Pocket Docket — legal

Cookie statement

Pocket Docket Ltd · company number NI742827 · registered in Northern Ireland · registered office 137 York Road, Belfast, BT15 3GZ


The short version

Pocket Docket sets two cookies. Both are strictly necessary to deliver the service securely. One of them is the main thing standing between a leaked dashboard link and someone else reading your books.

We set no analytics, advertising or tracking cookies, so we do not ask for cookie consent. There is no banner on this site, and that is not an oversight.

Nothing on this site loads from a content delivery network or any other third-party origin. There are no third-party pixels, no embedded fonts, no social buttons, no session recorders, no heatmaps. That is a standing engineering rule, not a policy position we arrived at afterwards.


The two cookies

pd_device_* — dashboard device binding

What it doesLocks your dashboard link to the first device that opens it. Every other device is refused and the refusal is logged.
What it containsA randomly generated identifier that we mint, and a signature over it. Nothing about you, your device or your browser. It is not a fingerprint — we do not fingerprint.
Set byPocket Docket. First-party.
FlagsHttpOnly, Secure, SameSite=Lax, Path=/
DurationCurrently 34,560,000 seconds (400 days). We are reducing this to 180 days, which is the shortest period that still avoids re-binding a device a customer uses only occasionally.
Why it is strictly necessaryYour dashboard is reached by a signed link. Without this cookie, anyone who ended up with a copy of that link — forwarded, screenshotted, left open on a shared screen — could open your figures. With it, the link works on your device and refuses everywhere else.

pd_bank_handoff — bank connection redirect

What it doesCarries a signup identifier across the redirect out to a bank's authorisation page and back again, so that when you return we know which signup you are completing.
What it containsA short-lived signup identifier.
Set byPocket Docket. First-party.
FlagsHttpOnly, SameSite=Lax
DurationThe length of the redirect journey only.
Why it is strictly necessaryWithout it, the return leg of the bank authorisation has nothing to attach to and the connection cannot be completed.
NoteThe bank connection feature is integrated but not active in production, so in normal use today this cookie is never set. It is documented here because it exists in the code and we would rather list it than have you find it.

Why there is no cookie banner

Under the Privacy and Electronic Communications Regulations, consent is required before storing information on your device — with exceptions. Regulation 6 was replaced with effect from 5 February 2026, and the exceptions now sit in Schedule A1, inserted by the Data (Use and Access) Act 2025.

Paragraph 3 of that Schedule covers storage or access that is strictly necessary for the provision of an information society service requested by the subscriber or user, and expressly includes protecting data, ensuring the security of the device, preventing fraud, detecting faults and maintaining authentication.

Both cookies above fall squarely inside that. Neither is used for analytics, measurement, advertising or profiling, and neither is shared with anyone.

So a banner would be actively misleading. A consent banner tells a visitor there is something here to consent to. There isn't. Putting one up to look diligent would imply we set non-essential cookies, which we do not.

If that ever changes — if we ever want an analytics tool — you will get a real consent mechanism with a genuine choice, refusing will be as easy as accepting, and nothing non-essential will be set until you say yes. We will also update this page and date the change.


Cookies our providers set

None, in the product. Nothing loads from a third-party origin on the dashboard or the marketing site.

The one exception is the payment page: when you subscribe, you are taken to Stripe's own hosted checkout, which is Stripe's page and sets Stripe's cookies under Stripe's policies. Your card details never touch our systems, which is the point of doing it that way. Once payment is finished you come back to us and the third-party surface ends.


Managing cookies

You can block or delete cookies in your browser settings. If you block pd_device_*, your dashboard link will not work — the security check has nothing to check against, and it fails closed. Clearing the cookie makes your browser look like a new device, and the link may need to be re-issued.

That is not a dark pattern. It is the same trade-off as blocking a login session cookie: the access control needs somewhere to keep the fact that you are the authorised device.


Questions

privacy@pocketdocket.co.uk · Pocket Docket Ltd, 137 York Road, Belfast, BT15 3GZ


Version 1.0 · in force from 21 August 2026

© 2026 Pocket Docket Ltd · Registered in Northern Ireland, company number NI742827 · Registered office: 137 York Road, Belfast, BT15 3GZ · ICO registration ZC223982