Cookie Policy
This Cookie Policy explains how MerchantLink uses cookies and similar technologies on our website at merchantlink.co.uk (the "Website"). It should be read together with our Privacy Policy.
1. What cookies are
Cookies are small text files that a website places on your device when you visit it. They allow the website to recognise your device on return visits, remember your preferences, and provide a smoother experience.
Cookies set by us are called "first-party" cookies. Cookies set by other organisations whose services we use are called "third-party" cookies.
2. How we use cookies
We use cookies for the following purposes:
2.1. Strictly necessary cookies. These cookies are essential for the Website to function. They let you sign in, keep your session alive while you browse, and remember the items in your basket. The Website cannot operate properly without them.
2.2. Performance and analytics cookies. These cookies help us understand how visitors use the Website, which pages are popular, and where users encounter errors. The data is aggregated and does not identify individuals.
2.3. Functional cookies. These cookies remember your preferences (for example, your delivery postcode, your preferred theme, the language you are using) so we can give you a better experience.
2.4. Payment cookies. Our payment processor, Stripe, may set cookies to support fraud prevention and to keep your payment session secure.
We do not currently use advertising or tracking cookies on the Website.
3. Your choices
3.1. Strictly necessary cookies are set automatically when you visit the Website because they are required for it to work.
3.2. For non-essential cookies (performance, analytics, functional), we will ask for your consent on your first visit through a cookie banner. You can:
(a) accept all non-essential cookies;
(b) reject all non-essential cookies; or
(c) choose specific categories to accept or reject.
3.3. You can change your cookie preferences at any time through the cookie preferences link in the Website footer.
3.4. You can also control cookies through your browser settings. Most browsers let you block or delete cookies; the methods vary. If you block strictly necessary cookies, parts of the Website may not work.
4. The cookies we use
Below is the current list of cookies on the Website. We update this list as the Website changes.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
[SESSION_COOKIE_NAME] | merchantlink.co.uk | Keeps you signed in during your visit. | Session |
[CSRF_COOKIE_NAME] | merchantlink.co.uk | Protects against cross-site request forgery on form submissions. | Session |
[CONSENT_COOKIE_NAME] | merchantlink.co.uk | Records your cookie preferences so we do not ask again. | 12 months |
_ga, _ga_* | Google Analytics (where enabled) | Distinguishes users and stores usage information used to compile reports. | 13 months |
__stripe_mid, __stripe_sid | Stripe | Fraud prevention and payment session continuity. | Session and 12 months |
__cf_bm | Cloudflare | Bot management. | 30 minutes |
If a cookie that is not listed here appears in your browser, please let us know and we will investigate.
5. Third-party services
The Website may include content or services from third parties. These third parties may set their own cookies when you interact with their content. Examples include:
(a) Stripe. Payment processing.
(b) Google Analytics. Aggregated usage analytics.
(c) Cloudflare. Security and content delivery.
We do not control third-party cookies. Their use is governed by the third party's own policies.
6. The mobile app and local storage
6.1. Our mobile application does not use browser cookies. It uses local storage on your device to:
(a) keep you signed in;
(b) remember your preferences (theme, postcode, notification permissions, onboarding state);
(c) cache content so the app works smoothly;
(d) hold your basket between sessions; and
(e) store a push notification token if you have given notification permission.
6.2. You can clear local storage by signing out of the app, deleting and reinstalling the app, or removing app data through your device settings.
6.3. The mobile app uses analytics and error reporting SDKs to understand how the app is used and to detect crashes. See the Privacy Policy for the providers used and the lawful bases on which we rely.
7. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date at the top shows when it was last revised. Where the changes are material, we will refresh the cookie banner so you have a chance to review your preferences.
8. How to contact us
For questions about cookies or about this Policy, contact us at app@merchantlink.co.uk.