Cookie policy
What we store on your device, and why. Last updated 20 August 2026.
The short version
Nilstock sets four cookies. Every one of them is needed to run the product: signing you in, keeping you signed in on a computer you have told us to trust, keeping a store terminal paired to its site, and remembering your answer to this page.
There is no advertising cookie, no tracking pixel, no third-party cookie, and no analytics. Nothing we set is shared with anyone, and nothing follows you to another website.
Why we are not asking for consent
UK law (the Privacy and Electronic Communications Regulations, regulation 6) requires consent before storing anything on your device — except where it is strictly necessary to provide a service you asked for. A cookie that keeps you signed in to a system you are deliberately signing in to is the textbook example of that exemption.
So we tell you what we set, and we do not ask permission for things we do not need permission for. A banner demanding consent for a login cookie is friction that teaches people to click “accept” without reading, which makes the consent that does matter worth less. The Information Commissioner’s Office says much the same.
If we ever add analytics — and we may, because knowing which of our guides are useful would help us write better ones — you will get a real choice first, off by default, with rejecting exactly as easy as accepting. Until then there is nothing to opt into, and you can see the current position any time from .
Every cookie we set
| Name | Purpose | Lasts | Type |
|---|---|---|---|
| sc_session | Keeps you signed in to the back office. Holds a random token — never your email, name or password — which is matched against a hash stored on our side. | 12 hours | Strictly necessaryNilstock (first party) |
| sc_device | Set only if you tick "Trust this computer" when signing in, so a shared office machine does not drop you out mid-shift. Revoked when you sign out, or from Settings. | 1 year, or until revoked | Strictly necessaryNilstock (first party) |
| sc_kiosk | Identifies a paired store terminal to its site. It carries no person — whoever is standing at the terminal identifies themselves by badge, and that identity is discarded as soon as the basket is posted. | 10 years, or until the terminal is revoked | Strictly necessaryNilstock (first party) |
| nilstock_consent | Remembers your cookie choices so you are not asked again. Strictly necessary in its own right: the alternative to storing your preference is asking on every page. | 6 months | Strictly necessaryNilstock (first party) |
What is not a cookie
Our servers keep ordinary web logs — the address requested, the time, the response code, and an IP address — for a short period, because without them we cannot tell a fault from an attack. That is not a cookie and it is not tracking; it is covered by our privacy policy.
The store terminal keeps its basket in the browser’s memory while somebody is part way through a transaction. It is discarded the moment the basket is posted or the terminal times out, and it never leaves the device.
Turning them off yourself
Every browser can block or delete cookies, and you are welcome to. Be aware that blocking ours means you cannot sign in — not as a punishment, but because the sign-in is the cookie. A store terminal will also lose its pairing and need a new code from an administrator.
Changes
If we add a cookie, this table changes in the same commit — it is generated from the same file the software reads, so it cannot quietly fall out of date. If we ever add one that needs consent, everyone is asked again rather than us assuming an old answer covers a new purpose.
Questions to [email protected].