Cookie Policy
Last updated: 18 September 2026
Required business details and production information still need completing. This policy isn’t ready for public launch.
1. About This Cookie Policy
This Cookie Policy explains how Keep Improving uses cookies and similar technologies on:
and associated Keep Improving web application routes.
It should be read alongside the Keep Improving Privacy Policy.
This policy explains:
- what cookies are
- why Keep Improving may use them
- the difference between essential and non-essential cookies
- how consent is handled
- how users can manage cookie preferences
- how long cookies may remain on a device
- which third-party services may place or use cookies
2. What Are Cookies?
Cookies are small text files placed on a device when a website or web application is used.
They can help a service:
- keep users signed in
- remember essential preferences
- protect accounts and sessions
- understand whether a request is legitimate
- remember consent choices
- measure website usage where analytics has been enabled
Some cookies exist only for the duration of a browser session.
Others remain on a device for a defined period unless deleted earlier.
3. Similar Technologies
Keep Improving may also use technologies that perform similar functions to cookies.
These may include:
- local storage
- session storage
- browser storage
- authentication tokens
- consent-management storage
- similar client-side technologies required to operate the Service
Where these technologies are used for the same purpose as cookies, they should be treated consistently with this policy and applicable law.
4. Cookie Categories
Keep Improving should classify cookies according to their purpose.
4.1 Strictly necessary cookies
These are required for the website or application to function securely.
They may be used for:
- authentication
- secure sessions
- maintaining logged-in state
- CSRF or request-security protection
- load balancing
- fraud and abuse prevention
- remembering essential cookie-consent choices
- other functions necessary to provide a service explicitly requested by the user
Where permitted by law, strictly necessary cookies do not require consent.
Users may not be able to use some authenticated or secure features if these cookies are blocked at browser level.
4.2 Analytics cookies
Analytics cookies may be used to understand how visitors use the public marketing website.
They may help measure:
- page visits
- navigation paths
- device and browser categories
- referral sources
- page performance
- conversion activity
- general website usage patterns
Analytics cookies must only be used where the production configuration and applicable consent requirements permit them.
[TO COMPLETE: confirm whether analytics cookies are used at launch and identify the provider]
4.3 Preference cookies
Preference cookies may be used to remember optional choices that improve the user experience.
Examples might include:
- display preferences
- consent settings
- optional interface preferences
Only list preference cookies that are actually used.
4.4 Marketing or advertising cookies
Keep Improving should not claim to use marketing or advertising cookies unless they are actually implemented.
At the time this draft was prepared:
[TO COMPLETE: confirm whether any marketing, advertising, remarketing or cross-site tracking technologies will be used at launch]
If such technologies are introduced later, this policy and the cookie-consent mechanism must be updated before they are used.
5. Essential Cookies and Authentication
Authorised organisation users log in to the Keep Improving management dashboard.
The authentication system may use strictly necessary cookies or similar technologies to:
- establish a secure session
- maintain the user's signed-in state
- protect authenticated routes
- refresh or maintain authorised access
- support password-reset and authentication flows
Public Reporters do not need to create an account or log in before submitting a public report.
Public reporting routes should not place non-essential cookies merely because a person scans a QR code or opens a reporting form.
6. Public Reporting and Cookies
The public reporting experience should remain as low-friction and privacy-conscious as reasonably possible.
Public reporters may access a form by:
Scan QR code or open public link → complete form → submit
The Service may process strictly necessary technical information needed for:
- rate limiting
- spam prevention
- abuse prevention
- request security
- service integrity
Where cookies or similar technologies are not necessary for those purposes, they should not be used on public reporting routes without the appropriate consent.
7. Cookie Consent
Where Keep Improving uses non-essential cookies, users should be given a clear choice before those cookies are set.
The consent mechanism should allow users to:
- accept optional cookies
- reject optional cookies
- change their preferences later
- understand the categories being requested
Consent should not be bundled into acceptance of the Terms of Service.
Strictly necessary cookies may remain active where they are required to provide the requested service.
8. Cookie Banner Requirements
If non-essential cookies are used, the production website should provide a cookie banner or equivalent consent interface.
The banner should:
- explain that optional cookies are being requested
- provide an equally accessible reject option
- avoid pre-selected optional categories
- link to this Cookie Policy
- allow preferences to be changed later
- avoid manipulative wording or design
Recommended button concepts:
- Accept optional cookies
- Reject optional cookies
- Manage preferences
Exact wording can be refined during implementation.
9. Managing Cookie Preferences
Where a consent-management interface is available, users should be able to reopen it from a persistent link such as:
Cookie Settings
This link should normally appear in the website footer.
Users can also manage cookies through their browser settings.
Browser controls may allow users to:
- view stored cookies
- delete cookies
- block cookies
- block third-party cookies
- clear site data
Blocking strictly necessary cookies may affect authenticated dashboard functionality.
10. Current Cookie Inventory
The final production cookie table must be generated from the actual live application configuration.
Do not publish guessed names.
