legal
Cookie Policy
What CallHQ stores on your device. The list is short, and every item on it is there because something you asked for would not work otherwise.
Version 1.0 · last updated 2026-08-09
Draft — not yet in force
These documents are complete in substance but still need 9 facts only the operator can supply: registered legal entity, company number, registered office address, privacy contact address, security contact address, support contact address, ICO registration number, governing law, hosting region. Until those are filled in and a solicitor has reviewed them, do not rely on this page or present it to a customer.
The short version
CallHQ sets no cookies at all until you either sign in or start a support conversation. An anonymous visitor reading the marketing site receives none.
There are no analytics, no advertising pixels, no tag manager, no session recording, and no third-party trackers of any kind. Not as a policy position we might revisit quietly — there is no such code in the product.
What we actually store
| Name | Type | What it does | Lasts |
|---|---|---|---|
| authjs.session-token | Cookie | Keeps you signed in. Set only after you log in. | Until you sign out or it expires |
| authjs.csrf-token | Cookie | Protects sign-in and form submissions against cross-site request forgery. | Session |
| authjs.callback-url | Cookie | Returns you to the page you were trying to reach after signing in. | Session |
| callhq_chat_session_id | Local storage | Threads your support conversation together so replies land in the same thread. Written only when you actually send a message — not on page load. | Until you clear site data |
All four are strictly necessary. There is no optional category, which is why there is nothing to toggle.
What we do not do
- No Google Analytics, Tag Manager, or any analytics product.
- No advertising or conversion pixels — no Meta, LinkedIn, Google Ads or otherwise.
- No session recording or heatmapping.
- No cross-site tracking, and no sharing of your browsing with anyone.
- No fingerprinting used as a substitute for cookies.
If this changes
If we ever add analytics or anything else that is not strictly necessary, we will ask for consent before it runs, with a real accept-or-reject choice where rejecting is exactly as easy as accepting, and this page will be updated first.
The mechanism for that is already built and switched off. It is not a promise to write some code later; the notice component reads a register of non-essential storage, and that register is currently empty. The day something is added to it, the notice becomes a consent gate on its own.
Managing storage yourself
You can clear or block cookies and local storage in your browser settings at any time. Blocking the session cookie will stop you being able to sign in — that is the trade-off with a strictly-necessary cookie, and it is why the exemption exists.
For anything else about data we hold, see the Privacy Policy.