Cookie and Device-Storage Policy
Last updated: · Last reviewed:
Last updated: 22 September 2026
1. What this policy covers
This policy explains how Lydmera Limited uses cookies, browser local storage and similar technology that stores information on or accesses information from your device.
Optional Google Analytics 4 is disabled by default. A fresh choice of Accept analytics authorises visits to our home, features, pricing and product-tour pages and the limited confirmed outcomes described below; earlier choices covering public-page visits only do not authorise this expanded purpose. The Google browser tag loads only on those four pages after acceptance. It does not measure page views inside the application, sign-in, checkout, contact or legal pages. No Google request or analytics cookie is made before acceptance. Lydmera does not use behavioural advertising, cross-site tracking, device fingerprinting or session replay.
2. Your storage choices
The storage used for the Service’s core functions is limited to:
- authentication and security needed for an Account;
- recording a unit or display selection you make;
- adapting appearance or functionality to your selected preference; and
- remembering that you asked to hide a particular prompt or announcement.
Guernsey’s e-Privacy Ordinance requires clear and comprehensive information and an opportunity to refuse device storage, subject to narrow transmission and strictly-necessary exceptions. Current UK rules contain strictly-necessary and specified appearance/functionality exceptions; the UK appearance exception requires clear information and a simple, free means to object.
The appearance and dismissal records listed below are created only after you select a theme, unit system or language, or expressly choose “Don’t show this again.” Lydmera provides this information through a persistent footer link and provides a Clear saved preferences control. Authentication storage is created only when you request sign-in and is necessary to maintain and protect that session.
When optional analytics is enabled, Accept analytics and Reject analytics are equally accessible choices. No choice is saved until you take an action. You can reopen Analytics preferences in the footer to change your choice. Analytics consent is separate from the core storage above and is not required to use the Service. Advertising data sharing, Google signals and advertising personalisation are disabled in this integration.
The Service is initially marketed in Guernsey and the United Kingdom. We review storage before targeted expansion into another territory and whenever its purposes change.
Using an exception does not mean the information is unregulated. Where a session or other stored identifier is personal data, the Privacy Notice and applicable data-protection law also apply.
If we introduce storage that does not meet an exception, we will update this policy and obtain valid consent before enabling it where required. An old choice from a retired banner will not be treated as consent to a new provider or purpose.
3. What Lydmera stores
| Name/family | Type | When set | Sole purpose | Duration/control | Storage basis |
|---|---|---|---|---|---|
lydmera-theme | local storage | You select an available appearance | Apply the selected appearance before the page displays | Until you change it, clear saved preferences or clear site data | Appearance/functionality preference; alternatively records an express selection |
lydmera-unit-system | local storage | You select metric or imperial | Apply the unit selection in the browser before display | Until changed or cleared | Records a requested selection |
lydmera-units | first-party cookie | The same unit selection | Allow the server to render pages and reports in the selected units | Up to 1 year, or until changed/cleared | Records a requested selection needed for server-rendered output |
lydmera-locale | first-party cookie | You select an available language | Allow the server to render pages and documents in the selected language | Up to 1 year, or until changed/cleared | Records a requested selection needed for server-rendered output |
lydmera-cta-dismissed:{feature} | local storage family | You choose “Don’t show this prompt again” | Keep that identified prompt hidden | Until cleared or the relevant application logic changes | Records the action you requested |
lyd-announce-v1 (or the current versioned key) | local storage | You choose “Don’t show this announcement again” | Keep that version of the announcement hidden | Until cleared; a materially new announcement uses a new key | Records the action you requested |
sb-* | authentication cookie family | You sign in or verify an Account | Maintain and refresh the authenticated session and protect Account access | Until sign-out, expiry or invalidation under the production Supabase configuration | Strictly necessary authentication/security |
lydmera-cookie-consent | first-party, host-only cookie | You accept, reject or change optional analytics | Remember your current analytics choice and an opaque random grant reference so a withdrawal can be honoured; the reference is never sent to Google and is cleared after confirmed withdrawal | Up to 365 days from your action, or until changed/cleared | Records the choice or refusal you requested |
lydmera_ga and lydmera_ga_* | first-party, host-only cookies used by Google Analytics | Analytics is enabled and you have accepted it | Distinguish browsers and sessions for public visits and provide identifiers for consented outcome measurement | Up to 90 days; expiry is not extended on each visit; cleared on rejection or withdrawal | Optional analytics consent |
__Host-lydmera-acquisition | first-party, host-only cookie; Secure, HttpOnly, SameSite=Lax | After current consent and successful context creation | Random token linking the consented visit to server-confirmed enquiry, trial and first-payment outcomes; Account linkage remains internal | Up to 30 days from creation, shortened by consent expiry; never extended by visits; cleared after confirmed withdrawal | Optional analytics consent |
The first six families are first-party preferences and are not intended to contain a name, email address or account identifier. Authentication tokens in sb-* identify a session and are personal data; Supabase processes them for Lydmera as described in the Privacy Notice and Subprocessors page.
