Cookie Policy
Version 1 · Effective from 7 September 2026
CLICKMEATS LIMITED (Company Number 17328291) · Registered office: 140 Caldervale Avenue, Manchester, M21 7PY, United Kingdom · ICO registration reference: ZC232709
1. What cookies are
Cookies are small text files a website stores on your device. They usually contain a short piece of data (like an ID or a preference) so the site can recognise you or remember what you did last time. Modern sites also use browser storage (such as localStorage) for similar purposes. This policy uses the word “cookies” to cover both cookies and similar technologies, including browser storage — they are treated the same way under UK law (the Privacy and Electronic Communications Regulations 2003 (PECR) and the UK GDPR).
This policy applies to our website at clickmeats.co.uk and our mobile app, and should be read with our Privacy Policy, which explains how we handle personal data generally.
2. The two kinds of cookies we use
We split every cookie into one of two categories:
Strictly necessary — needed for the Platform to work. Sign-in, basket and payment processing all fall in here. These run whether or not you accept the cookie banner. Under UK law we do not need your consent for strictly necessary cookies, but we still list them below so you can see what is running.
Analytics — help us understand which parts of the Platform people use. These only run if you click Accept on the cookie banner. If you decline (or have not answered), we do not load them.
We do not use advertising cookies, third-party trackers or fingerprinting. If that ever changes, we will update this page and reissue the banner so you can make a fresh choice.
3. Strictly necessary cookies
| Name | What it does | How long | Set by |
|---|---|---|---|
| cognito-* / amplify-* | Keeps you signed in. Set by Amazon Cognito when you log in and cleared when you sign out. | Session + refresh token (up to 30 days) | Amazon Cognito |
| clickmeats.cart | Remembers what is in your basket between page loads. Stored in your browser only. | Until you place the order or clear your basket | ClickMeats (localStorage) |
| clickmeats.cookie-consent | Records whether you accepted or declined the cookie banner, so we do not ask again on every visit. | 12 months | ClickMeats (localStorage) |
| __stripe_mid / __stripe_sid | Set by Stripe on the payment page to detect fraud and complete card payments securely. | Session (sid) or 1 year (mid) | Stripe |
4. Analytics cookies (opt-in only)
| Name | What it does | How long | Set by |
|---|---|---|---|
| ph_* | PostHog product analytics. Records pseudonymous page views and clicks so we can see which parts of the Platform are useful. Only set if you clicked Accept on the cookie banner. | 12 months | PostHog (EU region) |
PostHog is hosted in the EU. We do not send directly identifying personal data (names, emails, postal addresses) to PostHog — events such as “visited /shops” or “added item to basket” are recorded against a pseudonymous identifier.
In the mobile app the same rules apply to app storage, software development kits and device or installation identifiers: regulation 6 of PECR treats these in the same way as browser cookies. The PostHog analytics identifier in the app, the push notification token your device issues when you turn notifications on, and access to your device’s precise location are all opt-in, and none of them is set or read if you do nothing. On the website, choosing “Use my location” works the same way. The analytics identifier lasts up to 12 months. We store the push notification token from when you turn notifications on; turning them off in your device settings stops them appearing on your device. We mark the token inactive once the notification service reports it is no longer valid — for example after you uninstall the app — and we delete it when you close your account.
We rely on your consent for analytics. We do not rely on the exception for statistical purposes in Schedule A1 to PECR, because our analytics can include event-level and pseudonymous user and device information.
5. Error monitoring
We use Sentry to record technical errors that happen in your browser (for example, a page fails to load or a script crashes). This is not a cookie — Sentry sends error reports over the network in the moment they happen and does not persist an identifier on your device. Sentry runs on all visits because it is essential for keeping the Platform working. The app is configured to strip authorisation headers, cookies, payment details and common sensitive fields before each report is sent; accidental personal data in unusual error contexts remains possible and is handled under our incident process. We keep error reports for 30 days.
6. How to change your mind
You can change your choices at any time, and it is as easy to withdraw consent as it was to give it:
On the website: use Cookie settings to accept or decline analytics at any time. Your choice takes effect straight away. You can also clear the clickmeats.cookie-consent entry in your browser’s storage, and the banner will reappear on your next visit.
In the mobile app: use Account settings to turn analytics, push notifications and location access on or off at any time.
To block cookies entirely: your browser’s cookie settings can block third-party cookies or all cookies. Note that blocking strictly necessary cookies will stop you signing in or placing an order.
7. Changes to this policy
If we add or remove a cookie we will update this page and the effective date below. If the change is material — for example, a new analytics tag or a new notification channel — the consent banner will reappear so you can make a fresh choice, and where required we will seek fresh consent before the new cookie is set.
8. Contact
Questions about cookies or your data: admin@clickmeats.co.uk.
Version 1. Effective from: 7 September 2026.
