1. What cookies are
Cookies are small text files that a website stores in your browser. Some are needed for a site to work. Others are used to measure visitors or to show advertising. We use only the first kind.
2. The cookies we use
All of these are first-party cookies, set by joeloya.com itself. None of them is shared with advertisers or data brokers.
PHPSESSID - session cookie
- What it does: holds a random session identifier so the site can protect our forms against forgery and abuse, remember which step of the email verification you are on, and keep your place while you sign in to the portal.
- When it is set: only when you use the case form, the contact form or the client portal. Simply reading the site does not set it.
- How long it lasts: until you close your browser.
wdr_portal - client portal sign-in
- What it does: keeps you signed in to the client portal on a device you chose to sign in on, so you are not asked for a one-time code every time. It contains a random token. We store only a scrambled (hashed) copy of the token on our server.
- When it is set: after you confirm a one-time code, either when you submit a case or when you sign in at /portal.
- How long it lasts: 12 months, renewed each time you use the portal. It is an HttpOnly cookie, so scripts on the page cannot read it, and it is sent only to the portal part of the site, over HTTPS.
wdr_admin - staff only
- What it does: keeps our team signed in to the administration area. It is not set for clients or visitors.
3. What we do not use
- No advertising or retargeting cookies.
- No analytics or visitor-tracking cookies or scripts.
- No social media plug-ins or embedded third-party content that sets cookies.
- Fonts and images are served from our own site, so no third party sees your visit.
4. Why we do not ask for consent
Cookies that are strictly necessary to provide a service you have asked for, or to secure it, do not need consent under EU and UK rules. The session cookie protects the forms you choose to use, and the portal cookie is set only when you choose to sign in. If we ever add any non-essential cookie, we will ask first and update this page.
5. Your choices
- Sign out. In the client portal, "Sign out" ends the sign-in on the device you are using and deletes its record on our server. "Sign out everywhere" ends every device signed in to your email address.
- Use your browser settings to block or delete cookies. Without the session cookie the forms cannot work, and without the portal cookie you will need a new one-time code each time you visit the portal.
- On a shared or public computer, always sign out when you finish.
6. Changes and contact
We will update this page if the cookies we use change. Questions: privacy@joeloya.com. See also our Privacy Policy.