
Storage technologies
Cookie & Storage Notice
A technical account of cookies, browser storage and tracking in the current public pre-launch application.
Production-quality draft for owner review · Last reviewed 9 September 2026
Audit result
The Workforce Toolbox application does not currently set or read first-party application cookies. It does not use localStorage or sessionStorage, and it contains no analytics, advertising pixels, behavioural tracking or third-party embedded content.
A previously unused interface component that contained cookie-writing code has been removed. No application feature depended on it.
Free utilities
The seven free utilities keep entries in transient React/browser memory only. Information is cleared when the page is refreshed or the session ends and is not written to local storage or submitted to Workforce Toolbox.
Hosting and public access
The hosting platform uses security technologies to deliver and protect the public pre-launch site. The unauthenticated public-domain audit observed Cloudflare’s __cf_bm security cookie. It is an HTTP-only security cookie with a short lifetime of about 30 minutes and is controlled by the hosting layer rather than the Workforce Toolbox application. The former owner-only access boundary is no longer present on the public customer hostname.
Consent position
No non-essential storage or tracking technology was found in the application, so an application cookie-consent banner has not been added. If analytics, advertising, optional personalisation or another non-essential technology is introduced later, it must be assessed before use and consent obtained where required.
Software enquiries
The software-enquiry form sends completed submissions to Workforce Toolbox through Resend’s server-side HTTPS API. No Resend script or widget is embedded in the browser. Draft content is not persisted. The form adds no application cookies, localStorage, sessionStorage, external embeds, CAPTCHA, tracking or analytics. Its anti-abuse controls use a honeypot, strict validation, a request-size limit and a short-lived per-runtime request bucket; they do not create browser storage.
Stripe sandbox
Workforce Toolbox does not embed Stripe.js, Stripe Elements or a Stripe tracking script. The controlled pre-launch test flow redirects to Stripe-hosted Checkout. Cookies or storage used on Stripe’s separate checkout domain are controlled by Stripe and must be reassessed with the final live checkout.
Secure downloads
Secure delivery links carry the download credential in the URL fragment. The fragment is captured in transient page state, removed from the visible URL, and sent in the body of a same-site request to prepare the authorised download. The credential is not stored in an application cookie, localStorage or sessionStorage. The recovery form also uses transient form state only.
When this will be checked again
This notice and the technical audit must be reviewed before search indexing and live Stripe activation, and before any future analytics or other optional browser technology is introduced.