Photo1

Cookie Policy

Cookie & Tracking Technologies Policy

Last updated: 3 February 2026

 

1. Introduction

This Cookie & Tracking Technologies Policy explains how we use cookies and similar technologies on our website and within our mobile application. Some of these technologies are essential for our services to function, while others help us improve performance, personalise content, and understand how users interact with our platforms.


Where required under the Privacy and Electronic Communications Regulations (PECR), we will only use non-essential cookies and tracking technologies with your consent.


For more information about how we process personal data, please see the Salts Healthcare Website Privacy Policy. The Ostique Connect Privacy Policy is available directly within the mobile app.

 

2. What Are Cookies and Tracking Technologies?

Cookies (Website)
Cookies are small text files placed on your device when you visit a website. They help websites function, improve efficiency, and provide information to site owners.


Tracking Technologies (Mobile App)
Our mobile application uses technologies such as:
• secure local storage
• authentication tokens
• device identifiers
• server-side logging
These tools support secure login, personalised content, and app performance.

 

3. Types of Cookies and Technologies We Use

Essential (Strictly Necessary)
Required for the website or app to function. These do not require consent.

Analytics / Performance
Help us understand how users interact with our services so we can improve them. These require consent.


Advertising / Social Media (Third-Party)
Used by third-party providers to deliver features or measure engagement. These require consent.


The Ostique Connect mobile app does not use third‑party advertising cookies or tracking technologies.

 

4. Cookies Used on Our Website

Cookie Name Purpose

Cookie Consent

cookies_accepted Stores the user’s cookie consent state.

Visitors Session Status

ASP.Net_SessionId This cookie is essential for the functionality of this website. This cookie contains the user's session ID and the cookie will expire when you close your browser. This cookie does not store personal data about you

Visitor Session Status

ASP.Net_SessionId Maintains session state; expires when the browser closes.

Language Settings

lang Stores the website language selected by the user.

Statistics

Dynamicweb.SessionVisitor Records date of last visit for statistical purposes.

eCommerce

Ecom.SelectedLangID.Fronted Stores the selected ecommerce language.

Application Security 

auth_token Provides secure login authentication; destroyed on logout.

User Preferences

night_mode Stores user preference for Cookie Consent Panel theme.

Google Analytics

_ga, _gid, _gcl_au, _gat_gtag_UA_23414123_10, _gwcc Collects anonymised usage data to help improve the website.

 

 

More information:
Google Analytics: https://support.google.com/analytics/answer/6004245
Dynamicweb cookies: https://www.dynamicweb.com/system/cookie-policy

5. Tracking Technologies Used in Our Mobile Application

Technology Name/Platform Purpose

Token-Based Authentication

JWT (JSON Web Token) Securely verifies user identity for each API request. No personal data stored in the token. Tokens expire after 365 days.

Local Secure Storage

GetStorage (mobile app) Stores session data, authentication tokens, user identifiers, and preferences using lightweight key–value storage.

Admin-Side Secure Storage

Laravel encrypted cookies & session management Provides secure authentication and session handling for admin users.

Server-Side Data Storage

MySQL database (user data) + AWS S3 (files & images) Stores user accounts, content, and uploaded images securely in accordance with data protection laws.

Server Logs

MySQL-based logging Collects non-sensitive technical data for security monitoring, diagnostics, and performance optimisation.

Cookieless Personalisation

First-party profile & in-app activity Delivers personalised content based solely on user profile and in-app behaviour. The mobile app does not use third‑party advertising cookies or tracking technologies.

Biometric Authentication (optional) 

Face ID / Fingerprint (device‑level) Allows users to log in securely using biometric authentication. Biometric data is processed on the device only and is never stored or accessed by Ostique Connect.

 

 

Biometric data never leaves your device and is never transletted to Ostique Connect.

 

6. Cookies Created by Third Parties

Microsoft (Analytics)
Cookies: MUID, MUIDB
Used to identify users across Microsoft domains for analytics and advertising.
More information: https://privacy.microsoft.com/en-gb/privacystatement

 

Twitter
Cookies include: _twitter_sess, ct0, guest_id, personalization_id
Enable embedded Twitter features such as sharing content or viewing tweets.
More information: https://twitter.com/en/privacy


AddThis (Social Sharing)
Cookies:_atuvc, _atuvs, uvc, loc
Enable social sharing features and ensure share counts display correctly.
No data is sent back to AddThis.

 

7. Managing Your Cookie Preferences (Website)
You can update your cookie preferences at any time by selecting Cookie Settings on our website. You can also manage cookies through your browser settings:
• Chrome
• Edge
• Firefox
• Safari
• Opera


To opt out of Google Analytics across all websites: http://tools.google.com/dlpage/gaoptout

 

8. Managing Tracking Technologies in the Mobile App
You can control tracking technologies through:


In-App Settings
Adjust preferences for personalisation, analytics, and session tracking.


Device-Level Controls
• iOS: Settings > Privacy & Security > Tracking
• Android: Settings > Privacy > Ads


Permission Management
Control access to camera, storage, location, and other device features.

Resetting Identifiers
You may reset advertising identifiers or clear app data to remove stored tracking information.


Please note: disabling certain technologies may affect app functionality.

 

9. Retention of Cookies and Tokens
• Session cookies expire when you close your browser.
• Persistent cookies remain until they expire or are deleted.
• JWT authentication tokens expire after 365 days and are automatically invalidated.
• Local storage data remains until the user logs out, resets the app, or clears app data.

 

10. Changes to This Policy
We may update this policy from time to time. Any changes will be posted on this page with an updated “Last updated” date.


11. Contact us
If you have questions about this policy or how we use cookies and tracking technologies, contact:
Data Protection Officers
Salts Healthcare Ltd
Richard Street
Aston
Birmingham
B7 4AA
Email: dataprotection@salts.co.uk

Our partners and accreditations

  • Medilink logo
  • BSF logo
  • SHA logo
  • Disability Confident Committed
  • BHTA logo
  • UTA logo
  • SGS logo
  • SGS logo

Our site uses cookies for marketing (if appropriate) and to improve your experience by allowing us to remember you and analyse how you use our site. To accept cookies click ‘Accept all cookies’. Alternatively, you can select only the 'essential cookies' required for the site. At any time you can click on our cookie control panel and select a different option.  |  View our privacy policy or cookie policy

Only accept essential cookies Accept all cookies