Corporate Business Alliance

Policies and regulations

Cookie policy

Short, because there is very little to report.

Last updated

We set no tracking cookies

This site sets no analytics cookies, no advertising cookies and no third-party tracking of any kind. There is no consent banner because there is nothing to consent to. Under PECR, consent is required before anything that is not strictly necessary is stored on your device; we store nothing that is not.

What is actually stored

  • Nothing at all when you browse the public site without signing in or adding anything to your cart.
  • cba-cart-v1 in your browser’s local storage, once you add something to your cart. It is how the cart remembers what you chose between pages. It is not a cookie, so it does not travel with every page you load: the cart and checkout send its contents to our server only to price them, and nothing is kept there until you place an order. It holds which certification and which option you picked, or membership, and for a re-sit added from a result page, the reference of the sitting it follows, so that the re-sit can be priced. It holds no name, no email address and nothing else about you, and prices are always worked out afresh on our server. It is written only when you add something, it is strictly necessary for the cart you asked to use, and so under PECR it needs no consent. It is emptied once your order is placed. To clear it yourself, remove the items from your cart, or clear this site’s data in your browser’s settings.
  • payload-token once you sign in, whether as a candidate on this site or as staff at /admin. It keeps you signed in and is strictly necessary for that. It cannot be read by scripts in your browser, it lasts eight hours, and signing out ends the session immediately rather than waiting for it to expire.
  • cba_signed_in alongside it, holding a single character and nothing else. It exists so the site can show you the right link in the menu without asking our database on every page, which keeps pages fast. It contains no name, no email and no identifier, and it grants no access on its own: every page that shows your materials checks the real session on the server.

No third-party requests

Fonts and icons are served from our own domain rather than a third-party CDN. Loading a page on this site does not disclose your IP address to Google, to a font provider, or to anyone else.

When you pay

Nothing on this site takes card details. Payment is made on the payment provider’s own page, which loads from their domain and sets their own strictly necessary cookies — for fraud checking and for keeping the payment session together. Those are theirs, not ours, and are governed by their notice rather than this one. Browsing the site and filling your cart contact no payment provider at all.

If this changes

If we ever add analytics, it will be behind a genuine opt-in and this page will be updated before it goes live, not after.

Questions: contact us.