Last updated: 22 July 2026

Cookie & Storage Notice

This notice explains everything FoodCore stores on your device — the cookies used by our website, and the data the FoodCore app keeps in your browser so it can work offline. It covers why each thing is there, whether you can turn it off, and how to clear it. It is required under the UK Privacy and Electronic Communications Regulations (PECR) and UK GDPR. The same practices apply to all visitors and customers, including those based in the United States.

There are two different things covered here, and it helps to keep them apart:

  • The marketing websitefoodcore.io, the pages you are reading now. This is where cookies and analytics live (sections 1–3).
  • The FoodCore app — your own instance, for example yourbakery.foodcore.io, where you actually run your kitchen. The app stores things on your device so it keeps working when the signal drops (section 4).
You can change this at any time using the buttons.
What changed in this update — 22 July 2026

The FoodCore app now has an offline mode, so it keeps working when the wi-fi in the kitchen drops out. To do that it has to keep a copy of some of your data in the browser on your device. That is a real change to what sits on your tablet or laptop, so we have rewritten this page to cover it properly — and renamed it from "Cookie Policy" to "Cookie & Storage Notice", because cookies are now only part of the story.

In short: the app now caches your recipes, ingredients and label templates on the device. It deliberately does not cache customers, orders, receipts, staff rota or scanned receipt images. Logging out wipes the offline copy. Full detail is in section 4.

Nothing changed about the website cookies in sections 1–3, and your existing consent choice still stands.

1. Cookies, and the Other Things Browsers Store

Cookies are small text files stored on your device when you visit a website. They allow the site to remember information about your visit — such as your preferences or login state — and can help us understand how visitors use the site so we can improve it.

Modern browsers also offer software a few other places to keep things on your device. We use three of them in the FoodCore app, and they are all described in section 4:

  • localStorage — a small notepad for short pieces of text, like which site you last had open. It stays until something clears it.
  • IndexedDB — a proper little database in the browser. This is where the app keeps the offline copy of your recipes.
  • Cache Storage — where the app's own files (the screens, buttons and code) are kept so the app can load with no internet.

None of these are cookies in the technical sense, but they all put something on your device, so we treat them the same way here: we list them, and we tell you how to get rid of them.

2. Cookies on the FoodCore Website

We use two categories of cookies: essential cookies (which do not require consent under PECR) and analytics & marketing cookies (which require your consent). Analytics cookies include those set by Google Analytics 4, PostHog (visitor analytics, session recordings, and heatmaps), Google Ads, Endorsely, Tawk.to, and Sender.net.

Essential cookies — no consent required

Name What it is Purpose Essential? How long it lasts
fc_cookie First-party, localStorage Remembers your cookie consent choice ("all" or "essential") so we do not show the consent banner on every page visit. Contains no personal data. Yes 1 year
Session / auth cookies First-party, HTTP-only Required for logged-in users of the FoodCore.io application to maintain their authenticated session. Without this the app cannot function. Yes Session (cleared on browser close)

Analytics & marketing cookies — consent required

These cookies are only placed if you click "Accept all" on the cookie banner. If you select "Essential only", none of these cookies are set.

Name What it is Purpose Essential? How long it lasts
Google Analytics 4
_ga, _gid, _gat
Third-party (Google) Collects anonymised data about how visitors use the website — pages visited, session duration, referral source. Helps us understand which content is useful. No personally identifiable information is collected. Property ID: G-EJJZYBXJYE. No — only set if you accept _ga: 2 years; _gid: 24 hours; _gat: 1 minute
PostHog
ph_*, posthog_session
Third-party (PostHog, EU) Visitor analytics, session recording, and heatmaps. PostHog records how visitors interact with the website — pages visited, scroll depth, click patterns, and session replays — to help us identify where visitors drop off and improve the site experience. No passwords, payment card numbers, or personal account data are captured in recordings. Hosted on PostHog EU infrastructure. No — only set if you accept Session / up to 1 year
Google Ads
_gcl_aw, _gcl_au
Third-party (Google) Conversion tracking — records when a visitor completes an action (such as signing up for a trial) after clicking a Google Ad. Used to measure the effectiveness of our advertising. Account ID: AW-724508800. No — only set if you accept 90 days
Endorsely Third-party (Endorsely) Affiliate link management widget. May inject product recommendations into blog content and sets a cookie to track affiliate click-throughs from this website. Widget ID: c6520aa8-78a9-4c33-ae04-357e7b4b9809. No — only set if you accept Up to 30 days
Tawk.to
TawkConnectionTime, ss
Third-party (Tawk.to) Live chat widget that loads on all pages of the website. Stores your chat session, conversation history, and chat preferences so you don't lose your conversation if you navigate between pages. No — only set if you accept Session / up to 6 months
Sender.net Third-party (Sender.net) Email marketing platform. Sets a cookie related to newsletter signup form preferences and tracking email engagement (open / click events) for subscribers. Account: ad6083267e6001. No — only set if you accept Up to 1 year

3. AI Checks and Payment Pages

AI Checks: The FoodCore AI Checks feature does not introduce any additional cookies or client-side tracking beyond those already listed above. When an AI Check is run, structured recipe data is transmitted server-side to Anthropic’s API — this does not involve any new browser cookies.

