District
Cookie policy
Working draftVersion 0.1-draftNo effective date set
On this page
Draft v0.1 • Prepared 22 September 2026 • Effective date: [CONFIRM: effective date]
REVIEW DRAFT — NOT FOR PUBLICATION. The cookie inventory is an audit template, not a record of detected cookies. Kyle must populate it from the actual site. This draft proposes prior consent for optional analytics and marketing. It does not claim that every optional technology legally requires consent.
1. About this policy
District HQ Ltd [CONFIRM: exact registered entity] uses cookies and similar technologies to operate District. This policy explains what these technologies do and how you can control them. Our Privacy Policy explains our use of personal information and your rights. Questions can be sent to [CONFIRM: monitored privacy email].
2. What we mean by cookies and similar technologies
Cookies are small files stored on your device by a website. Similar technologies include local storage, tracking pixels, tags and other methods of storing information on, or accessing information from, your device. This policy covers the technologies we actually use, rather than cookies alone.
Some last only for a browsing session; others remain for a defined period. They may be set by District or a third-party provider. Server records that do not involve storage or access on your device are explained in the Privacy Policy where relevant.
3. Categories and choices
| Category | Purpose | Proposed launch control |
|---|---|---|
| Strictly necessary | Functions essential to the service you request, such as maintaining a secure login or recording cookie choices. Classification depends on the actual purpose. | Used without consent where the legal exception applies. Explained in the inventory. |
| Optional preferences | Remembering optional settings where not already covered by a valid exception. | Off until you choose to allow the relevant category. |
| Analytics | Understanding use of the site and improving it. | Off until you opt in under District's proposed launch configuration. |
| Marketing | Advertising measurement, retargeting or similar advertising-related tracking, if introduced. | Off until you opt in. No category implies a tool is already installed. |
| Third-party content | Maps, videos, virtual tours or other embedded services where loading them would introduce non-exempt storage or access. | Load after the appropriate choice, or provide an alternative such as an address or external link. |
The law provides specific exceptions, including narrowly defined statistical and appearance uses. We will not assume a tool qualifies merely because it is called “analytics” or “functional”. If we adopt an exception requiring an objection option, we will explain it and provide the required simple, free control. Advertising tracking is not covered by the statistical exception.
4. The technologies used on District
District does not use any analytics, advertising or measurement technology. Everything below exists because a function you asked for needs it. This is not a category list carried over from a template: it was read from District's own code on 22 September 2026, and the audit that produced it, with the file references for every row, is kept alongside this policy.
Cookies
| Exact name or storage key | Provider / domain | Purpose and category | Duration | Consent or applicable exception |
|---|---|---|---|---|
sb-<project>-auth-token, and its .0 and .1 parts | District, on District's own domain. Written by the Supabase client library we use for sign-in | Keeps you signed in as you move between pages. Strictly necessary | Your access token lasts one hour and is renewed while you keep using the site. [CONFIRM: the cookie's own expiry, read from a live response — District's code sets no expiry, so this is the library's default and we will not guess it] | Necessary for the sign-in you requested |
| The sign-in verification cookie set while a magic link is being exchanged | District, on District's own domain. Written by the same library | Completes your sign-in securely and stops the link being used by anyone else | The sign-in only; it is used up by the exchange | Necessary for the sign-in you requested |
district-sign-in-email | District | Remembers which inbox we sent your magic link to, so the next screen can tell you and "send another link" works | 15 minutes | Necessary for the sign-in you requested |
district-cookie-choices | District | Remembers the choices you made in Cookie settings, so we do not ask again and so your refusal is applied on every page. It holds only your four choices, the date you made them and a version number. It contains no identifier and nothing about you | [CONFIRM: preference expiry. Currently 180 days, chosen as a working default rather than a legal period] | Necessary to record a choice you made. This is the only District cookie a page's own scripts can read, so that a refusal can be applied immediately rather than on your next page load |
Other storage on your device
| Exact name or storage key | Provider / domain | Purpose and category | Duration | Consent or applicable exception |
|---|---|---|---|---|
district-theme (local storage) | District | Remembers whether you chose the light or the dark appearance | Until you change it or clear your browser storage | [CONFIRM: classification. Where you actively chose the appearance this is an interface customisation you asked for; confirm the treatment before publication] |
district.brief.handoff.v1 (local storage) | District | Carries the requirement you just wrote across signing in, because a magic link can open in a new tab | Deleted the moment it is read back, on the next screen | Necessary for the function you requested |
operator.locations.expanded (session storage) | District | Remembers which of your locations you expanded | The browser tab only | Necessary for the function you requested |
district.enquiry-draft. followed by the workspace reference (session storage) | District | Keeps a part-written enquiry while you sign in. Session storage deliberately, so it is not left behind on a shared machine | The browser tab only | Necessary for the function you requested |
Maps
Map views load tiles and styles directly from a map provider, which means that provider receives your IP address and can see which part of the map you are looking at. No District cookie is involved, and we set nothing on your device through them.
| Provider / domain | What it is used for | When it loads |
|---|---|---|
CARTO, basemaps.cartocdn.com | The base map behind search and listing maps | Any page with a map, in District's current configuration |
OpenStreetMap, tile.openstreetmap.org | The small location map on a workspace page | Every workspace page |
MapTiler, api.maptiler.com | An alternative base map and its label fonts | Only where District is configured to use it |
[CONFIRM: whether these map providers are loaded before a choice, or behind one with an address-only alternative. This is a live product decision, not a drafting point, and it is recorded in District's open questions.]
Not used
We do not use analytics cookies, advertising or retargeting technology, measurement pixels, social media trackers, session recording, or any embedded third-party content other than the maps described above. Our web fonts are served from District's own domain, not from a font provider.
Inventory last verified: 22 September 2026, from District's own source code rather than from a supplier's description. Provider descriptions alone do not establish what District's configured site actually does.
5. How to make and change your choices
Where optional technologies are used, our preference panel offers Accept optional cookies, Reject optional cookies and Manage preferences. You can choose by purpose without being required to accept unrelated technologies to browse listings or submit an enquiry.
Optional categories start off. Closing the panel or continuing to browse is not treated as agreement. You can revisit Cookie Settings in the footer at any time and withdraw consent as easily as you gave it.
When you withdraw, we stop the relevant future storage or access under our control and remove relevant stored items where technically possible. Withdrawal does not undo lawful processing that already happened. Browser or third-party controls may be needed for items outside our control; the inventory will identify relevant providers and guidance. Rejection must still stop District from making fresh optional tracking requests.
Choices apply to the browser or device where made unless we explicitly explain a supported cross-device mechanism. Clearing browser storage, using a different browser or a material change in our technologies may cause us to ask again. [CONFIRM: preference expiry and renewal rules.]
6. Browser controls and external services
Your browser can block or delete cookies. Blocking strictly necessary items may stop features such as login from working. Browser settings are an additional control; you can still use District's own preference panel for optional technologies.
If you follow a link to another website, its operator manages its own technologies and privacy practices. We identify an external service where needed before you choose to use it. Third-party content embedded inside District remains part of our own implementation assessment.
7. Changes
We update this policy when our technologies or purposes change. We show the effective date and keep the inventory current. We obtain a new choice where required before introducing a new consent-dependent purpose or provider.