Cookie Policy
1. About this policy
This Cookie Policy explains how Innostack Limited (“Innostack”, “we”, “us”) uses cookies and similar technologies on our websites at www.innostack.co and www.innostack-hub.com (the “Websites”).
Innostack Limited is registered in Ireland, company registration number 793621, registered office 56 Bramble Avenue, Castleoaks, Carlow, Co. Carlow, R93 F9NF, Ireland. We are the controller for personal data collected through cookies on our own Websites.
Contact: privacy@innostack.co
This policy should be read together with our Privacy Policy at innostack.co/privacy, which explains how we handle personal data generally and sets out your rights in full. Where this policy covers cookies specifically, the Privacy Policy governs everything else.
What this policy does not cover
We build and host websites for clients. If you are visiting a website we built for one of our clients, this policy does not apply to it. That client decides what cookies their site sets and is the controller for them. Their own cookie and privacy policies apply, and questions should go to them. If you are not sure, ask us at privacy@innostack.co and we will tell you whose site you are on.
Your choices come first
Right now, every cookie we set is strictly necessary — to run the Websites, keep them secure, sign you in to the client portal, and remember your cookie choice. None of these requires your consent, and we set nothing that does.
We do not currently use analytics, advertising or any other non-essential cookies. We plan to introduce analytics in future; if we do, it will be set only after you opt in, and we will update this policy to name each cookie before any is placed on your device. You can review your choice at any time — see section 7.
2. What cookies and similar technologies are
Cookies are small text files placed on your computer, tablet or phone when you visit a website. They let a site recognise your device and remember information between visits or between pages.
We also use technologies that work similarly:
- Local storage and session storage — browser storage mechanisms that hold information on your device. Session storage is cleared when you close the tab.
In this policy, “cookies” includes these technologies unless we say otherwise. The law treats them the same way: what matters is that information is stored on, or read from, your device — not the technical format.
Cookies are described as:
- First-party — set by us. Third-party — set by another organisation whose service we use.
- Session — deleted when you close your browser. Persistent — remain for a set period or until deleted.
3. What we do not use
For transparency, and so you do not have to wonder:
- No advertising, retargeting or cross-site tracking cookies
- No device fingerprinting
- No session replay or screen recording
- No Flash cookies (Local Shared Objects) — we do not use Adobe Flash
- No social media tracking pixels
- No tag manager container — we do not use Google Tag Manager or any tag-management container. If we add analytics, its tag will be loaded directly by the site and only after you opt in, so it cannot fire beforehand.
If we introduce any of these, we will update this policy and, where the technology is non-essential, obtain your consent before it is used.
4. The law, and our lawful basis
Our use of cookies is governed by two sets of rules working together. They are separate, and we set them out separately because they do different jobs.
4.1 Storing and reading cookies — the ePrivacy Regulations
The European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 (S.I. No. 336 of 2011) transpose the ePrivacy Directive into Irish law.
- Regulation 5(3) — we may only store information on, or access information stored on, your device with your consent, and after giving you clear and comprehensive information.
- Regulation 5(5) — consent is not required for cookies whose sole purpose is carrying out a transmission over a network, or which are strictly necessary to provide a service you have specifically requested.
The strictly-necessary exemption is narrow. The Data Protection Commission has been explicit that it covers only what is genuinely essential to deliver what you asked for. Cookies that are merely useful to us do not qualify — and analytics never does, however aggregated the results.
4.2 The personal data inside — the GDPR
Where a cookie also involves processing your personal data, we need a lawful basis under Article 6 GDPR:
| Cookie category | ePrivacy position | GDPR lawful basis |
|---|---|---|
| Strictly necessary | Exempt from consent under Reg 5(5) | Legitimate interests, Art 6(1)(f) — operating a secure, functioning website and portal |
| Functional | Consent required, Reg 5(3) | Consent, Art 6(1)(a) |
| Analytics | Consent required, Reg 5(3) | Consent, Art 6(1)(a) |
At present we set only strictly-necessary cookies. The functional and analytics rows describe how we would treat those categories if and when we introduce them.
