Skip to main content
Workforce Toolbox — Tools for real work
Free ToolsPaid ToolkitsPacks & LibrarySoftware

Storage technologies

Cookie & Storage Notice

A technical account of cookies, browser storage and tracking in the current public pre-launch application.

Production-quality draft for owner review · Last reviewed 9 September 2026

Audit result

The Workforce Toolbox application does not currently set or read first-party application cookies. It does not use localStorage or sessionStorage, and it contains no analytics, advertising pixels, behavioural tracking or third-party embedded content.

A previously unused interface component that contained cookie-writing code has been removed. No application feature depended on it.

Free utilities

The seven free utilities keep entries in transient React/browser memory only. Information is cleared when the page is refreshed or the session ends and is not written to local storage or submitted to Workforce Toolbox.

Hosting and public access

The hosting platform uses security technologies to deliver and protect the public pre-launch site. The unauthenticated public-domain audit observed Cloudflare’s __cf_bm security cookie. It is an HTTP-only security cookie with a short lifetime of about 30 minutes and is controlled by the hosting layer rather than the Workforce Toolbox application. The former owner-only access boundary is no longer present on the public customer hostname.

Consent position

No non-essential storage or tracking technology was found in the application, so an application cookie-consent banner has not been added. If analytics, advertising, optional personalisation or another non-essential technology is introduced later, it must be assessed before use and consent obtained where required.

Software enquiries

The software-enquiry form sends completed submissions to Workforce Toolbox through Resend’s server-side HTTPS API. No Resend script or widget is embedded in the browser. Draft content is not persisted. The form adds no application cookies, localStorage, sessionStorage, external embeds, CAPTCHA, tracking or analytics. Its anti-abuse controls use a honeypot, strict validation, a request-size limit and a short-lived per-runtime request bucket; they do not create browser storage.

Stripe sandbox

Workforce Toolbox does not embed Stripe.js, Stripe Elements or a Stripe tracking script. The controlled pre-launch test flow redirects to Stripe-hosted Checkout. Cookies or storage used on Stripe’s separate checkout domain are controlled by Stripe and must be reassessed with the final live checkout.

Secure downloads

Secure delivery links carry the download credential in the URL fragment. The fragment is captured in transient page state, removed from the visible URL, and sent in the body of a same-site request to prepare the authorised download. The credential is not stored in an application cookie, localStorage or sessionStorage. The recovery form also uses transient form state only.

When this will be checked again

This notice and the technical audit must be reviewed before search indexing and live Stripe activation, and before any future analytics or other optional browser technology is introduced.

Drafting basis

  • ICO: Cookies and similar technologies
  • ICO: Storage and access technologies guidance
Workforce Toolbox

Tools for real work.

Practical general-management resources for Great Britain. Not individual legal advice.

TermsPrivacyRefunds & digital contentCookiesAccessibilityContact & supportLegal information