1. What cookies we use
We use cookies and similar technologies (localStorage, sessionStorage) on getlocalhero.ie (marketing site) and app.getlocalhero.ie (the application).
We follow ePrivacy Directive (Ireland's S.I. 336/2011) and GDPR rules. Non-essential cookies are blocked until you give consent via the cookie banner.
We use Google Consent Mode v2 so that pre-consent traffic is anonymised at source and does not feed identifiable signals into analytics.
2. Cookie categories
2.1 Strictly necessary (always on — no consent needed)
These are required for the site/app to function. You cannot disable them.
| Cookie / storage | Purpose | Lifetime | Domain |
|---|---|---|---|
sb-access-token | Supabase auth session | Session | app.getlocalhero.ie |
sb-refresh-token | Supabase refresh token (httpOnly) | 7 days | app.getlocalhero.ie |
__cf_bm | Cloudflare bot management | 30 minutes | *.getlocalhero.ie |
lh_consent | Records your cookie-consent choice | 12 months | *.getlocalhero.ie |
cf_clearance | Cloudflare DDoS challenge clearance | 1 hour (when triggered) | *.getlocalhero.ie |
2.2 Functional (always on — strictly required for features you've requested)
| Cookie / storage | Purpose | Lifetime | Domain |
|---|---|---|---|
lh_currency | Remembers €/£ pricing toggle | 30 days | getlocalhero.ie |
lh_locale | Remembers en-IE / en-GB choice | 12 months | *.getlocalhero.ie |
2.3 Analytics (consent-gated — OFF by default in EU/UK/EEA)
Loaded only after you click "Accept analytics" on our cookie banner. Pre-consent, Consent Mode v2 forwards only anonymised pings.
| Cookie | Provider | Purpose | Lifetime |
|---|---|---|---|
_ga | Google Analytics 4 | Distinguish unique visitors | 13 months |
_ga_<container_id> | Google Analytics 4 | Session state | 13 months |
If you decline analytics, none of the above are set.
2.4 Marketing / advertising
None. We do not run Facebook Pixel, Google Ads conversion, LinkedIn Insight, TikTok pixel, or any other advertising tracker.
If we ever add a marketing pixel, this section will be updated, your prior consent will not auto-extend to the new tracker, and you will be re-prompted.
3. How to manage your choices
3.1 Via the banner
First visit: a banner asks you to Accept all or Reject non-essential. Either choice is recorded in lh_consent for 12 months. You can change your choice any time via the "Cookie settings" link in the footer.
3.2 Via your browser
Most browsers let you block or delete cookies. Doing so for strictly-necessary cookies will break sign-in and core functionality.
- Chrome: Settings → Privacy and security → Cookies and other site data
- Safari: Preferences → Privacy → Manage Website Data
- Firefox: Preferences → Privacy & Security → Cookies and Site Data
- Edge: Settings → Cookies and site permissions
3.3 Withdraw consent
You can withdraw analytics consent at any time. Click "Cookie settings" in the footer → uncheck Analytics → Save. Existing analytics cookies are deleted on the next page load.
4. Third-party data flows
When analytics consent is granted:
- Google Analytics 4 transmits pseudonymised event data to Google servers (US). IP addresses are truncated at source. Transfer mechanism: EU–US DPF + SCCs.
When analytics consent is denied:
- Consent Mode v2 forwards only "consent: denied" anonymised pings. No personal data leaves the browser.
We do not enrich GA4 data with first-party customer identifiers from the app.
5. Do Not Track
Most browsers send a "Do Not Track" (DNT) header. We treat DNT=1 as equivalent to denying analytics consent.
6. Mobile and email tracking
- Mobile app: not applicable — Local Hero is web-only.
- Email tracking pixels: transactional emails (sign-in links, billing) do NOT include open/click pixels. Marketing emails (consent-only — opt-in via Settings) include click tracking via Resend; pixels are 1×1 transparent and disclosed per Resend's policy.
7. Changes to this Policy
When we add, remove, or change a cookie/tracker, we update this Policy and re-prompt for consent if the change is material. The version number and effective date at the top are authoritative.
8. Contact
Questions about cookies: privacy@getlocalhero.ie.
v1.0 · under periodic review.