Subprocessors, cookies and tracking
Under a data processing agreement we must tell you before this list changes. It is reviewed quarterly, and adding an entry is a notification to every customer, not a quiet deploy.
Subprocessors
Vercel Inc.
Essential to the serviceApplication hosting, edge routing and TLS termination.
Personal data they can see
- IP address (transient, in request logs)
- Session cookie
- URL requested
- User agent
- Location
- London (lhr1) for compute; log retention in the United States
- Transfer safeguard
- EU/UK Standard Contractual Clauses and the UK Addendum, via Vercel's DPA
Supabase Inc.
Essential to the serviceManaged PostgreSQL database, authentication, session issuance, and delivery of authentication email — address confirmation, sign-in links and password recovery.
Personal data they can see
- Email address
- Hashed password
- Display name
- University and student reference
- Programme and academic year
- Assessment attempts and progress
- Audit records
- Location
- EU/UK region (project-configured)
- Transfer safeguard
- EU/UK Standard Contractual Clauses and the UK Addendum, via Supabase's DPA
Stripe Payments Europe Ltd.
Not required for institutional useCard payment processing for direct individual subscriptions only. The payment form on /checkout is served by Stripe inside an iframe, so a visitor on that one page connects to Stripe directly and Stripe sees their IP address and browser; no other page loads anything from Stripe. Institutional customers are invoiced and their students' data never reaches Stripe.
Personal data they can see
- Email address
- Billing name and address
- Card details (held by Stripe, never by us)
- Location
- Ireland, with group processing in the United States
- Transfer safeguard
- EU/UK Standard Contractual Clauses and the UK Addendum, via Stripe's DPA
Vercel Web Analytics
Not required for institutional useAggregate usage measurement — page views and named product events. Configured without cookies and without cross-site identifiers.
Personal data they can see
- Page path
- Referrer
- Coarse device and country, derived and not stored against an identifier
- Location
- Processed by Vercel, as above
- Transfer safeguard
- Covered by Vercel's DPA
Cookies
There is no cookie banner on this site, and that is a deliberate position rather than an omission. The Privacy and Electronic Communications Regulations require consent for anything that is not strictly necessary for a service the visitor has asked for. Both cookies below are strictly necessary, analytics runs without a cookie or a cross-site identifier, and there are no advertising or marketing pixels. If that ever changes, a banner becomes mandatory and this page will say so before it does.
| Name | Purpose | Duration | Consent |
|---|---|---|---|
| sb-<project>-auth-token | Holds the signed-in session. Without it a student cannot stay signed in between pages, so it is strictly necessary for a service they have asked for. | Session, refreshed on use; expires after inactivity | Not required |
| ba_signed_in | A flag stating only that somebody is signed in, so statically cached pages can skip an entitlement request for the anonymous majority. Carries no identity and no entitlement. | 30 days | Not required |
| ba:last-visit-day | One date, so a return visit is counted once a day rather than once a page. Never leaves the browser as an identifier. | Until cleared by the user | Not required |
The last two entries are browser storage rather than cookies. They are listed because the Regulations cover storage on a device generally, not cookies specifically, and neither value ever leaves the browser.
