Cookie Policy
Last updated: September 2026
1. What are cookies?
Cookies are small text files that a website places on your device when you visit. They are widely used to make websites work properly and to remember your preferences.
2. The cookies we set ourselves
Upfayre sets a small number of first-party cookies, listed below. Only the first two are needed for the site to work; the rest are set when you make a choice or arrive from a tagged marketing link.
| Cookie name | Purpose | Duration |
|---|---|---|
| _schoollink_session | Keeps you signed in between page loads and carries the CSRF security token. Without this cookie the site cannot function. (The name comes from the project's original working title.) | Session (cleared when you close your browser) |
| remember_user_token | Set when you sign in with "Remember me" ticked — it is ticked by default, so most sign-ins set it. Keeps you signed in across browser sessions; the window rolls forward each time you use the site. | 2 weeks, rolling |
| cookie_consent | Records whether you accepted or rejected analytics cookies, so the banner doesn't reappear on every page. | 1 year |
| hide_achievements | Set only if you choose to hide the achievements panel on your dashboard; remembers that choice. | 1 year |
| beta_variant | Set only on our (now closed) beta landing page: remembers which version of the page you were shown so it stays consistent and sign-ups can be attributed to it. | 30 days |
| _upf_vid | Random visitor identifier, set only if you arrive via a tagged marketing link. Lets us count unique visitors arriving via a marketing channel without identifying you personally. | 1 year |
| _upf_attr | First-touch attribution, set only if you arrive via a tagged marketing link: stores the campaign tags from the link you first arrived through, so we can see which channels lead to sign-ups. First-party only. | 90 days |
3. Third-party analytics (opt-in only)
We use three analytics tools, and they only load if you click Accept on the cookie banner. If you click Reject all, none of them load and none of the cookies in this section are set. They help us understand which marketing efforts bring real PTAs to Upfayre, and which parts of the app people find confusing.
- Google Analytics 4 — counts visits, sign-ups, and which links are clicked. Aggregated, not used to identify you personally.
- Meta Pixel — lets Facebook tell us when a click on one of our ads turned into a sign-up. Only fires for visitors who came in from a Facebook/Instagram ad link.
- Contentsquare — anonymised session recordings and heatmaps so we can see where the app gets in your way. Form inputs are masked by default. Used in aggregate.
The cookies those tools set once you accept, and the security cookies our network provider may set regardless:
| Cookie name | Purpose | Duration |
|---|---|---|
| _ga, _ga_* | Google Analytics 4: distinguishes visitors and sessions so visits and sign-ups can be counted in aggregate. | Up to 2 years |
| _fbp, _fbc | Meta Pixel: identifies the browser to Meta and, if you arrived from a Meta ad, records the click, so Meta can tell us an ad led to a sign-up. | 90 days |
| _cs_id, _cs_s, _cs_c | Contentsquare: identifies the visitor and session for anonymised session recordings and heatmaps, and remembers your consent state. | Up to 13 months (session cookie: 30 minutes) |
| __cf_bm, cf_clearance | Set by Cloudflare, which protects the site against bots and attacks. Security cookies that don't identify you; they can appear whether or not you accept analytics. | 30 minutes / up to 1 year |
4. Can I disable cookies?
The session cookie is essential — without it you cannot sign in or use any authenticated part
of Upfayre. The two attribution cookies (_upf_vid and _upf_attr) are
set only if you arrive via a tagged marketing link, and you can clear or block them at any time
via your browser without losing any functionality.
The third-party analytics tools (section 3) only load if you accept the cookie banner. You can
change your mind at any time by clearing the cookie_consent cookie via your
browser — the next page load will show the banner again.
If you'd like the attribution we've stored against your account deleted after sign-up, contact us using the link in section 6 — we'll remove it within one month.
5. Changes to this policy
If we ever introduce new cookies — for example, if we add an analytics tool — we will update this page and notify registered users by email before the change takes effect.
6. Contact us
Questions about our use of cookies? Email us at [email protected] or use the contact form.
For more detail on how we handle your personal data more broadly, see our Privacy Policy.