Cookie policy
Effective 15 August 2026 · Last updated 15 August 2026
The short version
- There are no analytics, advertising or tracking cookies on Carpoolish. Not “we anonymise them” — there are none.
- We store two things in your browser, both strictly necessary: your sign-in session, and a draft of your onboarding so a dropped connection does not cost you five minutes of typing.
- Because everything we store is strictly necessary to run the service, there is no consent banner. There is nothing to consent to.
- Signing in with Google, and loading our fonts, involves Google. That part is theirs.
This policy explains what Carpoolish stores in your browser and why. It sits alongside our privacy policy, which covers everything else.
1. What we actually store
Strictly speaking, we use almost no cookies at all — we use your browser's local storage, which does the same job without being sent to a server on every request. We are calling this a cookie policy anyway, because that is what people look for.
| Name | Type | What it does | How long |
|---|---|---|---|
| sb-…-auth-token | Local storage | Keeps you signed in and refreshes your session, so you are not asked for a password every time you open the app. Set by Supabase Auth, the service that handles our sign-in. | Until you sign out, or the session expires |
| cb.onboard.draft | Session storage | Holds what you have typed during signup — family name, address, players — so a lost connection or an expired session does not make you type it again. | Cleared when onboarding finishes, or when you close the tab |
Both are strictly necessary: the service cannot sign you in or complete signup without them. Neither is used to profile you, neither follows you to other websites, and neither is shared with anyone.
2. What we do not store
To be unambiguous, Carpoolish has none of the following:
- Analytics of any kind — no Google Analytics, no Plausible, no Fathom, nothing. We do not measure your visit.
- Advertising or retargeting pixels — no Meta pixel, no Google Ads tag, no LinkedIn Insight, nothing.
- Session recording or heatmaps.
- Third-party social widgets or embedded trackers.
- Any cookie that follows you to another website.
You can verify this. Open your browser's developer tools on any page of this site, look at the network requests and the storage, and compare it with what is written above.
3. Third parties your browser does talk to
Three of them, and only for the page to work:
| Who | Why | What they can see |
|---|---|---|
| Supabase | Sign-in, and every piece of data the app reads or writes | Your requests and your IP address |
| Google Fonts | Serves the typeface the site is set in | Your IP address and browser when the page loads. Google states these requests are not used to create profiles or serve advertising. |
| jsDelivr, unpkg | Serve the JavaScript library the app is built on | Your IP address when the app loads |
If you sign in with Google, you are sent to Google's own sign-in page and Google sets its own cookies there under its privacy policy. We receive only your name, email address and profile picture.
Links to Google Maps in the app are ordinary links. Nothing goes to Google until you choose to tap one.
4. Why there is no cookie banner
Consent banners exist because sites store things that are not necessary — usually for advertising or analytics. Under the ePrivacy rules and the GDPR, storage that is strictly necessary to deliver a service the user asked for does not require consent. Everything in section 1 is in that category, and we have nothing in the other one.
If that ever changes, we will ask you properly before setting anything, rather than putting a banner in your way and treating a click as agreement.
5. Controlling it yourself
- Sign out from Account → Sign out. That removes the session token.
- Clear site data in your browser settings removes both items above. You will need to sign in again, and any unfinished signup draft is lost.
- Block storage for this site in your browser settings. Carpoolish will not be able to keep you signed in, so you will be asked for a password on every page load.
- Private browsing works normally; everything is discarded when you close the window.
There is no “reject non-essential” option because there is nothing non-essential to reject.
6. Changes
If we ever add anything that is not strictly necessary, this page will change first and we will ask for consent before setting it. The date at the top tells you when it last moved.
7. Contact
info@hqforai.com. If you find something stored in your browser by this site that is not listed above, please tell us — that would be a bug and we would want to fix it.