Legal
Cookie policy
Most cookie policies are long because the site has a lot to declare. Ours is short because we set one cookie, it keeps you signed in, and there is no tracking of any kind.
Last updated 21 August 2026
Draft, pending professional review. This document describes how Dialspire actually works today, but it has not been reviewed by a solicitor and some details are still to be filled in. Please don’t rely on it as a final statement of our obligations.
The short version
Dialspire sets one cookie. It holds your sign-in session, and without it you cannot stay signed in. We store one other thing in your browser: your answer to the cookie banner, so we stop asking.
Those two are the whole inventory on a deployment with nothing else switched on, and they are all you get unless you choose otherwise. There is never advertising, session replay, cross-site profiling or a social button anywhere on this site.
Three optional things can be switched on, and all three are named here whether or not they are running today, because a policy that only describes the quiet case is one you cannot rely on:
- Vercel Web Analytics — page views and referrers, with the country, browser and type of device they came from, so we can tell whether this site is any use. Run by Vercel Inc., which already hosts the site, and processed in the United States. It sets no cookie at all: visitors are counted by a hash of the request that Vercel discards after 24 hours, and it cannot follow you to another site. It counts the public website only, never the signed-in app, and any part of an address that works as a key — in a checkout, password-reset or invite link — is removed before anything is sent. It loads only after you choose “Accept all”, and stops sending anything the moment you change your mind.
- Plausible Analytics — page views and referrers, so we can tell whether this site is any use. Run by Plausible Insights OÜ on servers in Germany. It sets no cookie at all and no device identifier, and it cannot follow you to another site. It loads only after you choose “Accept all”, and is removed again the moment you change your mind.
- Cloudflare Turnstile — a bot check on the enquiry form, and only on that form. It loads when you start filling the form in, not when you arrive, and it may set its own storage while it runs. We treat it as strictly necessary, because it exists to stop that one form being abused rather than to learn anything about you — so it is not held behind the banner.
The rules this follows
Storing anything on your device — a cookie, a localStorage entry, anything else — is governed in the UK by regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003. That regulation was replaced on 5 February 2026 by the Data (Use and Access) Act 2025, and the exceptions now sit in Schedule A1 to those regulations.
The general rule is that you have to be told and have to consent. Schedule A1 then carves out storage that is strictly necessary to provide the service you asked for, and paragraph 4(2)(e) names two examples that describe exactly what we do: automatically authenticating the identity of the user, and maintaining a record of selections made on a website.
Schedule A1 also creates newer, narrower exceptions for statistical measurement and for appearance settings, both of which need an easy free opt-out. We do not currently rely on either: the analytics described above waits for you to choose “Accept all” rather than counting on the statistics exception.
Everything we store on your device
| Name | Type | What it does | How long | Consent needed? |
|---|---|---|---|---|
cb_session | Cookie (httpOnly, SameSite=Lax, Secure in production) | Holds your sign-in session so the app knows who you are on each request. Only the server can read or set it — page scripts cannot. | 30 days, or until you sign out | No — strictly necessary (Sch. A1 para. 4(2)(e)(i)) |
cb_cookie_consent | localStorage entry | Records whether you chose “Essential only” or “Accept all”, so the banner stops appearing. | Until you clear your browser storage, or reopen the settings and change it | No — strictly necessary (Sch. A1 para. 4(2)(e)(ii)) |
Both entries are exempt from consent, which means Dialspire would work correctly with no banner at all. We show one anyway, because being told what is stored is worth more than being technically excused from saying it.
Changing your mind
There is a Cookie settings link in the footer of every page. Click it and the banner comes back with both options, so changing your answer takes exactly as long as giving it did.
Or use your browser
Schedule A1 paragraph 2(3) expressly recognises browser controls as a way of signifying your choice. Every major browser lets you block or clear cookies and site data for a single site. Blocking ours will sign you out and keep you signed out — that is the cookie doing its job, not a fault.
Third parties
Fonts
Our fonts are downloaded at build time and served from our own domain, so loading a page makes no request to Google and sets no font-provider cookie.
Payments
We do not embed a payment form. Choosing a plan sends you to Stripe’s own hosted checkout page, where Stripe sets its own cookies under its own policy, on its own domain — not ours. Card details are entered there and never reach us.
Inside the product
When your team connects a mailbox, a carrier or a CRM, those connections are made server-to-server. They do not put anything in your browser.
Questions
Ask us at [PRIVACY CONTACT EMAIL]. The wider picture of what we hold and why is in our privacy notice.