Google Analytics cookies contain browser and session identifiers and are not anonymous. Google also receives your IP address and browser/device information from browser connections. Public-page measurement uses approved page metadata and recognised search/social referrer origins. Our server stores a fixed context for up to 30 days and may link it to your authenticated Account internally to confirm an accepted sales enquiry, activated trial or first captured subscription payment. Server outcome reports send the browser identifier, actual outcome time, outcome, plan where relevant and fixed campaign codes; they do not send the internal Account link or associate delayed payments with an old session.
Permitted campaign codes are organic LinkedIn or YouTube campaigns launch_2026_09 and q4_2026, with optional li01–li30 or yt01–yt15 content codes, and google/cpc/us_engineering_pilot with thermal_rsa or hydraulics_rsa. Other sources remain unattributed. We exclude names, email addresses or their hashes, Account/project and Paddle identifiers, Customer Content, form text, payment amounts/card details, search terms, advertising click identifiers, arbitrary URL parameters, fragments and private-page addresses. No click-level advertising attribution or advertising personalisation is enabled. The Privacy Notice explains recipients and retention, including Google’s unchanged two-month user/event retention; browser-cookie expiry is separate.
4. Clear or object to saved preferences
To reject or withdraw, open Analytics preferences and choose Reject analytics. Browser measurement stops immediately and its cookies are cleared. Our server must also confirm withdrawal, clear the acquisition cookie, remove Google identifiers from its context and cancel unsent outcome exports. A network or storage failure shows a warning to retry; local measurement remains off, but do not assume server withdrawal succeeded until confirmed. Your refusal may be saved for up to 365 days. The opaque withdrawal reference is cleared after server confirmation, or retained if a retry is needed. A request already dispatched cannot be recalled, and withdrawal does not undo earlier lawful processing or automatically erase data already held by Google. The separate control below clears appearance and dismissal preferences, not your analytics choice.
This page provides a first-party Clear saved preferences button. It clears the six non-authentication preference families listed in section 3, and only those:
- removes
lydmera-theme; - removes
lydmera-unit-system; - removes every
lydmera-cta-dismissed:*key; - removes the current and known retired
lyd-announce-*keys; and - expires the
lydmera-unitscookie using the same host/path attributes with which it was set. - expires the
lydmera-localecookie using the same host/path attributes with which it was set.
The interface then returns to its default or current system appearance and units without immediately recreating a persistent key.
Clears the 6 preference families listed above. Your sign-in is not affected.
The control does not clear authentication and does not sign you out: sb-* authentication storage is retained, and your session continues. If you later select a preference or again ask to hide an item, that action may store the corresponding choice again.
You can also clear site data in browser settings. Browser controls are additional controls, not the only means of objecting to appearance-preference storage.
Signing out clears the local authenticated session. A server-side session may also be invalidated for security.
5. Paddle Checkout
When you open Paddle Checkout or the Paddle buyer portal, Paddle may use its own cookies or similar technology for checkout, authentication, payment security, fraud prevention, buyer support and legal compliance. Paddle acts as the authorised reseller/Merchant of Record and an independent controller for that transaction activity. Paddle’s own Privacy Policy and storage information apply on its surfaces.
Paddle is not a Lydmera subprocessor for buyer transactions and determines its own transaction purposes and legal bases. Whether Paddle relies on consent or an exception for its own technology is explained on Paddle’s surfaces.
6. Other providers
Lydmera does not currently set a separate generic hosting/CDN cookie. If a new third-party storage item is introduced, this Policy will identify its provider, purpose, duration and applicable storage basis before the item is enabled where prior information or consent is required.
Links to other websites take you to services with their own storage practices.
7. How we review storage
We review the storage used on clean anonymous and authenticated sessions and after changes to authentication, checkout, embeds or measurement technology. We update this Policy when an item, purpose or duration materially changes. Storage controlled by Paddle on its own checkout or buyer-portal surfaces is covered by Paddle’s notices.
8. Changes and contact
We will update this policy before materially changing device-storage purposes. We will not treat a previous preference or retired consent record as permission for a new analytics, advertising, attribution, replay, profiling, fingerprinting or third-party-embed purpose.
Questions or complaints: privacy@lydmera.com. You may also contact the Office of the Data Protection Authority in Guernsey and, where applicable, the UK Information Commissioner’s Office or the relevant EEA supervisory authority.