Legal
Cookie policy
Last updated 28 September 2026
The cookies Herd sets, what each one is for and how long it lasts. They are all essential: they sign you in and they finish a connection to a social, storage or mailbox account. We set no analytics and no advertising cookies, so there is nothing here to consent to and no preference centre to visit.
2. How We Use Cookies
We use cookies for two purposes, and only these two:
- Authentication: To recognise you when you sign in, to keep you signed in as you move between pages, and to renew your session when the short-lived sign-in token expires
- Connection flows: To complete a connection to a social account, a storage account or a mailbox safely, by checking that the reply coming back from that provider is the one we sent you to and has not been tampered with
We do not use cookies to remember preferences, to measure how you use the Service, or for advertising. We set no analytics cookies and no advertising cookies, and there is no analytics or advertising script on our website or in the product.
3. Types of Cookies
Cookies can be classified in several ways:
By Duration
- Session Cookies: Temporary cookies that are deleted when you close your browser. Used for things like keeping you logged in during your session.
- Persistent Cookies: Remain on your device for a set period or until you delete them. Used for remembering preferences and analytics.
By Origin
- First-Party Cookies: Set by us directly when you visit our website.
- Third-Party Cookies: Set by another company, on that company’s own domain, when part of its service is used inside ours. The only example on Herd is Stripe’s hosted checkout (clause 8).
Every cookie listed in clause 4 is a first-party cookie set by us. All of them are httpOnly, which means the page’s scripts cannot read them, and all of them are marked Secure in production so they are only ever sent over an encrypted connection.
4. Essential Cookies
These cookies are necessary for the Service to function and cannot be disabled. They are the only cookies we set. Signing in sets the first two; the rest are set only at the moment you start connecting an account, and are cleared as soon as that connection finishes.
| Cookie Name | Purpose | Duration |
|---|---|---|
sb-access-token | The sign-in token that identifies you on every request. Set when you sign in. | Matches the life of the token itself: about an hour once it has been renewed, and never more than 30 days |
sb-refresh-token | Renews the token above without making you sign in again, including after you come back from a provider’s consent screen | 30 days |
facebook_oauth_state, instagram_oauth_state, tiktok_oauth_state, twitter_oauth_state, gdrive_oauth_state, aurinko_oauth_state | A one-time random value we send to the provider and check when it sends you back, so that the reply cannot be forged. One is set only when you start that particular connection. | 10 minutes |
tiktok_code_verifier, twitter_code_verifier | The PKCE verifier for those two connections: the secret half of the proof that the sign-in reply belongs to the request we made | 10 minutes |
gdrive_oauth_origin, aurinko_oauth_origin | Remembers which page you were on when you started the connection, so we can return you to it | 10 minutes |
Signing out clears the session cookies. The connection cookies expire by themselves, and the one used to complete a connection is cleared as soon as it has been checked.
Legal basis: These cookies are strictly necessary to provide the Service and do not require your consent under PECR (Privacy and Electronic Communications Regulations).
5. Functional Cookies
We set no functional cookies. The few things the product remembers about how you are using it — which tips you have dismissed, how far through onboarding you are — are kept in your browser’s own local storage, which is never sent to us. Clause 10 lists them.
Legal basis: Not applicable while no functional cookies are set. If we introduce one, this clause will say what it is for and how long it lasts.
6. Analytics Cookies
We set no analytics cookies. There is no Google Analytics, no Meta Pixel, no product-analytics tag and no session-recording script on our website or in the product: none is loaded, and none is loaded in the background awaiting consent either. Nothing tracks which pages you visit, how long you spend on them or where you came from.
If we ever add a measurement tool, we will name it here, say what it collects and for how long, and ask for your consent before it sets anything.
Legal basis: Not applicable while no analytics cookies are set. Consent would be required before any were.
7. Marketing Cookies
We set no marketing or advertising cookies. We do not run advertising campaigns that track you, and there is no Meta, Google Ads or TikTok conversion tag on the site.
If that changes, we will update this policy to name the cookies and obtain your consent before enabling them.
Legal basis: Not applicable while no marketing cookies are set. Explicit consent would be required before any were.
