Cookie policy
Last updated: July 2026
What we use
Covered Beauty only sets strictly necessary cookies. We do not use any analytics, advertising, profiling or third-party tracking cookies. We do not track you across other sites and we do not sell your browsing data.
Anonymous page counting.To understand which of our public pages get visited, we count page views on our marketing pages (the homepage, pricing, find-a-salon and public salon pages) using our own first-party system. It sets no cookies and stores nothing on your device. We record the page, the site you arrived from (domain only), and whether the device was a phone or a computer. We do not store your IP address or browser details — they are combined into an anonymous code that changes every day, so we can count visitors for a day but can never identify you or follow you over time. If your browser sends a “Do Not Track” or Global Privacy Control signal, we don’t count you at all. Nothing is counted inside the dashboard or client portal.
Under the Privacy and Electronic Communications Regulations (PECR) we are not required to ask for your consent before setting strictly necessary cookies, but we do tell you about them through the cookie notice you see at the bottom of the screen on your first visit.
Cookies in use
| Name | Category | Purpose | Duration | Set by |
|---|---|---|---|---|
| sb-access-token / sb-refresh-token | Strictly necessary | Keeps you signed in to the dashboard. Without this you would have to re-enter your credentials on every page load. | Session + 7 days for the refresh token | Supabase auth (first-party) |
| gb_cookies_ack | Strictly necessary | Records that you have seen and dismissed our cookie notice so we don’t show it on every page. | 12 months | Covered Beauty (first-party) |
| gb_portal | Strictly necessary | Keeps tanning-shop customers signed in to their wallet portal after they verify a one-time email code. The cookie holds a signed reference to the customer record but no payment or health data. | 30 days | Covered Beauty (first-party) |
Stripe (payment pages)
When a client is paying a deposit, the booking flow temporarily redirects them to Stripe’s hosted Checkout page. Stripe sets its own cookies on that page for fraud prevention and PCI-DSS compliance. Those cookies are governed by Stripe’s cookie policy. We never see the contents of those cookies.
How to control cookies
Because we only set strictly necessary cookies, the dashboard will not work without them. You can clear or block cookies in your browser at any time, but doing so will sign you out and you will have to dismiss the cookie notice again on your next visit.
You can re-open our cookie notice at any time and withdraw your acknowledgement by clicking here, or via the “Manage cookies” link in the footer of every page.
Contact
Questions about this policy? Email hello@covered.technology.
You also have the right to lodge a complaint with the UK Information Commissioner’s Office at ico.org.uk.
Hamr Ltd