Cookies
Last updated: 18 April 2026
Cookies are small pieces of text stored by your browser. Some are essential for a website to work. Others track you — we don't use any of those. This page tells you exactly what BuildRound does and does not set.
The short version
- - We only set essential cookies (for keeping you signed in).
- - No advertising cookies. No tracking cookies. No pixels.
- - Our product analytics (PostHog Cloud EU) uses your browser's local storage, not cookies, and is hosted in the EU.
- - You won't see a cookie consent banner because under UK PECR we don't need one for essential cookies, and we don't use any non-essential ones.
1. What we set
| Cookie | Set by | Purpose | Lifetime |
|---|---|---|---|
| authjs.session-token | BuildRound (Auth.js) | Keeps you signed in | 30 days |
| authjs.csrf-token | BuildRound (Auth.js) | Anti-CSRF protection for sign-in forms | Session |
| authjs.callback-url | BuildRound (Auth.js) | Remembers where to send you after sign-in | Session |
| authjs.pkce.code_verifier | BuildRound (Auth.js) | PKCE proof during sign-in handshake | 15 minutes |
| authjs.state | BuildRound (Auth.js) | CSRF state for the OAuth handshake with AWS Cognito | 15 minutes |
| __stripe_mid | Stripe (only on payment pages) | Fraud prevention for card payments | 1 year |
All of these are "strictly necessary" cookies under UK PECR — they are required for the service to function (authentication, payment fraud protection). Under PECR Regulation 6(4) these do not require prior consent.
2. What we do not set
- - Advertising cookies (Google Ads, Facebook Pixel, etc.) — never.
- - Analytics cookies — our product analytics tool (PostHog Cloud EU) uses local storage, not cookies, and is configured with
person_profiles: identified_onlyso we don't spawn a server-side profile for anonymous visitors. - - Cross-site tracking cookies — we don't follow you around the web.
- - Fingerprinting technologies — we don't try to identify your device beyond session auth.
3. Local storage
We use your browser's local storage in two ways. Both stay on your device unless you sign up.
- - Wizard progress. During Steps 1-5 we save what you entered (business name, services, coverage area, pricing) under the key
buildround_wizard. When you sign up at Step 6 the data transfers to our servers and is removed locally. - - Analytics state. PostHog stores an anonymous device id and session id under keys starting with
ph_. We also store the marketing source you arrived from (UTM parameters, captured at first visit) underbuildround_utmfor 30 days, so we know which channels drive sign-ups. None of this is shared with third parties beyond PostHog Cloud EU (Frankfurt).
You can clear all of this from your browser's site-data settings at any time. We honour the DNT(Do Not Track) browser header — when it's on we skip loading PostHog entirely.
4. How to control cookies
All modern browsers let you view, clear, or block cookies in Settings. If you block essential cookies, BuildRound won't be able to keep you signed in — you'll be forced to sign in again every time.
5. Changes
If we ever add a non-essential cookie we would update this page, show a consent banner, and only set the cookie once you opt in. We have no current plans to do so.
6. More
See our Privacy Policy for the wider picture on how we handle personal data.
Company information
- Legal name
- BuildRound Ltd
- Company number
- TBA
- Registered office
- TBA — Companies House registered address
- Jurisdiction
- England and Wales
- Support
- hello@buildround.com
- Privacy
- privacy@buildround.com