8. Third-Party Cookies
We do not let third parties set cookies on herduk.co.uk. What follows are cookies another company sets on its own domain, when you are taken to its page or when its content is embedded in ours. We do not control them and we cannot read them.
Payment Processing (Stripe)
Paying for a subscription, or paying an invoice through Herd, takes you to Stripe’s own hosted checkout page. Stripe sets its own cookies there, on Stripe’s domain, for fraud prevention and to keep the payment secure. Those cookies are Stripe’s, not ours. See Stripe’s Cookie Policy.
Social Media Embeds
If you view embedded content (like TikTok videos), those platforms may set their own cookies. These are subject to the respective platform’s cookie policies:
Customer Support
We do not currently use a live chat or support widget, so none is setting cookies. If we add one, we will name it here.
9. Managing Your Cookie Preferences
9.1 Current Preference Controls
There is no cookie preference centre, because there is nothing to set a preference about: every cookie we set is strictly necessary to sign you in or to complete a connection you asked for, and we set no analytics or advertising cookies. If we ever introduce a non-essential cookie, we will build the controls and ask for your consent before setting it. In the meantime you can manage cookies through your browser, as described below.
9.2 Browser Settings
Most browsers allow you to control cookies through their settings. Here’s how to manage cookies in popular browsers:
- Chrome: Settings → Privacy and security → Cookies and other site data (More info)
- Firefox: Settings → Privacy & Security → Cookies and Site Data (More info)
- Safari: Preferences → Privacy → Manage Website Data (More info)
- Edge: Settings → Cookies and site permissions → Manage and delete cookies (More info)
9.3 Opt-Out Tools
Herd does not use any of the tracking these tools opt you out of, so you do not need them for us. They are listed because they are useful across the rest of the web:
- Google Analytics Opt-Out Browser Add-on
- Network Advertising Initiative Opt-Out
- Digital Advertising Alliance Opt-Out
9.4 Impact of Disabling Cookies
If you block or delete cookies, please note:
- You will not be able to sign in, and deleting the session cookies while signed in will sign you out
- Connecting a social account, Google Drive or a mailbox will fail, because the check that makes the connection safe depends on the cookie set at the start of it
- The Service cannot be provided without these cookies, so they are not something we can offer to switch off
- Blocking local storage as well will not stop you using Herd, but tips you have already dismissed may reappear
10. Similar Technologies
Alongside cookies, the product keeps a small amount of information in your browser’s own storage. Unlike a cookie, this is never sent to our servers: it stays on the device, and clearing your browsing data removes it.
Local Storage
Local storage keeps the item until you clear it. We use it only to avoid repeating things at you:
| Item | Purpose |
|---|---|
herd_hints_seen | Remembers that you have dismissed the first-run hints, so they are not shown again |
herd_progressive_tips_shown | Remembers which of the in-page tips you have already been shown |
herd_first_session_shown | Remembers that the welcome shown on your first visit has been seen |
herd_onboarding, herd_onboarding_progress_<your account id> | Remembers how far through the onboarding steps you are, so you can leave and come back |
herd_first_deal_created, herd_first_payment_received | Remembers that the one-off “first deal” and “first payment” messages have been shown |
signupAccountType | Remembers which account type you chose while you finish signing up |
herd-portal-name:<portal link token> | On a client portal opened from a shared link, remembers the name you gave, so you are not asked for it on every action |
Session Storage
Session storage is cleared when you close the tab. We use two items, password_reset_in_progress and password_reset_timestamp, which exist only while you are part-way through resetting your password, so that the reset screen behaves correctly if the page reloads.
Pixels and Beacons
We do not use tracking pixels or web beacons on our website or in the product. If we introduce open- or click-tracking in marketing email, we will update this policy and ask for your consent first.
11. Changes to This Policy
We may update this Cookie Policy from time to time to reflect:
- Changes in the cookies we use
- Changes in legal requirements
- Changes to our practices
We will update the “Last updated” date at the top of this policy. For significant changes, we will request consent through any preference controls we implement for non-essential cookies.
12. Contact Us
If you have questions about our use of cookies, please contact us:
Herd UK Ltd
Email: privacy@herduk.co.uk
Website: https://herduk.co.uk
For more information about how we handle your personal data, please see our Privacy Policy.
