Legal

Cookie Policy

Version: 2026-07-30-cookie-final
Last updated: 30 July 2026

This Cookie Policy explains how Cully Express, a trading name of A&S Signatures Ltd, uses cookies and similar browser-storage technologies on cullyexpress.com. It is based on an audit of the website’s current production source and deployed responses.

1. Controller identity

A&S Signatures Ltd, company number 15693230, is the controller responsible for the website processing described in this policy. Cully Express is its trading name.

Registered office: The Collar Factory 112 St Augustine Street Taunton TA1 1QN United Kingdom

2. Scope

This policy applies to cookies, IndexedDB, local storage, session storage, pixels and comparable storage or access technologies used by the Cully Express website, including the restricted administrator portal.

Ordinary HTTP requests also disclose technical information such as an IP address, browser information, requested URL and timestamp to the website’s Google Firebase App Hosting infrastructure. That server-side request processing is described in the Privacy Policy; it is not evidence that a browser cookie was set.

3. What cookies and similar technologies are

Cookies are small values stored by a browser and sent with matching website requests. Session cookies normally end when the browser session ends; persistent cookies remain until their expiry or deletion.

IndexedDB, local storage and session storage allow a website or its software to retain information within the browser. Pixels, tags and embedded scripts can also access information from a device or cause information to be sent to another provider. This policy uses “technologies” to cover all of them.

4. Native-app distinction

The native Cully Express Flutter application does not rely on browser cookies for its core operation. It uses device storage, application identifiers and native SDKs described in the Privacy Policy. This Cookie Policy governs the separate Next.js website only.

5. Technologies actually used

Public informational pages do not deliberately set cookies, local-storage entries or session-storage entries. A legacy consent preference created by the former banner may remain on a returning visitor’s device but is no longer read or written. The website otherwise uses the following limited technologies for its restricted administrator service.

Name / providerCategory and storagePurpose / informationDuration and timingControl / transfers
cullyexpress_cookie_consent (legacy, inactive)
Cully Express
First-party
Legacy functional preference — no longer used
Local storage
Previously recorded whether a visitor selected Accept or Decline on the former banner. The final website does not read, update, or rely on this value.
Information: The word accepted or declined; no account or advertising identifier.
A copy created by the former website may remain until the visitor clears cullyexpress.com site data. The final code creates no new copy.
When: Not accessed before or after consent by the final implementation. It is listed only because a legacy copy may remain on a returning visitor’s device.
A visitor can remove it using the browser’s site-data or local-storage controls.
Transfers: The final website does not transmit this legacy value to Cully Express or another provider.
admin-session
Cully Express using Firebase Authentication
First-party
Strictly necessary / security
Secure HTTP-only cookie
Authenticates an approved administrator to protected website administration routes.
Information: An encrypted Firebase session value linked to the administrator’s authenticated account and security claims.
Five days from successful administrator sign-in, or earlier logout, revocation, deletion, or browser clearing.
When: Set only after a successful administrator sign-in. It is not set for ordinary public-site visitors.
Administrators can sign out. It may also be removed through browser controls, although doing so ends the protected session.
Transfers: Related authentication information may be processed by Google or Firebase outside the UK.
Firebase Authentication browser persistence
Google Firebase
First-party browser storage supplied by a third-party SDK
Strictly necessary / security
IndexedDB by default, with local-storage or session-storage fallback where required by browser support
Maintains and synchronises the signed-in administrator’s Firebase Authentication state so the requested administration service can operate securely.
Information: Firebase user identifier, authentication state, token and token-expiry information, provider information, and SDK metadata. Provider-defined keys may include firebaseLocalStorageDb and firebase:authUser-prefixed entries.
Until sign-out, account or token invalidation, browser-data clearing, or provider-managed replacement. Individual identity tokens expire and refresh separately.
When: The Firebase SDK initialises on administration pages. Authentication state is stored when an administrator signs in; it is not used on ordinary public pages.
Administrators can sign out or clear site data. Removing it prevents the administration session from continuing.
Transfers: Firebase Authentication is a Google service and may process authentication information outside the UK, including in the United States.
Firebase SDK heartbeat storage
Google Firebase
First-party IndexedDB storage supplied by a third-party SDK
Strictly necessary / security and service operation
IndexedDB, using Firebase provider-defined heartbeat records
Allows the Firebase SDK used by the administration portal to send limited SDK and platform heartbeat information with Firebase service requests.
Information: Service name, SDK/platform version, dates and related technical metadata; not form content, order information or advertising profiles.
Provider-managed and replaced or removed after transmission; it can also be removed by clearing browser site data.
When: May be created when the Firebase SDK initialises on administration pages. It is not initialised by the public website pages.
It can be cleared using browser site-data controls, but Firebase-backed administration features may recreate it when used.
Transfers: The associated Firebase request may be processed by Google outside the UK.

