F The Hours

Cookie Policy

Last updated 17 September 2026

This Cookie Policy explains how F The Hours uses cookies and similar technologies (such as localStorage) on fthehours.io. It is written to satisfy the information requirements of the UK Privacy and Electronic Communications Regulations 2003 (PECR) and the UK GDPR.

For information on the personal data we hold and your rights over it, see our Privacy Policy.

1. What cookies and similar storage are

Cookies are small text files saved in your browser. We also use related browser storage (localStorage, and sessionStorage, which clears when you close the tab) to keep the application working between page loads. Throughout this policy we treat both technologies the same way and refer to them collectively as "cookies".

2. Categories of cookies we use

Strictly necessary

These are required for the Service to function. They do not require your consent under UK law because without them the Service cannot deliver the feature you have asked for.

  • Authentication session: stored as a token in localStorage by our authentication provider, Supabase. Keeps you signed in as you move around the application, and is removed when you sign out.
  • Account access details: a copy of your account's role and page permissions is kept in localStorage so the right pages open straight away. If you follow a password reset link, a short-lived marker is kept in sessionStorage until you set the new password.
  • Stripe payment cookies: Stripe's script loads, and sets its cookies, only once a payment form actually opens: on our pricing page, the page you return to after paying, or the billing and team membership pages you see when signed in. Stripe then sets __stripe_mid (kept for a year) and __stripe_sid (kept for 30 minutes) on our site, and m on its own domain, to help prevent payment fraud. Stripe is the controller of these cookies; see their cookie policy at stripe.com/cookie-settings.

Functional

These remember preferences you have set, so the features you use work the way you set them up.

  • Theme preference: stored in localStorage as fthehours-theme; remembers whether you chose light or dark mode in the app.
  • Your app preferences: stored in localStorage, and your task log filters in sessionStorage for as long as the tab is open. They remember how you have set up the app: the sidebar, dashboard and toolbar layout, the clock, list and calendar views, filters, notification choices, notices you have dismissed, the income basis on the Tax page, the budget warning levels on team client and project pages, and the defaults you choose in Settings.
  • Working data: a few things kept in localStorage so you can pick up where you left off: a running timer, your progress through the welcome steps, the last hourly rate you entered, the annual income goal and tax pot amount you set on your dashboard, the dates of your last export or import, and the day the app last recorded you as active. For as long as the tab is open, sessionStorage also notes which notifications have already been shown, and when the page last reloaded itself after an update.

Your theme, account access details, app preferences and working data stay in this browser after you sign out, until you clear this site's data. The entries in sessionStorage go when you close the tab.

Visit counting

These support the public-page visit counter, which is covered by "Analytics" below rather than by consent.

  • Public-page visit counter: stored in sessionStorage as fth_pageview_session, with any campaign parameters from the address you arrived on kept alongside it as fth_pageview_utm. The identifier is random, is not linked to an account, and clears when the tab closes. See "Analytics" below.
  • Visit-counter opt-out: stored in localStorage as fth_pageview_optout if you turn the counter off below. It has to outlast the tab, which is why this one entry is kept until you clear it.

Analytics — first-party only

We do not run any third-party analytics anywhere on the Service. We do not use Google Analytics, Mixpanel, or any similar product. On the public pages only, we count visits ourselves. For each page view we store:

  • the page path, and the address of the page that brought you to the site, as much of it as your browser sends
  • any campaign tags in the address you arrived on (utm_source, utm_medium, utm_campaign)
  • the random session identifier described above
  • your browser's user-agent string, and the device type, browser and operating system we read from it
  • the width of your browser window, and your browser's language setting
  • the country our hosting provider works out from your IP address
  • a visitor code, made each day from your IP address and user-agent string with a secret key, so we can tell how many visitors came each day and not only how many pages were viewed
  • the date and time, whether the visit looks automated, and where it came from (for example Google, LinkedIn or a direct visit), worked out from the linking address or campaign tags

Your IP address is used to make the visitor code. It also makes a separate code that limits how many visits one IP address can send. The address itself is not kept in our database. We do not store your region or city. Visits from a browser that is signed in to F The Hours are not counted.

We ask for no consent before counting, relying on the statistical-purposes exception in the UK's storage and access rules: the counts tell us how the public pages are used and nothing else. They are never used for advertising, never joined to a profile, and never shared with an advertising platform. You can turn the counter off for this browser at any time, and we stop counting straight away.

Marketing — pending

We intend to install the Meta Pixel on the public landing page (fthehours.io) to measure the effectiveness of paid advertising on Instagram and Facebook. Activation is pending Meta's business-account review. When the Pixel is enabled, this page will be updated to describe exactly which cookies it sets, and a consent banner will appear on first visit asking for your permission before any marketing cookies are set. No marketing cookies are set today.

3. Cookies set by third parties on our pages

The only third party setting cookies on the Service is Stripe, and only once a payment form opens: see "Strictly necessary" above. Stripe acts as a separate data controller for those cookies. Their detailed cookie information is at stripe.com/cookie-settings.

4. How to control cookies

You can:

  • Use your browser's controls to delete cookies, block cookies from specific sites, or block all cookies. Note that blocking strictly necessary cookies will prevent the Service from working: you will not be able to stay signed in.
  • Clear this site's data (cookies, localStorage and sessionStorage) in your browser settings to remove every entry described above, except Stripe's m cookie, which sits on Stripe's own domain.
  • Sign out of the Service at any time to invalidate the authentication token.
  • Turn off the public-page visit counter for this browser, using the control in "Analytics" above.
  • When we activate the Meta Pixel (described above), nothing it sets will run until you agree to it on the consent banner.

5. Changes to this policy

If we add, remove, or change cookies in a way that materially affects the categories listed above, we will update this page and update the "Last updated" date at the top.

6. Contact

Questions about our use of cookies can be sent to support@fthehours.io.