4.3 What valid consent means
If and when we rely on consent — which will be for analytics, once it is introduced — it will meet the Article 4(11) GDPR standard:
- Freely given — you can use our Websites fully whether or not you accept non-essential cookies. Nothing is withheld if you decline.
- Specific — each category is a separate choice, not one bundled switch.
- Informed — this policy and the banner explain what each category does before you decide.
- Unambiguous — given by a clear affirmative action.
We do not use pre-ticked boxes, and we do not treat scrolling or continued browsing as consent. Rejecting is as easy as accepting, and both options are presented with equal prominence.
4.4 Special category data
We do not use cookies to collect special category data — health, biometrics, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation — as defined in Article 9 GDPR.
5. The cookies we use
Every cookie we currently set is strictly necessary, and is listed below. We do not set any analytics or other non-essential cookies at this time.
Set on both Websites
| Cookie / storage key | Provider | Type | Purpose | Duration |
|---|---|---|---|---|
__cf_bm | Cloudflare, Inc. | HTTP cookie | Distinguishes human visitors from automated traffic, protecting the Websites from bots and abuse. A separate cookie is generated for each site; it is not used to track you between sites. | Approx. 30 minutes |
cf_clearance | Cloudflare, Inc. | HTTP cookie | Records that you have passed a security challenge so you are not repeatedly challenged. Set only where a challenge is presented. | Approx. 30 minutes |
cookieConsent | Innostack | Local storage | Stores your cookie choice, and the version of this policy it was given against, so we do not ask on every visit | Re-asked after 12 months |
Set only when you sign in to the client portal (innostack-hub.com)
These authenticate your session on our client portal. They are set only if you sign in, and the HTTP cookies among them are httpOnly — they cannot be read by JavaScript.
| Cookie / storage key | Provider | Type | Purpose | Duration |
|---|---|---|---|---|
__Host-sso_access_token | Innostack | HTTP cookie | Holds the single sign-on access token that authenticates your session | 15 minutes |
__Host-sso_refresh_token | Innostack | HTTP cookie | Renews your access token so you are not signed out mid-session | Approx. 8 hours |
__Host-portal_sid | Innostack | HTTP cookie | Sealed session identifier for the OpenID Connect (OIDC) login | 8 hours |
__Host-portal_idtoken | Innostack | HTTP cookie | Stores the OIDC ID token for your session | 8 hours |
__Host-portal_txn | Innostack | HTTP cookie | Protects a login transaction while it is in progress | 10 minutes |
ist_sess | Innostack | HTTP cookie | Session hint — signals that a session may exist | 8 hours |
accessToken | Innostack | Local storage | The token the portal uses to call our API on your behalf while you are signed in | Until you sign out |
| Silent-authentication marker | Innostack | Session storage | A guard used by the sign-in flow to re-authenticate you quietly. Not analytics. | Cleared when the tab closes |
Analytics — not currently used
We do not set any analytics cookies at present. We plan to introduce analytics. When we do, it will sit in a separate “analytics” category, will be set only after you opt in, and we will update this policy to name each analytics cookie — with its provider, purpose and duration — before any is placed on your device.
Functional, marketing and advertising
None. We set no functional, marketing or advertising cookies. See section 3.
Notes on the table
No tag manager. We do not use Google Tag Manager or any other tag-management container. Any future analytics tag will be loaded directly by the Websites, and only after you opt in.
Cloudflare cookies are treated as strictly necessary because they are required to keep the Websites secure and available — part of delivering the service you requested.
No payment cookies. We do not take payments through our Websites. Where you pay us, we send a payment link and the transaction happens on our payment provider’s own pages, under their notices. No payment-provider cookies are set on our Websites.
The specific cookies set may vary depending on which pages you visit and whether you sign in to the portal. Our cookie settings panel always reflects what is actually in use.
6. Third parties and international transfers
Some cookies on our Websites are set by a provider whose service we use. It processes information under its own privacy notice, which we recommend reviewing.
| Provider | What they do | Where they process |
|---|---|---|
| Cloudflare, Inc. | Security, bot protection and content delivery for our Websites | Global edge network |
We do not currently set any third-party analytics cookies. When we introduce analytics (see section 5), the provider and each of its cookies will be added here, and set only after you opt in.
Other providers we use in running our business — including our payment provider and our email host — do not set cookies on our Websites, so they do not appear here. They are listed in our Privacy Policy.
International transfers. Cloudflare operates a global edge network, so information may be processed outside the European Economic Area, including in the United States. Where that happens, transfers are protected by appropriate safeguards under Article 46 GDPR — ordinarily the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914), together with technical and organisational measures, and, where the provider is certified, the EU–US Data Privacy Framework.
Our own infrastructure is in Ireland — we own and operate our servers in Carlow. Further detail on transfers is in our Privacy Policy.
7. Managing your cookies
7.1 Our cookie settings
Our cookie settings let you accept or reject non-essential cookies by category. We currently set only strictly-necessary cookies, so there is nothing non-essential to turn on or off yet; these controls will govern analytics once we introduce it. You can open them at any time through the cookie settings link on our Websites.
7.2 Your browser
Most browsers let you view, delete and block cookies:
- Chrome — Settings → Privacy and security → Third-party cookies
- Firefox — Settings → Privacy & Security → Cookies and Site Data
- Safari — Settings → Privacy → Manage Website Data
- Edge — Settings → Cookies and site permissions
Browser settings apply to every website, not just ours.
7.3 If you block cookies
Blocking strictly necessary cookies may stop parts of our Websites working — signing in to the client portal and our security protections in particular — and we will not be able to remember your cookie choice, so you may be asked again. We do not currently set analytics or other non-essential cookies, so there is nothing else to block; if we add them in future, they will be optional and off until you opt in.
7.4 Do Not Track and Global Privacy Control
Some browsers send a “Do Not Track” (DNT) or “Global Privacy Control” (GPC) signal. There is no agreed legal or industry standard requiring a website to respond to these in a particular way, and we do not currently act on them automatically. Our Websites respond to the choices you make in our cookie settings. You can control any non-essential cookie there, and through your browser settings.
8. Consent and withdrawal
We record any cookie choice you make — the date, the categories accepted or rejected, and the version of this policy in force at the time — so that we can honour it and demonstrate it was given, as Article 7(1) GDPR requires. That choice is held in the cookieConsent item described in section 5.
Withdrawing is as easy as giving (Article 7(3) GDPR). Use the cookie settings link, or your browser controls. Withdrawal does not affect the lawfulness of anything done before you withdrew. Once withdrawn, we stop setting cookies in that category and delete existing ones where technically possible.
We will ask again periodically. We ask you to confirm your preferences again after 12 months, so your choice stays current, and sooner if we make a material change to the cookies we use.
9. Your rights
Where cookies process your personal data, you have the full set of GDPR rights — access, rectification, erasure, restriction, portability and objection. These are set out in detail in our Privacy Policy, along with how to exercise them and our response times.
Specific to cookies, you may:
- withdraw consent at any time for any cookie set on that basis (section 8);
- object to processing based on our legitimate interests — though we cannot disable cookies strictly necessary to provide the Websites and portal; and
- ask what cookies we set, their purpose, duration, and whether they are first- or third-party.
Exercising these rights is free. Contact privacy@innostack.co.
10. Changes to this policy
We update this policy when the cookies we use change, or for operational, legal or regulatory reasons. The version number and date at the top show which version you are reading.
Where a change is material — including when we introduce analytics — we will bring it to your attention, by notice on the Websites or by asking you to review your cookie preferences.
11. Contact and complaints
Questions about this policy or our cookies: privacy@innostack.co
Post: Innostack Limited, 56 Bramble Avenue, Castleoaks, Carlow, Co. Carlow, R93 F9NF, Ireland
We would welcome the chance to resolve any concern first. You also have the right to complain to the Irish supervisory authority:
6 Pembroke Row, Dublin 2, D02 X963, Ireland
www.dataprotection.ie · Telephone (01) 765 0100
The DPC does not have a public counter and does not accept complaints by telephone — complaints are made through the contact form on its website.
This policy is provided in English, which is the governing language for its interpretation. It is governed by Irish law.