Credit top-up payments (Stripe): When you purchase additional AI Check credits, you are directed to a Stripe-hosted payment page. Stripe’s payment pages operate under their own cookie policy during the checkout flow — see stripe.com/gb/cookie-settings for details. FoodCore does not set any additional cookies as part of this process.

4. What the FoodCore App Stores on Your Device

Everything above is about the marketing website. This section is about the FoodCore app itself — your own instance, for example yourbakery.foodcore.io, the one you log into to cost recipes and print labels.

The app has an offline mode. Kitchen wi-fi is unreliable, walk-in fridges are basically Faraday cages, and market stalls often have no signal at all — so the app is built to keep working without a connection. That only works if it keeps a copy of certain things on your device. Here is exactly what it keeps, and why.

4.1 The app's own files (service worker + Cache Storage)

The app registers a service worker — a small piece of the app that the browser keeps around in the background. Its job is to make sure that once you have opened the app online at least once, it will still open with no signal at all.

To do that it saves the app's own HTML, JavaScript and CSS — the screens, the buttons, the code that makes it all work — into the browser's Cache Storage. This is strictly functional. It is not analytics, it is not advertising, and it contains none of your business data: it is the app's own furniture, not what you keep in it.

4.2 The offline mirror (IndexedDB) — and what we deliberately leave out

So that you can actually use the app offline, and not just load an empty shell, the app keeps a copy of some of your data in IndexedDB — a small database inside your browser. We call this the offline mirror.

The offline mirror holds only three things:

  • Your recipes
  • Your ingredients
  • Your label templates

It does NOT hold: customers, orders, receipts, staff rota, or scanned receipt images. None of those are ever written to your device.

This is an allow-list, not a block-list. Only the three things named above are cached. If we add a new type of data to FoodCore tomorrow, it is not cached on your device unless somebody deliberately adds it to that list. Nothing gets swept into the offline mirror by accident.

Why we drew the line there. Data sitting in a browser cannot be meaningfully protected against somebody who is holding an unlocked, shared tablet — if the device is open, the data is open, and encrypting it on the device does not change that. So rather than try to protect your customer list on the device, we simply never put your customer list on the device.

What that means in practice. If a bakery tablet is lost or stolen, what is exposed is your recipes and label templates. That is commercially sensitive — it is your intellectual property, and we are not pretending otherwise — but it is not personal data. No customer's name, address, phone number or dietary information is on that device, because it was never put there.

4.3 Everything the app stores, itemised

The app uses localStorage for a handful of small settings, plus the two storage areas described above. Here is the full list.

Name What it is Purpose Essential? How long it lasts
Session token First-party, localStorage Keeps you logged in as you move around the app, so you are not asked for your password on every screen. Yes — the app cannot work without it Until you log out, or the session expires (see 4.6)
Menu preferences First-party, localStorage Remembers how you like the app's menus set up, so it looks the same next time you open it. No — convenience only Until you clear your browser's site data
Sidebar state First-party, localStorage Remembers whether you had the sidebar expanded or collapsed. Handy on a small kitchen tablet where screen space is tight. No — convenience only Until you clear your browser's site data
Dismissed announcements First-party, localStorage Records which in-app notices you have already closed, so we do not show you the same message over and over. No — convenience only Until you clear your browser's site data
Active site First-party, localStorage Remembers which of your sites you were last working in, so you land back in the right kitchen if you run more than one. No — convenience only Until you clear your browser's site data
fc_dt First-party device token Fraud and abuse prevention — for example, spotting repeated free-trial signups coming from the same device. Not used for advertising, not sold, and not used to build a marketing profile. See 4.4 below, where we explain it properly. Yes — security and abuse prevention Stays on the device until you clear your browser's site data. Logging out does not remove it.
Offline mirror First-party, IndexedDB A copy of your recipes, ingredients and label templates so you can keep working with no signal. Never includes customers, orders, receipts, staff rota or scanned receipt images. Only if you want offline mode Until you log out, or you clear your browser's site data
Cached app files First-party, Cache Storage (service worker) The app's own HTML, JavaScript and CSS, saved so the app opens with no internet connection. Contains none of your business data. Yes — this is what makes offline mode possible Until you log out, or you clear your browser's site data

4.4 fc_dt — the device token, explained honestly

We could have left this one buried in a table, but it deserves a straight explanation, because on paper it looks like the kind of thing people are right to be suspicious of.

