LAST UPDATED 25 August 2026
Cookie notice
This notice explains cookies and similar browser storage used on Chasd. We do not use advertising cookies or third-party behavioural analytics cookies.
1. What we use
| Name or category | Purpose | Duration |
|---|---|---|
| Supabase authentication cookies (names include the project reference) | Authenticate users, refresh sessions and protect signed-in access. | Session-dependent; renewed while signed in and removed or expired after sign-out according to authentication settings. |
| chasd_locale | Remember the language explicitly selected by the user. | 1 year |
| chasd_time_zone | Remember the time zone explicitly selected by the user. | 1 year |
| chasd_currency | Remember the display currency explicitly selected by the user. | 1 year |
| owed_xero_state | Secure the Xero connection redirect and prevent request forgery. | 10 minutes |
| chasd-theme | Store the light or dark colour-theme choice in local storage. | Until the user removes browser-site data or changes the choice. |
| owed-demo-v2 | Keep the fictional interactive demo state in local storage on the user’s device. It contains demo data only and is not sent to Chasd. | Until Reset demo is selected or browser-site data is removed. |
2. Why no cookie banner appears
These technologies are limited to authentication, security, a feature the user requests, or a preference the user chooses. They fall within applicable UK consent exceptions for strictly necessary or low-risk user-preference storage. We still provide this clear information as required.
If we add advertising, cross-site tracking or non-exempt analytics, we will update this notice and obtain valid consent before setting or accessing that technology.
3. Provider sites
When you choose to continue to Stripe Checkout, the Stripe customer portal or Xero authorisation, you leave the Chasd site. Those providers may use cookies on their own domains under their own notices and controls. Chasd cannot read provider-domain cookies.
4. Your controls
Browser controls can view, block or delete cookies and local storage. Blocking authentication or security storage can prevent sign-in and integrations. Removing preference storage resets the relevant display choice. In the demo, Reset demo removes the saved fictional state and starts again.
Questions or concerns can be sent to privacy@chasd.co.uk. Data-protection complaints follow the process in our Privacy Notice.