COOKIE POLICY
COOKIE POLICY
COOKIE POLICY
This Cookie Policy explains how DEATH DOULA LTD, a private limited company incorporated in England and Wales (Company Number 17171845), with its registered office at 54 Mead Way, High Wycombe, England, HP11 1RH ("Company", "we", "us", or "our"), uses cookies, browser storage, and similar storage and access technologies when you visit or use our digital platform (the "Platform").
This Policy should be read together with our Privacy Policy.
We use storage and access technologies in accordance with the Privacy and Electronic Communications Regulations 2003 ("PECR"), including the amendments made by the Data (Use and Access) Act 2025, the UK General Data Protection Regulation ("UK GDPR") where personal data is involved, the Data Protection Act 2018, and other applicable law.
1. WHAT THIS POLICY COVERS
1.1. Cookies
Cookies are small pieces of data stored on or accessed from your device by a website or online service. They can be used for purposes such as maintaining an authenticated session, remembering choices, securing transactions, or measuring how a service is used.
1.2. Browser storage
The Platform may also use browser technologies such as Local Storage and Session Storage.
- Local Storage can retain information in your browser until it is cleared, replaced, or removed by the Platform.
- Session Storage is generally limited to the current browser tab or session and is normally removed when that tab or session ends.
1.3. Similar technologies
PECR can also apply to other technologies that store information on, or access information from, a user's device, including scripts, tags, tracking technologies, or comparable browser mechanisms.
For simplicity, this Policy sometimes refers collectively to cookies, browser storage, and similar technologies as "storage and access technologies".
2. WHEN WE NEED YOUR CONSENT
2.1. Strictly necessary technologies
We may use storage and access technologies without consent where they are strictly necessary to provide a service that you have requested, or where another applicable PECR exemption applies.
Examples may include technologies needed to:
- authenticate you and maintain a secure session;
- protect account and Platform security;
- complete a checkout or payment flow you have requested;
- retain information necessary for navigation immediately connected with a service you requested.
We still provide information about these technologies even where consent is not required.
2.2. Non-essential technologies
We do not use non-essential storage and access technologies that require consent before you have given valid consent.
Where consent is required, the Platform's consent mechanism allows you to make a choice before those technologies are used.
2.3. Your choice
You may accept or reject optional technologies through the cookie or privacy preference controls made available on the Platform.
You may withdraw or change your consent at any time through the same preference mechanism, where available. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
Simply continuing to browse or use the Platform is not treated as consent to non-essential technologies.
3. CATEGORIES OF TECHNOLOGIES WE USE
3.1. Strictly necessary and security technologies
These technologies support essential Platform functions such as authentication, session security, secure navigation, and transaction processing.
They may include:
- refresh_token — an authentication cookie used to maintain and securely rotate an authenticated session;
- access_token — an authentication token that may be stored in a cookie or browser storage, depending on the relevant Platform flow, and used for authenticated API access;
- doula_session_id — a randomly generated browser-storage identifier used for session stability, security, or related technical purposes;
- temporary security, checkout, anti-fraud, or session technologies used when you request a payment or other essential Platform function.
Authentication and security identifiers are retained only for the period reasonably required for the relevant session or security purpose. Current technical settings may provide for authentication credentials or related session information to remain valid for up to 30 days unless they expire, are rotated, revoked, or removed earlier.
3.2. Language and interface preferences
The Platform may use technologies that remember interface choices you make, including:
- site_lang — a cookie used to remember a language choice;
- site-locale — Local Storage used to remember a language or locale choice;
- __post_login_nav — Session Storage used temporarily to remember the page or destination to which you should return after authentication.
Language preferences may be retained for up to 12 months unless you change the setting or clear the relevant browser data.
The __post_login_nav value is temporary and is normally removed when the relevant browser session or tab ends.
Where a preference technology is strictly necessary to provide a setting or feature you have expressly requested, it may fall within an applicable PECR exemption. Where consent is legally required, we use it only in accordance with your consent choice.
3.3. Cookie preference record
The Platform may use:
- cookie_consent_v1 — Local Storage used to remember the cookie or storage preference you selected.
This preference may be retained for up to 12 months, or until you change your choice or clear the relevant browser data.
Remembering your consent or refusal is necessary to respect the choice you have made and avoid repeatedly asking you for the same preference during that period.
3.4. Analytics technologies
Where analytics are enabled, we may use Google Analytics to understand, in aggregate, how visitors use the Platform and to improve performance, navigation, and content.
Google Analytics and related analytics technologies are treated as optional. They are not loaded or used for analytics purposes before the consent required by law has been obtained.
Google Analytics technologies may include identifiers such as:
- _ga and related Google Analytics identifiers.
Depending on Google's configuration and the identifier concerned, analytics data or identifiers may be retained for a period of up to 24 months or another period configured by us and permitted by applicable law.
If you reject analytics technologies, the optional analytics scripts covered by that choice are not loaded for analytics purposes.
