Last updated: 2026-10-04
The rules we are working to
Storing information on your device, or reading information already stored there, is governed by regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003. That regulation was rewritten on 5 February 2026. It now reads *"Subject to Schedule A1, a person must not store information, or gain access to information stored, in the terminal equipment of a subscriber or user"* — and the consent requirement and all of the exceptions are now in Schedule A1 to those Regulations.
Two things follow, and we would rather state them than leave them implied:
- These rules apply whether or not the stored information is personal data, and they cover cookies,
localStorage,sessionStorage, IndexedDB, device fingerprinting and app identifiers alike. - There is no "legitimate interests" route here. The only lawful routes are an exception in Schedule A1, or your consent. So for every item below we name which one we rely on.
As this page is published, no analytics or advertising cookie is set on this website and no third-party script is loaded.
Strictly necessary — no consent needed
These are the ones Fin-Central cannot work without. We rely on the Schedule A1 exception for storage that is strictly necessary for the provision of the service you asked for, which expressly covers security, fraud prevention, fault detection and keeping authentication records.
| Name | Type | What it does | How long it lasts |
|---|---|---|---|
fincentral_session | Cookie | Keeps you securely signed in. The app does not work without it | Up to 7 days, or until you sign out |
financeos_session | Cookie | The pre-rebrand session cookie. Still accepted so the rename did not sign existing users out; it is upgraded to the current name on your next request | Up to 7 days, or until you sign out |
fincentral_cookie_ack | Local storage | Remembers that you have answered this notice, so you are not asked again | Until you clear this site's storage |
financeos_cookie_ack | Local storage | The pre-rebrand equivalent, read as a fallback so a rename does not re-prompt you | Until you clear this site's storage |
fincentral_analytics_consent | Local storage | Records your Accept or Decline for non-essential storage. Without it we could not honour your choice | Until you clear this site's storage |
We list them rather than just asserting they exist, because "strictly necessary" is a claim you should be able to check.
Remembering how you like the app — no consent needed
We rely on the Schedule A1 exception for storage whose only purpose is to provide the appearance or functionality of the service you asked for. None of these is sent to us for tracking, and none of them can follow you to another site.
| Name | Type | What it does | How long it lasts |
|---|---|---|---|
fincentral.theme | Local storage | Light, dark or match-my-system | Until you clear this site's storage |
fincentral.sidebarCollapsed | Local storage | Whether you keep the sidebar collapsed | Until you clear this site's storage |
fincentral.onboarding | Local storage | Setup steps you completed before progress moved to your account. Read once and never written to | Until you clear this site's storage |
financeos.theme, financeos.sidebarCollapsed, financeos.onboarding | Local storage | The pre-rebrand versions of the three above, read as a fallback so the rename did not reset your choices | Until you clear this site's storage |
Knowing which link brought you here
| Name | Type | What it does | How long it lasts |
|---|---|---|---|
fc.attribution.v1 | Session storage | If you arrived from a link carrying campaign information (utm_ values, gclid, msclkid, fbclid), the first such link is stored so we can tell which advertising works | Cleared when you close the tab |
What this is and is not. It stays on your device, no third-party script is involved, we never share it, and we do not use it for advertising or to build a profile. It only reaches us if you submit the walkthrough form, and then only so we can tell which campaign produced the enquiry.
Which route we rely on, and the condition we are still short of. This is marketing attribution, not authentication and not appearance, so the strictly-necessary exception does not reach it. The route that does is the Schedule A1 statistical purposes exception, and that exception applies only if we give you clear and comprehensive information and a simple way to object, free of charge. This page is the information. For the objection, today the mechanisms are your browser's own controls for this site's storage, and asking us at privacy@fin-central.com or on the form at /contact — there is not yet a one-click switch in this notice. We would rather tell you that than imply a control that is not there. If you clear or block this site's storage, nothing is captured and nothing in the product stops working except staying signed in.
Anything else — only with your consent, and never before
We set no advertising, cross-site tracking, retargeting or profiling storage, and we load no third-party script that sets its own storage, unless you have agreed to it first. Consent means before the thing is set: there is no implied consent under these Regulations, and a tag that fires on page load and waits for your answer afterwards has already broken the rule.
The software can load website analytics, and it is switched off unless we configure a provider. If we ever do:
- Google Analytics 4 and a Google Ads conversion tag set their own cookies (names beginning
_gaand_gcl). They will not load, and no such cookie will be set, unless you press Accept on the cookie notice — which gives Accept and Decline equal prominence, same size and same shape. You can withdraw your agreement by clearing this site's storage, and if you withdraw it we will delete what was set. - Plausible is our preferred provider and is cookieless — it sets no cookie and stores no identifier on your device. We would rely on the Schedule A1 statistical-purposes exception for it, on the same two conditions as the section above, rather than on the fact that it sets no cookie: since 5 February 2026 regulation 6 also reaches information automatically emitted by your device, so "cookieless" is not a complete answer by itself.
If we ever introduce anything in this category we will update this page first and ask you before setting anything.
Payments
When you subscribe you are taken to a checkout page hosted by Stripe, which processes the payment. That page sets its own cookies, including for fraud prevention, under Stripe's own cookie and privacy notices. We do not control them and they are not covered by your choices here.
Marketing email
We do not send marketing email. If that ever changes we will say so here first, we will ask you when we collect your address rather than assuming, every message will carry a working unsubscribe link, and we will not pass your address to any other brand or product. Note for sole traders and partnerships: the marketing rules in regulation 22 of these Regulations treat you as an individual subscriber, so you get the same protection as a private individual.
Managing cookies and storage
You can clear or block cookies and site storage in your browser settings. Blocking the session cookie will prevent you from signing in; nothing else on this page is needed for the product to work.