Cookie notice

Last updated 14 August 2026 · version 2026-08-14

The cookie that signs you in and cannot be refused, the analytics cookies that run only if you agree, and how to change your mind.

UnitOps uses two kinds of cookie, and the difference between them is the whole of this page. One signs you in and you cannot turn it off. The other counts visits to the public pages, runs only if you say yes, and can be turned off again at any time. There is no advertising, no profiling, and nothing that follows you around other websites.

1. The short version

Signing you in — always on
One cookie, set by UnitOps itself. Without it you cannot sign in at all, so you are not asked about it. Details in section 2.
Counting visits — cookies only if you agree
Google Analytics, on the public pages only: this one, the sales page, the sign-in form and the other two legal documents. Its cookies are set only if you agree. If you refuse, or never answer, the visit is still counted — anonymously and without any cookie, which is a real distinction and section 3 explains it rather than glossing it.
Behind the login — nothing extra, ever
Once you are signed in, the only cookie in play is the one that signed you in. Analytics does not run on any page inside the application. Section 4 says why, and it is a decision about your customers' data rather than about your privacy.

2. The cookie that signs you in

PHPSESSID — strictly necessary, cannot be refused
What it does: identifies your session on the server, so that every page you open knows you are signed in and which company you are working in. It holds a random identifier and nothing else — no name, no email address, nothing readable.
How long it lasts: until you close the browser, or until the session expires after a period of inactivity (two hours by default), whichever comes first. Signing out ends it immediately.
Who sets it: UnitOps, on its own domain. It is a first-party cookie and no other company can read it.

You are not asked to consent to this one, and that is not an oversight. Consent is required for cookies that are not strictly necessary; it is not required for one that exists solely to carry out the thing you asked for, and a cookie that remembers you have signed in is the textbook example of that, under regulation 6(4) of the Privacy and Electronic Communications Regulations 2003. What the law does require is that we tell you it is there, which is what this section is.

Blocking it makes signing in impossible. Not awkward — impossible: the sign-in page will accept your password and then return you to the sign-in page, because there is nothing to remember you by. This is not a fault, and it is why the cookie is described as strictly necessary.

3. Counting visits to the public pages

We use Google Analytics to see how many people reach the public pages, which ones they read, and how many arrive and leave again without going further. It tells us whether the sales page is doing its job.

There are two levels to this, and the difference between them is what you are being asked about.

Counted anonymously — happens either way
When you open one of the public pages, your browser tells Google that a page was viewed. That message carries the address of the page, the site you arrived from, and the IP address the request came from. It sets no cookie, reads nothing from your device, and leaves nothing behind — the next page you open is a separate, unconnected message, so it cannot be joined up into a picture of you or followed to another site.
Measured properly — only if you agree
If you press Yes, that's fine, Google Analytics also sets the cookies listed below. Those let one visit be recognised as one visit across several pages, which is what turns a pile of anonymous page views into visitor numbers. This is the part that needs your permission, and it is the part you can withdraw.

Why it works that way, said plainly. The law that governs cookies governs storing things on your device, which is why the cookies wait for your permission and why we are not pretending otherwise. The anonymous count stores nothing, so it is not covered by that law — but it is still your IP address going to Google, so you should know it happens. We do it because the one question analytics exists to answer here is how many people bounce off the sales page, and the visitors who bounce are exactly the ones who leave before answering a banner. Measuring only the people who stopped to say yes would have measured the wrong crowd and flattered the result.

Refusing costs you nothing: every page works identically either way, no cookie is set, nothing about you is stored, and you will not be asked again unless you clear your browser storage. The strip that asks puts No thanks and Yes, that's fine side by side, the same size, because refusing should be no harder than accepting.

What it sets, if you agree

_ga
Distinguishes one browser from another so that two visits from you are not counted as two people. Contains a randomly generated identifier. Lasts 2 years.
_ga_E1P1B8QSX7 (the property counter)
Keeps the state of the current visit — when it started, how many pages in you are. Lasts 2 years.
_gid, and _gat variants
Older-style session and rate-limiting cookies that Google may still set alongside the two above. Lasts 24 hours or less.

What Google is told

The first two apply to the anonymous count as well. The rest need the cookies, and so need your agreement.

  • The address of the public page you looked at, when, the page you arrived from, and general information about your browser, device and approximate location.
  • With your agreement: how long you stayed, which pages you moved between, and whether you had been here before.
  • Not your IP address in full. IP anonymisation is switched on, so the address is truncated before it is stored.
  • Nothing that identifies you personally, and nothing from inside the application — no name, no email address, no client record, no booking, no invoice. See section 4.
  • Nothing for advertising. Google's advertising features, remarketing and personalisation signals are switched off explicitly rather than left at their defaults, so the data cannot be used to build an advertising profile of you.

Google acts as our processor for this and is based in the United States, so both the anonymous count and the measured version involve a transfer outside the UK, made under the safeguards described in the privacy notice. Google publishes its own terms at business.safety.google/privacy.

If you would rather Google saw nothing at all, a tracker blocker or a browser that blocks third-party requests will stop both levels of this, and UnitOps will work exactly as it does now. We would rather say that than have you find it out somewhere else.

4. Why analytics stops at the login

Analytics runs on the public pages and on none of the pages inside UnitOps. That is a deliberate limit, and the reason is your customers rather than you.

Google Analytics records the address of every page it runs on. Inside the application those addresses are not anonymous — they carry record identifiers, and a page title can name a client or a member of staff. Switching it on behind the login would send fragments of your business's data to a third party in another country as a side effect of our wanting to know which screen is popular, and no customer of ours agreed to that. So it does not run there, and the decision sits in code rather than in a setting somebody could flip: the list of pages analytics is permitted on is fixed, and every one of them is a page a stranger can already read.

5. Changing your mind

Use the Your choice panel at the top of this page. It shows what you have chosen and lets you change it, in one click, either way — and withdrawing deletes the analytics cookies rather than merely stopping new ones, so nothing is left sitting in your browser afterwards.

Your answer is remembered in your browser's local storage rather than in a cookie — a cookie banner that sets a cookie to remember you have read it is not a good look. It is one word, it never leaves your browser, and clearing your browsing data clears it, after which you will be asked again.

You can also block or delete cookies in your browser's own privacy settings. That works too, with the consequence for the sign-in cookie described in section 2.

6. What else the browser keeps

Cookies are not the only thing a browser stores, and the law treats the rest the same way, so here is the rest of it. All of it is set by UnitOps itself and none of it leaves your browser.

Appearance settings in localStorage — light or dark, menu layout, colours
So the page does not flash the wrong theme while it loads. These are also saved to your account, which is what makes them follow you to a new device; the copy in the browser is the one read before any stylesheet is parsed.
Your analytics answer (unitops.cookie-consent)
One word — whether you agreed or refused — so that you are asked once rather than on every page. See section 5.

7. More

What we do with personal data is in the privacy notice. The agreement your company is on is in the terms of use. Anything else, email the address at the foot of this page.


Who you are dealing with

Trading name
Sweet Pea Software
Registered name
[registered company name]
Company number
[company number]
Registered office
[registered office address]
VAT
Not VAT registered. No VAT is charged on our invoices.
Hosting
[country the hosting is in]
Governing law
England and Wales
Contact
support@sweetpeasoftware.com