenged on every sign-in. | Until you sign out or revoke the device |
ca_step_up_at | CrowAgent | Essential | Records when you last re-confirmed your identity before a sensitive action, so you are not re-prompted seconds later. | Until you sign out |
ca_active_org | CrowAgent | Essential | Remembers which organisation you are working in when your account belongs to more than one. | Until you switch organisation |
platform_connector_oauth_nonce | CrowAgent | Essential | A one-time value that ties an integration authorisation back to the request that started it. Security, not tracking. | The length of that connection flow |
__cf_bm, cf_clearance | Cloudflare | Essential | Bot management: distinguishes humans from automated traffic, and records that a challenge has already been passed. Set only when Cloudflare actually challenges a request. | 30 minutes |
ca_cookie_consent_v2 | CrowAgent | Essential | Stores your consent decision. This is a local-storage item, not a cookie, so it stays in your browser and is never sent to a server. | Until you clear it |
ph_* | PostHog (EU) | Analytics | Product analytics: distinct ID, session ID, window ID. Consent-gated, and off until you turn it on. | 365 days |
ca_analytics_optout | CrowAgent | Analytics | Records that you have opted out of analytics, so the opt-out survives your next visit. | Until you clear it |
utm_source, utm_medium, utm_campaign, utm_content | CrowAgent | Analytics | Records which campaign brought you to the platform so a later sign-up can be attributed to it. | Session |
_calendly_session, _cfuvid | Calendly | Marketing | Booking-flow state for the demo scheduler embedded in the platform's support page, and Cloudflare bot mitigation on calendly.com. Loaded only when you open that scheduler. | 21 days, and session |
3. The three categories we use
We group cookies into three plain-English categories so you can choose what you are comfortable with. On this website all three are empty; the descriptions below are what each one means inside the platform.
- Strictly necessary: Always on. Keep you signed in, remember a trusted device, protect against bots, and remember your consent choice. The platform would not work without them. This website sets none of them, because it has no sign-in and no session.
- Analytics: Optional and off by default. Helps us understand which pages are used and where people get stuck. Hosted on PostHog EU cloud, inside the platform only. There is no analytics script of any kind on this website.
- Marketing and scheduler: Optional. Loads the Calendly demo scheduler inside the platform’s support page. On this website, “book a call” is an ordinary link to calendly.com, so nothing from Calendly loads or is stored until you choose to follow it.
4. Third-party providers
Some cookies are set by trusted providers we use to run the platform. The ones that actually set something are PostHog (product analytics hosted in the EU, consent-gated), Cloudflare (security and performance), and Calendly (scheduling, inside the platform’s support page). All are handled under Standard Contractual Clauses or EU residency.
Stripe handles our payments, and is named here because people look for it: it sets no cookie on our domains. Checkout is a redirect to a page Stripe hosts, so any cookie Stripe sets belongs to Stripe’s own site and is covered by Stripe’s policy, not this one.
5. Frequently Asked Questions
Do you sell my data or use cookies for advertising?
No. CrowAgent does not sell personal data and does not use cookies for advertising. Analytics are aggregated on PostHog EU and never shared with ad networks. We have zero interest in tracking you across the web.
How long do cookies last?
On this website, nothing is stored, so nothing has a lifetime. On the platform: your consent choice is kept until you clear it; sign-in items last for your session, except the remember-this-device cookie, which lasts 30 days; Cloudflare security cookies typically expire within 30 minutes; and PostHog identifiers last 365 days, and only if you have accepted analytics.
What happens if I reject all optional cookies?
The platform will work perfectly for your core tasks. You will still be able to sign in, use every tool, and manage your data. We simply will not collect analytics about your visit, and the demo scheduler will only load if you choose to open it.
6. How to change your choices
On this website there is nothing to change, because nothing is set. The cookie preferences page sets that out category by category and shows you how to confirm it for yourself.
Inside the platform, the consent banner appears the first time you use it and your choice can be changed at any time from the same control. You can also block or delete cookies in your browser settings, though on the platform that may sign you out and interrupt the secure session.