1. What this policy covers
"Cookies" here means every technology that stores or reads information on your device: HTTP cookies, localStorage and sessionStorage (used, for example, to remember your cookie choices and appearance preferences), pixels, tags and scripts. The law treats them all the same way, and so do we. This policy explains what we use, why, for how long, and how you stay in control. How we handle personal data generally is in the Privacy Policy.
2. The law on cookies (UK)
In the UK, storing or accessing information on your device requires your consent unless an exemption applies — the main one being cookies that are strictly necessary for a service you have asked for.
The DUAA added new consent exemptions to PECR (for example, purely statistical audience measurement with a clear notice and a simple opt-out, and cookies that adapt the site's appearance to your preferences). Our position is stricter than the law requires: we continue to load analytics — including Microsoft Clarity — only with your opt-in consent, because session-level usability analytics goes beyond bare statistics and you should choose it, not inherit it.
3. Your choices — how the banner works
- On your first visit the banner offers Accept all, Reject all and granular category toggles — with equal prominence, and no pre-ticked optional categories.
- Four categories: Strictly Necessary (always on — the site cannot work without them), Preferences, Analytics and Performance, and Marketing and Advertising.
- Your choice is stored locally (see the table below) and as a hashed consent record so we can prove how consent was given (UK GDPR Article 7(1)).
- Withdrawing is one click: the "Privacy choices" control on every page reopens the preference centre; switching a category off stops its scripts on the next page view and deletes its cookies immediately.
4. The cookies and storage we use
4.1 Strictly necessary — always on
| Name | Set by | Purpose | Duration |
|---|---|---|---|
laravel_session | Dogetlawyer (first-party) | Keeps you logged in and your session secure | Session |
XSRF-TOKEN | Dogetlawyer (first-party) | Protects forms against cross-site request forgery | Session |
remember_web_… | Dogetlawyer (first-party) | "Remember me" login, only if you tick it | Up to 12 months |
privacy_consent_v1 (localStorage) | Dogetlawyer (first-party) | Remembers your cookie choices | 12 months |
4.2 Preferences — only with your consent
| Name | Set by | Purpose | Duration |
|---|---|---|---|
locale | Dogetlawyer (first-party) | Remembers your chosen language | 12 months |
dash_theme | Dogetlawyer (first-party) | Remembers light/dark mode | 12 months |
| Feature preferences (localStorage) | Dogetlawyer (first-party) | Remembers in-app appearance settings you choose (for example chat appearance and text size) | Until you clear them |
4.3 Analytics and Performance — only with your consent
Currently Microsoft Clarity (heatmaps and masked session replays — see section 5). Google Analytics 4 cookies load only if we have analytics configured and you consent; if we enable it we will list it here first.
| Name | Set by | Purpose | Typical duration* |
|---|---|---|---|
_clck | Microsoft Clarity (first-party) | Clarity user identifier for this browser | 12 months |
_clsk | Microsoft Clarity (first-party) | Links page views within one session | 1 day |
CLID | clarity.ms (third-party) | Clarity's own identifier | 12 months |
ANONCHK | clarity.ms (third-party) | Indicates whether MUID is used for advertising (we use it for analytics only) | 10 minutes |
MR | clarity.ms / Microsoft (third-party) | Signals whether to refresh MUID | 7 days |
MUID | Microsoft (third-party) | Microsoft's cross-site browser identifier | ~13 months |
SM | Microsoft (third-party) | Microsoft ID synchronisation | Session |
*Durations are set by Microsoft and may change — see Microsoft's privacy statement.
4.4 Marketing and Advertising — only with your consent
We do not currently run marketing or advertising cookies. The banner includes the category so that if we ever introduce one (for example the Meta Pixel, _fbp, up to 90 days), it cannot load unless you have opted in — and this table will be updated first.