Before launch, identify every cookie or equivalent storage item used by:
- Next.js application infrastructure
- Supabase authentication
- hosting infrastructure
- cookie-consent tooling
- analytics
- error monitoring
- support tooling
- embedded services
- any future third-party scripts
The public Cookie Policy should include a table in this format:
| Cookie / storage name | Provider | Purpose | Category | Duration |
| [TO COMPLETE] | [TO COMPLETE] | [TO COMPLETE] | Strictly necessary / Analytics / Preference / Marketing | [TO COMPLETE] |
Only include cookies or storage technologies that are actually used in production.
11. Supabase
Keep Improving uses Supabase for application services that may include:
- authentication
- PostgreSQL database
- storage
- server-side functions
- Row Level Security
Supabase authentication may use browser storage, cookies or other session-management technologies depending on the final implementation.
Before publication, confirm:
- the exact session-storage method used in production
- any cookie names
- whether cookies are first-party or third-party
- duration
- purpose
[TO COMPLETE BEFORE PUBLICATION]
12. Stripe
Keep Improving uses Stripe for subscription billing.
Stripe may use cookies or similar technologies when a user interacts with Stripe-hosted services such as:
- Checkout
- Customer Portal
- payment authentication
- fraud prevention
Stripe's own services may be subject to Stripe's privacy and cookie information.
Keep Improving should identify any Stripe cookies that are placed directly through the Keep Improving domain or embedded components.
Where Stripe-hosted pages are opened separately, their own cookie controls may apply.
13. Hosting Provider
Production hosting may use strictly necessary cookies or infrastructure-level technologies for:
- security
- routing
- bot protection
- performance
- request integrity
Production hosting provider:
[TO COMPLETE: confirm current provider, for example Vercel if still current]
Before publication, confirm whether the hosting provider places any browser cookies through the Keep Improving domain.
14. Analytics
If analytics is enabled, this section must identify the provider and actual behaviour.
Potential purposes may include:
- understanding which public pages are visited
- identifying popular use-case pages
- measuring navigation patterns
- measuring signup conversion
- identifying broken journeys
- improving page performance
Analytics must not be enabled merely because it is convenient.
Where consent is legally required, analytics must remain disabled until the user provides valid consent.
Analytics provider:
[TO COMPLETE]
Analytics cookie names and duration:
[TO COMPLETE]
If no analytics cookies are used, this section should be revised before publication to say so clearly.
15. Error Monitoring
Keep Improving may use an error-monitoring service to identify technical faults.
Error monitoring should be configured to minimise unnecessary personal information.
Provider:
[TO COMPLETE: confirm whether error monitoring is used and identify provider]
Before publication, determine whether the provider uses cookies or browser storage and whether those technologies are strictly necessary.
16. Embedded Content
If the marketing website later embeds third-party content such as:
- video
- maps
- external forms
- support widgets
- social-media content
those providers may set their own cookies or tracking technologies.
Do not embed third-party content that sets non-essential cookies before valid consent where consent is required.
At launch, list only embedded providers actually used.
Current embedded providers:
[TO COMPLETE OR STATE: None]
17. Marketing Technologies
Keep Improving should not add remarketing pixels, advertising networks or cross-site tracking by default.
If future marketing tools are introduced, this policy must be updated before activation.
Potential examples that would require review include:
- advertising pixels
- remarketing tags
- social-media tracking pixels
- cross-site advertising identifiers
Consent and transparency requirements must be considered before use.
18. Cookie Duration
Cookies may be:
Session cookies
Deleted when the browser session ends.
Persistent cookies
Remain until:
- their configured expiry date
- the user deletes them
- the application replaces them
- consent is withdrawn and they are removed where technically possible
The exact duration of each cookie must be shown in the production cookie inventory.
Avoid vague labels such as "a long time" or "as needed".
19. Withdrawing Consent
Where processing relies on cookie consent, users should be able to withdraw consent as easily as they gave it.
Withdrawal should:
- stop future use of the affected optional cookies
- update stored consent preferences
- remove optional cookies where reasonably possible
- not affect processing that occurred lawfully before consent was withdrawn
A persistent Cookie Settings control should be available where optional cookies are used.
20. Browser Do Not Track and Similar Signals
If Keep Improving supports browser-based privacy signals such as Global Privacy Control or Do Not Track, the policy should explain how those signals are handled.
At the time of drafting:
[TO COMPLETE: confirm production behaviour]
Do not claim support for privacy signals unless it has been implemented and tested.
21. Children's Privacy and Cookies
Keep Improving is not designed specifically as a service for children acting as account holders.
Where a customer organisation operates in an environment involving children or young people, the organisation remains responsible for ensuring that its use of the Service is appropriate and lawful.
Non-essential tracking should not be introduced into public reporting journeys involving children without appropriate legal assessment and safeguards.
22. Changes to This Cookie Policy
This Cookie Policy may be updated when:
- cookie usage changes
- a new provider is introduced
- analytics changes
- authentication behaviour changes
- consent tooling changes
- legal requirements change
- new embedded services are introduced
The latest version should be published at:
https://keepimproving.app/cookies
The Last updated date should change whenever a material revision is published.
23. Contact
Questions about cookies or privacy can be sent to:
[TO COMPLETE: Legal entity name] [TO COMPLETE: Postal address] Email: [TO COMPLETE] Website: https://keepimproving.app
For wider information about personal-data handling, see:
