Subprocessors, cookies and tracking
Under a data processing agreement we must tell you before this list changes. It is reviewed quarterly, and adding an entry is a notification to every customer, not a quiet deploy.
Subprocessors
Vercel Inc.
Essential to the serviceApplication hosting, edge routing and TLS termination.
Personal data they can see
- IP address (transient, in request logs)
- Session cookie
- URL requested
- User agent
- Location
- London (lhr1) for compute; log retention in the United States
- Transfer safeguard
- EU/UK Standard Contractual Clauses and the UK Addendum, via Vercel's DPA
Supabase Inc.
Essential to the serviceManaged PostgreSQL database, authentication and session issuance.
Personal data they can see
- Email address
- Hashed password
- Display name
- University and student reference
- Programme and academic year
- Assessment attempts and progress
- Audit records
- Location
- EU/UK region (project-configured)
- Transfer safeguard
- EU/UK Standard Contractual Clauses and the UK Addendum, via Supabase's DPA
Stripe Payments Europe Ltd.
Not required for institutional useCard payment processing for direct individual subscriptions only. Institutional customers are invoiced and their students' data never reaches Stripe.
Personal data they can see
- Email address
- Billing name and address
- Card details (held by Stripe, never by us)
- Location
- Ireland, with group processing in the United States
- Transfer safeguard
- EU/UK Standard Contractual Clauses and the UK Addendum, via Stripe's DPA
Vercel Web Analytics
Not required for institutional useAggregate usage measurement — page views and named product events. Configured without cookies and without cross-site identifiers.
Personal data they can see
- Page path
- Referrer
- Coarse device and country, derived and not stored against an identifier
- Location
- Processed by Vercel, as above
- Transfer safeguard
- Covered by Vercel's DPA
Cookies
There is no cookie banner on this site, and that is a deliberate position rather than an omission. The Privacy and Electronic Communications Regulations require consent for anything that is not strictly necessary for a service the visitor has asked for. Both cookies below are strictly necessary, analytics runs without a cookie or a cross-site identifier, and there are no advertising or marketing pixels. If that ever changes, a banner becomes mandatory and this page will say so before it does.
| Name | Purpose | Duration | Consent |
|---|---|---|---|
| sb-<project>-auth-token | Holds the signed-in session. Without it a student cannot stay signed in between pages, so it is strictly necessary for a service they have asked for. | Session, refreshed on use; expires after inactivity | Not required |
| ba_signed_in | A flag stating only that somebody is signed in, so statically cached pages can skip an entitlement request for the anonymous majority. Carries no identity and no entitlement. | 30 days | Not required |
| ba:last-visit-day | One date, so a return visit is counted once a day rather than once a page. Never leaves the browser as an identifier. | Until cleared by the user | Not required |
The last two entries are browser storage rather than cookies. They are listed because the Regulations cover storage on a device generally, not cookies specifically, and neither value ever leaves the browser.
