
Cookie Policy
Cookie & Tracking Technologies Policy
Last updated: 3 February 2026
1. Introduction
This Cookie & Tracking Technologies Policy explains how we use cookies and similar technologies on our website and within our mobile application. Some of these technologies are essential for our services to function, while others help us improve performance, personalise content, and understand how users interact with our platforms.
Where required under the Privacy and Electronic Communications Regulations (PECR), we will only use non-essential cookies and tracking technologies with your consent.
For more information about how we process personal data, please see the Salts Healthcare Website Privacy Policy. The Ostique Connect Privacy Policy is available directly within the mobile app.
2. What Are Cookies and Tracking Technologies?
Cookies (Website)
Cookies are small text files placed on your device when you visit a website. They help websites function, improve efficiency, and provide information to site owners.
Tracking Technologies (Mobile App)
Our mobile application uses technologies such as:
• secure local storage
• authentication tokens
• device identifiers
• server-side logging
These tools support secure login, personalised content, and app performance.
3. Types of Cookies and Technologies We Use
Essential (Strictly Necessary)
Required for the website or app to function. These do not require consent.
Analytics / Performance
Help us understand how users interact with our services so we can improve them. These require consent.
Advertising / Social Media (Third-Party)
Used by third-party providers to deliver features or measure engagement. These require consent.
The Ostique Connect mobile app does not use third‑party advertising cookies or tracking technologies.
4. Cookies Used on Our Website
| Cookie | Name | Purpose |
|---|---|---|
|
Cookie Consent |
cookies_accepted | Stores the user’s cookie consent state. |
|
Visitors Session Status |
ASP.Net_SessionId | This cookie is essential for the functionality of this website. This cookie contains the user's session ID and the cookie will expire when you close your browser. This cookie does not store personal data about you |
|
Visitor Session Status |
ASP.Net_SessionId | Maintains session state; expires when the browser closes. |
|
Language Settings |
lang | Stores the website language selected by the user. |
|
Statistics |
Dynamicweb.SessionVisitor | Records date of last visit for statistical purposes. |
|
eCommerce |
Ecom.SelectedLangID.Fronted | Stores the selected ecommerce language. |
|
Application Security |
auth_token | Provides secure login authentication; destroyed on logout. |
|
User Preferences |
night_mode | Stores user preference for Cookie Consent Panel theme. |
|
Google Analytics |
_ga, _gid, _gcl_au, _gat_gtag_UA_23414123_10, _gwcc | Collects anonymised usage data to help improve the website. |
More information:
Google Analytics: https://support.google.com/analytics/answer/6004245
Dynamicweb cookies: https://www.dynamicweb.com/system/cookie-policy
5. Tracking Technologies Used in Our Mobile Application
| Technology | Name/Platform | Purpose |
|---|---|---|
|
Token-Based Authentication |
JWT (JSON Web Token) | Securely verifies user identity for each API request. No personal data stored in the token. Tokens expire after 365 days. |
|
Local Secure Storage |
GetStorage (mobile app) | Stores session data, authentication tokens, user identifiers, and preferences using lightweight key–value storage. |
|
Admin-Side Secure Storage |
Laravel encrypted cookies & session management | Provides secure authentication and session handling for admin users. |
|
Server-Side Data Storage |
MySQL database (user data) + AWS S3 (files & images) | Stores user accounts, content, and uploaded images securely in accordance with data protection laws. |
|
Server Logs |
MySQL-based logging | Collects non-sensitive technical data for security monitoring, diagnostics, and performance optimisation. |
|
Cookieless Personalisation |
First-party profile & in-app activity | Delivers personalised content based solely on user profile and in-app behaviour. The mobile app does not use third‑party advertising cookies or tracking technologies. |
|
Biometric Authentication (optional) |
Face ID / Fingerprint (device‑level) | Allows users to log in securely using biometric authentication. Biometric data is processed on the device only and is never stored or accessed by Ostique Connect. |
Biometric data never leaves your device and is never transletted to Ostique Connect.
6. Cookies Created by Third Parties
Microsoft (Analytics)
Cookies: MUID, MUIDB
Used to identify users across Microsoft domains for analytics and advertising.
More information: https://privacy.microsoft.com/en-gb/privacystatement
Twitter
Cookies include: _twitter_sess, ct0, guest_id, personalization_id
Enable embedded Twitter features such as sharing content or viewing tweets.
More information: https://twitter.com/en/privacy
AddThis (Social Sharing)
Cookies:_atuvc, _atuvs, uvc, loc
Enable social sharing features and ensure share counts display correctly.
No data is sent back to AddThis.
7. Managing Your Cookie Preferences (Website)
You can update your cookie preferences at any time by selecting Cookie Settings on our website. You can also manage cookies through your browser settings:
• Chrome
• Edge
• Firefox
• Safari
• Opera
To opt out of Google Analytics across all websites: http://tools.google.com/dlpage/gaoptout
8. Managing Tracking Technologies in the Mobile App
You can control tracking technologies through:
In-App Settings
Adjust preferences for personalisation, analytics, and session tracking.
Device-Level Controls
• iOS: Settings > Privacy & Security > Tracking
• Android: Settings > Privacy > Ads
Permission Management
Control access to camera, storage, location, and other device features.
Resetting Identifiers
You may reset advertising identifiers or clear app data to remove stored tracking information.
Please note: disabling certain technologies may affect app functionality.
9. Retention of Cookies and Tokens
• Session cookies expire when you close your browser.
• Persistent cookies remain until they expire or are deleted.
• JWT authentication tokens expire after 365 days and are automatically invalidated.
• Local storage data remains until the user logs out, resets the app, or clears app data.
10. Changes to This Policy
We may update this policy from time to time. Any changes will be posted on this page with an updated “Last updated” date.
11. Contact us
If you have questions about this policy or how we use cookies and tracking technologies, contact:
Data Protection Officers
Salts Healthcare Ltd
Richard Street
Aston
Birmingham
B7 4AA
Email: dataprotection@salts.co.uk








