Cookie Policy
Settl · Settl · Version 1.0 · Effective 2026-09-19 Part of the Privacy Policy and the Terms of Service. Contact: partners@piedmontaccounting.com
One-line version: this site sets one cookie, and it is the one that keeps you signed in. There is no analytics, no advertising, no tracking pixel, and no third-party content that would see your IP address. We do not use a cookie banner because there is nothing to consent to — see §4 for the reasoning.
1. What a cookie is
A cookie is a small text file that a website asks your browser to store and send back with later requests. Cookies are used to keep a session, remember a preference, or (in the advertising industry) recognise a visitor across sites. This policy covers cookies and the closely related technologies (local storage, session storage, pixels, beacons).
2. What this website and the licensed application actually set
| Name | Type | Set by | Purpose | Data it contains | Lifetime |
|---|---|---|---|---|---|
session |
Strictly necessary | The application (Flask session cookie) | Keeps you signed in; carries the CSRF token that protects forms against cross-site request forgery | A signed, encrypted-or-signed session reference. It does not contain your invoices, your customers, your password, or your provider credentials | 12 hours, or until you sign out or the server invalidates it |
Flags on the session cookie: Secure (only sent over HTTPS), HttpOnly (not readable by
JavaScript), SameSite=Lax (not sent on cross-site form posts, so it also blunts CSRF).
Cookies we do not set: analytics (no Google Analytics, Plausible, Matomo, Hotjar), advertising or retargeting (no Meta, LinkedIn, TikTok pixels), session replay, A/B testing, chat widgets, embedded videos, social buttons, and no third-party CDN that would receive a visitor's IP address for the application's own interface.
Where our data-check-ins are not cookies: a licensed installation contacts our licence service every 6 hours and sends licence identifiers plus counts, and nothing about your customers. That is a server-to-server request, not a cookie, and it is described in the Privacy Policy §3.4.
3. Third-party requests
Currently: none for the application interface. The user interface serves its font files and all images from the same origin as the application (see §6, which records the change that made this true). No request from a page you are viewing goes to a third party for the purpose of displaying that page.
Requests that do leave your browser are the ones you initiate — following a link to a third-party site (for example a payment page you have configured, or a provider's sign-in page during OAuth) — and those sites set their own cookies under their own policies.
4. Do we need a consent banner? (our position, stated plainly)
No, and here is the reasoning, so that it can be checked rather than trusted:
- A consent requirement under the ePrivacy rules (and the equivalent laws built on them) attaches to storing or reading information on a visitor's device that is not strictly necessary for the service the visitor asked for.
- The only cookie this application sets is the session cookie without which sign-in cannot work — it is strictly necessary. There is no preference cookie, no statistics cookie, no marketing cookie.
- A banner that asks for consent to something that does not happen would be a false statement to visitors, and clicking "reject all" could not change any behaviour. Showing it would also imply we process data in ways we do not.
- The one genuine third-party exposure was Google Fonts (
fonts.googleapis.com), which transmits every visitor's IP address to Google and has been challenged in court in the EU. We removed that request by self-hosting the font files (see §6). With the request gone, there is nothing left that needs prior consent. - If any of the above changes — if analytics, a chat widget, an A/B test, an advertising pixel, an external font, a CDN, an embedded video, or any marketing or statistics cookie is ever added to this website or the licensed application — then prior consent becomes necessary and a consent banner must be added before the new tool goes live, with granular opt-in, no pre-ticked boxes, a reject-all path as easy as accept-all, and no cookie set before a choice is made. Section 7 makes that a rule, not an intention.
Because of point 5, this policy is the trigger for building a banner, not a substitute for one. The current position is recorded, dated, in §6 so a future reader can see what was true when.
5. Your controls
- Block or delete cookies in your browser (all major browsers do this in Settings → Privacy). Blocking the session cookie means you cannot sign in — that is the whole extent of the impact.
- Do Not Track / Global Privacy Control. We do not track you across sites, so there is nothing for these signals to switch off; we honour them as a matter of principle.
- Private/incognito window. The session cookie will be discarded when you close the window.
- Sign out. Ends the session immediately; the cookie is cleared.
6. Technical verification log (for the record)
A reader — a client's security reviewer, or a regulator asking — should be able to confirm the statements in §2 and §3. This is how:
| Check | How to confirm it |
|---|---|
| Only one cookie is set by the application | Sign in with the browser developer tools open, on the Network tab, and inspect Set-Cookie on the login response and document.cookie. One session cookie is present |
| No analytics or tracking script | View page source / the Network tab: no request to an analytics, advertising, or third-party font domain; no <script src> pointing off-origin |
| The font is self-hosted | The stylesheet and the font files load from the application's own origin (/static/...), not fonts.googleapis.com |
| No third-party request for the interface | The Network tab of a normal page load shows only same-origin requests |
| The licence check-in is server-to-server and carries no personal data | Privacy Policy §3.4; licensing.build_payload in the delivered image; a network capture on the client's own server shows one outbound request every 6 hours to the configured licence address |
Change record:
| Date | Change |
|---|---|
| 2026-09-19 | This policy first published. The application previously loaded the Inter typeface from Google Fonts (fonts.googleapis.com); the font files are now self-hosted in the application, and the third-party request has been removed. No analytics or tracking technology is present, and none was present before this change either |
7. Rule for anyone changing this website or the application (internal)
Before any of the following is added — analytics, tag manager, heatmap or session-replay tool, chat or support widget, A/B testing, advertising or retargeting pixel, social login button, embedded video or map, external font, external CSS/JS, error-monitoring tool that captures the DOM or session, or any cookie that is not strictly necessary — this checklist must be completed first:
- Choose a lawful basis and confirm what is actually transmitted to the third party.
- Add a consent banner with granular purposes, an accept-all and a reject-all of equal prominence, no pre-ticked boxes, no cookie or script loaded before a choice, and a way to withdraw consent as easily as granting it.
- Update this policy's §2, §3 and §6 before the change goes live.
- Record the third party in the Privacy Policy §4.1 sub-processor table, and confirm the transfer mechanism if data leaves the visitor's jurisdiction.
- If the tool can see personal data of a client's customers, it must not be enabled in a licensed installation at all without a written decision and a client-facing notice.
8. Changes to this policy
We update this policy when our practices change, and change the version and effective date together. We do not retro-fit consent: if a consent-requiring technology is introduced, consent starts being collected from that point, and this document says so.
9. Contact
Questions about cookies, or about anything in this policy: partners@piedmontaccounting.com
Comments