What it is. fc_dt is a device token. It is created when you sign up and it stays on that device. It is a random identifier — it does not contain your name, your email or anything about your business — but it does mean the same browser on the same device can be recognised as the same device later.

Why it exists. Fraud and abuse prevention. The clearest example: FoodCore offers a free trial, and without something like this, one person can take an unlimited number of free trials from the same laptop under different email addresses. fc_dt lets us notice that pattern.

Being upfront about the obvious objection. Yes — this is a persistent identifier on your device, and persistent identifiers are exactly what advertising trackers are. So we want to be specific about what we do not do with it. fc_dt is not used for advertising. It is not sold or shared with data brokers or ad networks. It is not used to build a marketing profile of you, and it is not used to follow you around other websites. It does one job: telling our own abuse checks whether it has seen this device before.

It survives logging out. That is deliberate — a token that vanished the moment somebody logged out would be useless for the job it exists to do. If you want it gone, clear your browser's site data for the app (see section 5).

4.5 What logging out clears — and what survives

This matters most on a shared device: the tablet on the bench that four people use across a shift. When you explicitly log out, the app clears all three of these:

  • The session token — you are signed out.
  • The offline mirror in IndexedDB — your recipes, ingredients and label templates are wiped from the device.
  • The service worker's caches — the stored copies of the app's own files.

In other words, logging out does not just sign you out, it takes your data back off the device. If you are handing a tablet to the next shift, or selling an old one, log out.

What logging out does not clear. The fc_dt device token stays — as explained in 4.4, surviving logout is the whole point of it. Small local preferences such as your menu settings and sidebar state may also remain. To remove absolutely everything, clear the site data in your browser (section 5).

4.6 Installed app vs browser tab (and a note for iPhone and iPad)

On iPhone and iPad, Safari tidies up after itself: if you have not used a website in a browser tab for roughly a week, it clears that site's stored data. An app that has been installed to the home screen is exempt from that clear-out.

What this means for you. If you rely on offline mode on an iPad — say at a weekend market where there is no signal — add FoodCore to your home screen. Used as an installed app, your offline recipes stay available. Used in an ordinary Safari tab that you only open occasionally, the offline copy may simply not be there when you need it. And it works both ways: if you want the data gone from a device, logging out removes it straight away, whichever way you use the app.

4.7 A note about sessions and being offline

Sessions expire normally when you are online — that has not changed. But the app will only end your session on a failed token refresh if the device is actually online at the time. A refresh that fails purely because there is no signal is not treated as an expired session, so a dead spot in the kitchen will not throw you out mid-bake.

5. How to Manage Cookies and App Storage

You can change your consent preference at any time using the buttons at the top of this page. Selecting "Essential only" will prevent all analytics and marketing cookies from being set.

You can also manage or delete cookies through your browser settings. Most browsers allow you to view, block, and delete cookies. Note that blocking all cookies may affect the functionality of some websites.

To opt out of Google Analytics tracking specifically (across all websites), you can install the Google Analytics Opt-out Browser Add-on. To opt out of personalised Google Ads, visit Google Ads Settings.

Clearing what the FoodCore app has stored

There are two ways, and they do different amounts of work.

  • Log out of the app. This is the everyday option, and the one to use when handing a device to someone else. It clears your session, the offline mirror of your recipes, ingredients and label templates, and the app's cached files. It does not remove the fc_dt device token.
  • Clear the site data in your browser. This is the thorough option and removes everything, including fc_dt and your saved preferences. In most browsers this lives under Settings → Privacy → Cookies and site data, where you can clear data for a single site. The same browser guides linked above cover it. If you use FoodCore installed to your home screen on an iPhone or iPad, deleting the installed app removes its stored data too.

Clearing site data will take the app offline-unready until the next time you open it with a connection — it needs one online visit to rebuild its cache. Nothing in your FoodCore account is deleted by any of this; your recipes and data remain safe on our servers and reappear when you log back in.

6. Changes to This Notice

We may update this notice if we change the cookies we use, add new third-party services, or change what the app stores on your device. The date at the top of this page reflects the most recent revision. Material changes will be communicated via the cookie consent banner on your next visit.

7. Contact

If you have questions about cookies or about what the app stores on your device, please contact us at info@foodcore.io.