Draft template. Replace the bracketed placeholders in lib/company.js and have a qualified solicitor review these documents before launch. Hide this notice by setting draft: false.

Cookie Policy

Last updated: 26 September 2026

This policy explains how Wellspring uses cookies and similar technologies on our public website and booking pages, and how you can control them. It should be read with our Privacy Policy.

1. What cookies are

Cookies are small files stored on your device. Similar technologies include local storage and tracking pixels. We use them to keep you signed in, remember preferences, and — only with your consent — measure advertising.

2. Categories we use

  • Strictly necessary — required for the site to work, so they don’t need consent. These include your sign-in session, your cookie-consent choice, and interface preferences (such as the sidebar state).
  • Marketing / analytics (optional) — the Meta (Facebook) Pixel, which measures whether bookings and purchases came from an ad. This loads only after you accept on the cookie banner.

The cookies and similar technologies currently used on our website and booking pages are listed below. We review this table regularly and will update it whenever our use of cookies or similar technologies changes.

Where a cookie is categorised as “Strictly necessary”, it is required for the operation, security or functionality of the website and does not require consent under applicable law. Where a cookie or similar technology is categorised as “Marketing / analytics”, it will only be deployed after you have provided consent through our cookie banner.

The duration stated below reflects the intended lifespan of the relevant cookie or technology. Some cookies may be removed sooner if you clear your browser data or withdraw consent.

Cookie / TechnologyProviderPurposeCategoryDurationPartyInformation collected
cf_sessionWellspringKeeps you signed in (secure, HttpOnly session cookie)Strictly necessary30 daysFirst partyA signed token identifying your user account
cf_ownerWellspringLets authorised Wellspring platform staff return to their own account after providing support inside a clinic account; never set for ordinary visitorsStrictly necessary4 hoursFirst partyA signed token identifying the staff account
cf_consent (local storage)WellspringRecords your Accept / Reject choice on the cookie bannerStrictly necessaryUntil you clear your browser's site dataFirst party“accepted” or “rejected”
cf_sidebar (local storage)WellspringRemembers whether the app sidebar is open or collapsed (signed-in staff only)Strictly necessaryUntil you clear your browser's site dataFirst party“open” or “collapsed”
cf_privacy (local storage)WellspringRemembers the calendar's on-screen privacy mode, which hides client names from view (signed-in staff only)Strictly necessaryUntil you clear your browser's site dataFirst party“1” or “0” (on / off)
cf_pastdue_seen (session storage)WellspringShows the overdue-billing notice once per browser session rather than on every pageStrictly necessaryBrowser sessionFirst party“1” (notice shown)
ws_attrWellspringRecords which marketing campaign or problem page brought you to our website, so we can tell which of our own pages and adverts actually help clinics find us. Set only after you Accept on the cookie banner, and only if you arrived via a campaign link. Read once if you start a free trial, then deletedMarketing / analytics30 daysFirst partyCampaign name and source from the link you followed, the page you landed on, the website you came from (site name only), and whether you were on a phone or a computer
Meta Pixel (script + _fbp cookie)Meta PlatformsMeasures whether bookings and purchases came from a Facebook / Instagram ad. Loads only on a clinic's public booking pages, only where that clinic has connected Meta advertising, and only after you Accept on the cookie bannerMarketing / analytics_fbp: 90 days (set by Meta)Third partyPage views and booking events, device and browser information, IP address
__stripe_mid / __stripe_sidStripeFraud prevention while taking a card payment; set when a payment form loadsStrictly necessary (payments)1 year / 30 minutesThird partyA device identifier used for fraud detection

The exact cookies and storage technologies used may vary depending on whether you are browsing our public website, using an online booking page, or accessing authenticated areas of the Service. We will update this table to reflect any material changes to the technologies we use.

Where a third-party provider changes the name, duration or technical implementation of its cookies without materially changing their purpose, we may update this table without providing additional notice. Where we introduce a new category of optional cookies or a new third-party provider, we will request fresh consent where required by law.

3. Your choices

When you first visit, a banner lets you Accept or Reject optional cookies. If you reject, the Meta Pixel is not loaded. You can change your mind at any time by clearing your browser’s site data (which resets the banner) or by adjusting your browser’s cookie settings. Rejecting optional cookies does not affect essential functionality.

4. Managing cookies in your browser

Most browsers let you block or delete cookies via their settings. Note that blocking strictly necessary cookies may stop parts of the site — such as signing in — from working.

We record your cookie preferences so that we can respect and demonstrate your choices. We retain those records only for as long as reasonably necessary for those purposes. We may ask you to confirm your choice again periodically or if our use of optional technologies changes materially.

We are not responsible for the operation, availability or cookie practices of third-party services, platforms or websites that we do not control, including providers whose technologies may be deployed following your interaction with embedded content, external links or optional integrations.

5. Third parties

Our blog. The articles on /blog are written in a third-party publishing tool, Soro. Our own server fetches them from Soro and sends them to you as part of our page, so your browser does not contact Soro. The pictures on the blog are stored by Soro and load from Soro’s file storage (supabase.co), which means your IP address reaches that storage so it can send the picture — the same as any image loaded from another website. The blog itself sets no cookies and uses no local storage.

The Meta Pixel is provided by Meta Platforms and is governed by Meta’s own policies. Payment providers may also set cookies during checkout. See our Privacy Policy for the providers we work with.

California residents: we do not load the Meta Pixel unless you actively opt in through the cookie banner described in Section 3. You can withdraw that consent at any time using the same banner or your browser’s cookie settings, which will stop further use of the Pixel for cross-context behavioural advertising.

6. Changes

We may update this policy as our use of cookies changes. The date above shows the latest revision.

If you have questions about this policy or our use of cookies and similar technologies, please contact us using the details provided in our Privacy Policy.

Questions about this page? Contact us at help@wellspringscheduling.com.