Cookies

Last updated: 18 April 2026

Cookies are small pieces of text stored by your browser. Some are essential for a website to work. Others track you — we don't use any of those. This page tells you exactly what BuildRound does and does not set.

The short version

  • - We only set essential cookies (for keeping you signed in).
  • - No advertising cookies. No tracking cookies. No pixels.
  • - Our product analytics (PostHog Cloud EU) uses your browser's local storage, not cookies, and is hosted in the EU.
  • - You won't see a cookie consent banner because under UK PECR we don't need one for essential cookies, and we don't use any non-essential ones.

1. What we set

CookieSet byPurposeLifetime
authjs.session-tokenBuildRound (Auth.js)Keeps you signed in30 days
authjs.csrf-tokenBuildRound (Auth.js)Anti-CSRF protection for sign-in formsSession
authjs.callback-urlBuildRound (Auth.js)Remembers where to send you after sign-inSession
authjs.pkce.code_verifierBuildRound (Auth.js)PKCE proof during sign-in handshake15 minutes
authjs.stateBuildRound (Auth.js)CSRF state for the OAuth handshake with AWS Cognito15 minutes
__stripe_midStripe (only on payment pages)Fraud prevention for card payments1 year

All of these are "strictly necessary" cookies under UK PECR — they are required for the service to function (authentication, payment fraud protection). Under PECR Regulation 6(4) these do not require prior consent.

2. What we do not set

  • - Advertising cookies (Google Ads, Facebook Pixel, etc.) — never.
  • - Analytics cookies — our product analytics tool (PostHog Cloud EU) uses local storage, not cookies, and is configured with person_profiles: identified_only so we don't spawn a server-side profile for anonymous visitors.
  • - Cross-site tracking cookies — we don't follow you around the web.
  • - Fingerprinting technologies — we don't try to identify your device beyond session auth.

3. Local storage

We use your browser's local storage in two ways. Both stay on your device unless you sign up.

  • - Wizard progress. During Steps 1-5 we save what you entered (business name, services, coverage area, pricing) under the key buildround_wizard. When you sign up at Step 6 the data transfers to our servers and is removed locally.
  • - Analytics state. PostHog stores an anonymous device id and session id under keys starting with ph_. We also store the marketing source you arrived from (UTM parameters, captured at first visit) under buildround_utm for 30 days, so we know which channels drive sign-ups. None of this is shared with third parties beyond PostHog Cloud EU (Frankfurt).

You can clear all of this from your browser's site-data settings at any time. We honour the DNT(Do Not Track) browser header — when it's on we skip loading PostHog entirely.

4. How to control cookies

All modern browsers let you view, clear, or block cookies in Settings. If you block essential cookies, BuildRound won't be able to keep you signed in — you'll be forced to sign in again every time.

5. Changes

If we ever add a non-essential cookie we would update this page, show a consent banner, and only set the cookie once you opt in. We have no current plans to do so.

6. More

See our Privacy Policy for the wider picture on how we handle personal data.

Company information

Legal name
BuildRound Ltd
Company number
TBA
Registered office
TBA — Companies House registered address
Jurisdiction
England and Wales
Support
hello@buildround.com
Privacy
privacy@buildround.com