5. Session replay (Microsoft Clarity)
If — and only if — you accept "Analytics and Performance", we use Microsoft Clarity to understand how the site is used: aggregated heatmaps and replays of page interactions. Clarity is configured with strict masking, so text you type and on-page content are masked in replays. We do not send Clarity your name, email or account identifier, and replays are not used to make any decision about you. Withdrawing consent (via "Privacy choices") stops Clarity on your next page view and deletes its cookies; data already collected expires on Microsoft's schedule (replays ≈ 30 days, aggregates within ≈ 13 months).
6. Checkout and payment pages
When you pay, our payment processors — Stripe and PayPal — set their own strictly necessary cookies on their payment elements for security and fraud prevention (for example Stripe's __stripe_mid/__stripe_sid, and PayPal's own security cookies). These are required to take payment safely and are governed by the relevant provider's own privacy policy (Stripe · PayPal), linked at checkout.
7. Controlling cookies in your browser
Beyond our banner, every major browser lets you block or delete cookies (Settings → Privacy). Two honest caveats: blocking strictly necessary cookies will break login and forms; and clearing storage also deletes the record of your "reject" choice, so the banner will ask again. Instructions: Chrome · Firefox · Safari · Edge.
8. Other countries
🇮🇪 Republic of Ireland and the EU/EEA
The same consent-first approach satisfies EU law: Article 5(3) of the ePrivacy Directive (2002/58/EC) — implemented in Ireland by the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 (S.I. No. 336 of 2011), regulation 5 — with consent to the EU GDPR standard. The Irish Data Protection Commission's cookie guidance is our reference for Irish users; complaints may go to the DPC (dataprotection.ie).
🇺🇸 United States
There is no general federal cookie-consent law; state privacy laws regulate "selling" or "sharing" personal information instead. We do not sell personal information and do not share it for cross-context behavioural advertising — our only optional tracking is consent-based analytics. Where legally applicable, we recognise supported Global Privacy Control signals as an opt-out request; optional analytics remains disabled unless the required consent has been provided (Microsoft states Clarity itself also supports GPC). California users: the analytics data described above falls under "internet or other electronic network activity information", collected only with your opt-in.
🇨🇦 Canada
PIPEDA requires meaningful consent for tracking technologies; the Office of the Privacy Commissioner's guidance on online behavioural advertising treats opt-in as best practice — which is what our banner does. Quebec's Law 25 requires technologies that identify, locate or profile a user to be off by default: they are (only strictly necessary cookies run without action from you).
🇦🇺 Australia
Australia has no cookie-consent regime; the Privacy Act 1988 (Cth) instead requires open and transparent handling of personal information (APPs 1 and 5). This policy is that transparency — and Australian users get the same opt-in banner as everyone else, which exceeds current Australian requirements.
🇳🇿 New Zealand
New Zealand's Privacy Act 2020 takes the same notice-based approach: IPP 3 requires us to tell you what is collected and why — this policy does — and our opt-in banner goes further than the Act requires.
9. Changes
When our cookies change, this page changes first — with a new version number and effective date. Material changes (for example, introducing a marketing cookie) will also be flagged by the banner asking again.
10. Contact
Questions about cookies: support [at] dogetlawyer [dot] com ("Cookies" in the subject). Complaints follow the route in the Privacy Policy — us first (acknowledged within 30 days), then the ICO (ico.org.uk).
Version 2.1 · Effective 24 July 2026 · Framework: PECR 2003 regulation 6 as amended by the Data (Use and Access) Act 2025 (in force 5 February 2026) · UK GDPR consent standards · ePrivacy Directive 2002/58/EC and S.I. 336/2011 (Ireland) · CCPA/CPRA (California) · PIPEDA and Law 25 (Canada) · Privacy Act 1988 (Australia) · Privacy Act 2020 (New Zealand). · 5 August 2026: presentation redesigned (new header, contents sidebar and footer); the contact e-mail is never displayed on the page — the “our support inbox” link opens your e-mail app directly, which defeats spam harvesters.