Cookie policy
Last updated 14 August 2026
vaCRM sets one cookie. It keeps you signed in. There is no analytics, no advertising and nothing that follows you anywhere else.
Why there is no banner
Cookies that are strictly necessary for a service you have asked for do not require consent under the Privacy and Electronic Communications Regulations. A cookie that remembers you are signed in is exactly that, so there is nothing here to agree to.
If that ever changes, and something is added that is not strictly necessary, you will be asked properly before it is set rather than told afterwards.
What is set
PHPSESSID. Keeps you signed in as you move between pages, and carries the token that stops a form on another site being submitted as you. It lasts until you sign out or close the browser.
It is set only when you sign in. Visiting the public pages sets nothing.
Things kept in your browser
Once signed in, vaCRM remembers a couple of preferences in your browser's own storage rather than in a cookie: which way a list was last sorted, and similar. They never leave your device, are not sent to us, and clearing your browser data removes them.
Your clients
A client opening their portal link gets a session cookie on the same terms, so that the page knows who they are while they use it.
Other companies
Stripe sets its own cookies on its payment pages if you subscribe, which are covered by Stripe's own policy. Google may set cookies while you are signing in to connect a calendar, on the same basis. Neither happens unless you go through those flows.
Turning them off
You can block cookies in your browser, but the session cookie is what signing in consists of, so blocking it means the app cannot keep you signed in.
See also our privacy policy.