How this product uses cookies

Version 1.1,

Three cookies, none of which tracks anybody. No advertising, no tracking between sites, and nothing that counts page views anywhere behind the sign-in. The six public pages count visits, with no cookie and nothing stored on your device, which is why there is still nothing here to ask your consent for and no banner to click away.

The short version

Two of the three are strictly necessary: one keeps you signed in and one keeps a pupil's identifier out of the address bar. Neither requires consent under the Privacy and Electronic Communications Regulations, because the product cannot work without them. The third remembers a display preference and holds one word.

There is no cookie banner, and that is deliberate. A banner exists to collect consent for tracking, and there is no tracking here to consent to. Making sign-in conditional on accepting cookies would also be the wrong thing to do: consent has to be freely given, so an account you cannot reach without agreeing is not consent at all. What the law asks for instead is clear information and a way to object, which is this page and the paragraph below.

Every cookie, in full

NameWhat it is forHow long it lastsStrictly necessary
sb-…-auth-tokenKeeps you signed in after you have authenticated with your school's Microsoft or Google account.
Set by Supabase, the platform this product's database runs on. Without it you would be asked to sign in again on every page.
Until you sign out, or until the session expires. Sessions end after a period of inactivity.Yes
at_basisRemembers whether you are looking at all pupils or only those currently on roll, so the choice survives moving between tabs.
Contains one word, either 'statutory' or 'current'. Nothing about you and nothing about any pupil.
One year, or until you change it.No
at_pupilRemembers which pupil's report is open, so the report survives a page refresh without the pupil's identifier appearing in the address bar.
Holds a school identifier, a random token and a pupil identifier, and nothing else. Marked httpOnly, so no script on the page can read it, and it is only sent to this school's own pages. It exists specifically so that a pupil identifier does not end up in your browser history or in a server log. The random token also has to be present in the address bar for the cookie to open anything, which is what stops the report reappearing when you come back to the page later.
Until you leave the pupil report, close the report, or close your browser. It is a session cookie with no expiry date, so it is never written to disk with a lifetime attached, and on its own it opens nothing: the report only reappears while you stay on that page.Yes
These are the literal cookie names. You can open your browser's developer tools and check this table against what is actually set, which is the only thing that makes a policy like this worth reading.

What this product does not do

  • No analytics once you are signed in. Nothing counts your page views, records your mouse movements or builds a picture of how you work. Not on your dashboard, not on any report, not on any screen that has ever shown a pupil.
  • Page views are counted on the six public pages. The front page, the price list, the answers page, the privacy notice, the enquiry form and this one, which between them are every page you can reach without signing in. It is so we can tell whether schools are finding the site at all. It sets no cookie and reads nothing from your device. What is recorded is the page address, where you arrived from, your country, and your browser and device type. A visit is identified by a value worked out from the request itself, which is thrown away after a day, so nobody is identifiable and nothing follows you to another site. Because it stores nothing on your device, the consent rule in the Privacy and Electronic Communications Regulations, which is about storing or reading information on your equipment, does not bite.
  • No advertising or third-party tracking. No pixels, no tags, no social media buttons, nothing loaded from another company's server.
  • No cross-site cookies. Every cookie above is first-party and set by this site alone.
  • No pupil data in any cookie. The only identifier stored is in at_pupil, and it exists precisely so that identifier stays out of your browser history and out of server logs. No name, no attendance figure, ever.

Objecting, and turning them off

You can object to the preference cookie, at_basis, by blocking cookies for this site in your browser. Nothing breaks: the product still works and the choice between all pupils and current pupils simply starts fresh each time instead of being remembered.

Blocking cookies also blocks the two that keep you signed in, so you will not be able to use the product at all. That is what "strictly necessary" means in practice rather than as a category. If your school manages your browser centrally, your IT team controls this, and it is worth asking them rather than fighting the setting.

Who to ask about this

Your school is the data controller for its pupils' attendance records and iCT4 Limited is the processor, so questions about how your school uses this product go to your school's data protection lead. Questions about the product itself, including anything in this page, go to iCT4 Limited.

Write to dpo@ict4.co.uk, use the enquiry form, or ring the helpdesk on 01209 311344, option 1 for the MIS team.