4. THIRD-PARTY PAYMENT AND SERVICE TECHNOLOGIES
4.1. Hosted payment pages
When you choose to make a payment, you may be redirected to or interact with a hosted checkout operated by a third-party payment provider.
Depending on the product, payment method, currency, and availability, payment providers may include:
- Stripe;
- NOWPayments;
- Lemon Squeezy;
- another payment provider clearly identified in the relevant checkout flow.
These providers may use cookies or similar technologies on their own websites or hosted checkout environments for purposes including transaction processing, authentication, security, fraud prevention, regulatory compliance, and service operation.
4.2. Responsibility for third-party technologies
Where a third party independently sets or accesses technologies on its own domain or service, its use of those technologies is governed by its own privacy and cookie information.
Where third-party technologies operate on our Platform and PECR requires us to obtain consent for them, we provide relevant information and obtain consent before enabling them.
4.3. Stripe
Stripe may use security and fraud-prevention technologies in connection with hosted checkout and payment processing. Identifiers historically associated with Stripe checkout may include technologies such as __stripe_mid and __stripe_sid, although the precise technologies and retention periods are controlled by Stripe and may change.
4.4. NOWPayments
NOWPayments may use its own storage and access technologies in connection with cryptocurrency payment processing, transaction security, fraud prevention, compliance, and operation of its hosted services. The precise technologies and retention periods are determined by NOWPayments.
4.5. Lemon Squeezy
Where Lemon Squeezy is offered as a payment or merchant-of-record provider, it may use its own cookies and similar technologies for checkout, authentication, transaction processing, fraud prevention, compliance, and operation of its services. The precise technologies and retention periods are determined by Lemon Squeezy.
5. SUMMARY OF CURRENT FIRST-PARTY TECHNOLOGIES
The Platform may use the following first-party technologies:
- refresh_token — cookie — authentication, secure session maintenance and rotation — generally up to 30 days unless expired, rotated, revoked, or removed earlier;
- access_token — cookie or browser storage, depending on implementation — authenticated API access — generally limited to the relevant authentication period and up to 30 days where configured;
- doula_session_id — Local Storage — session stability, security, and related technical purposes — until cleared or replaced;
- site_lang — cookie — language preference — up to 12 months;
- site-locale — Local Storage — language or locale preference — up to 12 months;
- cookie_consent_v1 — Local Storage — records your cookie or storage preference — up to 12 months or until changed;
- __post_login_nav — Session Storage — temporary post-login navigation — normally until the relevant tab or session ends.
Optional third-party analytics or hosted-payment technologies are described separately in sections 3.4 and 4.
6. HOW TO MANAGE YOUR PREFERENCES
6.1. Platform controls
When the Platform asks for consent to optional storage and access technologies, you can accept or reject the relevant optional uses through the consent interface.
Where the Platform provides a Manage Cookie Preferences or equivalent control, you can use it to review and change your choice later.
6.2. Browser controls
Most browsers allow you to view, block, or delete cookies and browser storage through browser settings.
Deleting your browser's site data may remove saved language preferences, authentication information, and your stored cookie choice. If your preference record is removed, the Platform may ask you to make a new choice.
6.3. Effect of blocking necessary technologies
Blocking or deleting strictly necessary authentication, security, or transaction technologies may prevent some Platform functions from working correctly, including signing in, maintaining a session, or completing a requested checkout.
Rejecting optional analytics technologies does not prevent you from using the core Platform.
7. HOW LONG WE KEEP TECHNOLOGIES
Retention periods depend on the purpose and technical configuration of the relevant technology.
Session technologies may expire when a browser session ends. Persistent technologies may remain for the period stated in this Policy, until they expire, until they are replaced, or until you delete them.
We review retention settings and seek not to keep device identifiers or browser-storage information for longer than reasonably necessary for the stated purpose.
Third-party providers determine the retention periods for technologies they independently control on their own services.
8. PERSONAL DATA AND STORAGE TECHNOLOGIES
Some storage and access technologies may involve personal data, for example an online identifier associated with an account or device.
Where personal data is processed, our Privacy Policy explains:
- the categories of personal data involved;
- why we process it;
- the lawful bases we rely on;
- who we share it with;
- international transfers;
- retention;
- your data protection rights.
Cookie consent under PECR and a lawful basis for processing personal data under the UK GDPR are related but distinct legal requirements. Where both apply, we comply with both.
9. CHANGES TO THIS COOKIE POLICY
We may update this Cookie Policy to reflect changes in law, regulatory guidance, Platform functionality, analytics, payment providers, or the storage and access technologies we use.
The current version will be published on the Platform with its Last Updated date.
Where a change materially affects optional technologies for which consent is required, we will update the information provided through our consent mechanism and request a new choice where required by law.
10. CONTACT
For questions about our use of cookies, browser storage, or similar technologies:
DEATH DOULA LTD
Company Number: 17171845 (England and Wales)
Registered Office: 54 Mead Way, High Wycombe, England, HP11 1RH
Email: [email protected]
For information about how DEATH DOULA LTD processes personal data, please see our Privacy Policy.