6. Strictly necessary and security technologies

The administrator technologies in the table are used only to provide and protect a sign-in and administration service requested by an approved administrator. They are not used to analyse ordinary visitors, advertise, or create behavioural profiles.

The administrator session cookie is HTTP-only, uses the Secure attribute in production, has SameSite=Lax, and is limited to the website path. Firebase Authentication browser persistence is required to maintain the corresponding authenticated browser state.

7. Categories not currently used

Functional or preference technologies

The audited public website does not actively store or read theme, language, personalisation, or cookie-consent preferences. A legacy banner value may remain on a returning visitor’s device as listed above, but the final website does not access it because there are no optional technologies to accept or reject.

Analytics or statistics technologies

The audited website does not initialise Google Analytics, Google Tag Manager, Firebase Analytics, Microsoft Clarity, Hotjar, or another browser analytics service. The Firebase package contains optional modules, but no Analytics module is imported or activated by this website.

Advertising or marketing technologies

The audited website does not load advertising cookies, Meta Pixel, TikTok Pixel, conversion tracking, cross-site tracking, or behavioural-advertising scripts.

8. Local storage, session storage and IndexedDB

The final public website does not create or access a cookie-consent local-storage entry because there are no optional technologies to control. A legacy accepted or declined value from the former banner may remain until the visitor clears site data, but it has no effect and is not transmitted. The website does not use browser storage for theme, language or public-site personalisation.

Firebase Authentication may use IndexedDB, local storage or session storage on administrator pages as described in the table. Firebase SDK heartbeat information may also be held in IndexedDB. The server-only development instrumentation file contains an in-memory storage compatibility shim; it is not downloaded to or persisted in a visitor’s browser.

9. Third-party services and external content

Google Firebase provides App Hosting, administrator authentication and the protected administration data service. Public fonts are bundled and served from the Cully Express website rather than requested from Google Fonts in the visitor’s browser.

Contact, restaurant and driver forms submit to first-party Cully Express API routes. The server then uses Firebase and Resend to store the submission and send operational email; Resend is not loaded as a browser script and does not set a verified website cookie. The website does not embed maps, videos, payment forms, social-media widgets, chat tools or advertising services. External app-store and social links load another service only if a user chooses to follow them.

10. Consent and lawful basis

The audited website has no optional analytics, functional, advertising or marketing technology. It therefore does not display a consent banner or pretend to offer optional settings that have no technical effect.

The administrator technologies are treated as strictly necessary to provide and secure the administration service requested by the administrator. The related personal-data processing is necessary for the applicable administration relationship and for Cully Express’s legitimate interests in authenticating authorised personnel, preventing unauthorised access and maintaining service security.

If optional technology is introduced, it must remain disabled until any required consent has been obtained. The policy and controls must be updated before that technology is enabled.

11. Changing choices and browser controls

There is currently no optional consent to change or withdraw. Administrators can end authenticated storage by signing out. Browser controls can view or remove cookies and site data, including IndexedDB, local storage and session storage.

Blocking or deleting the necessary administrator technologies may prevent sign-in or end an existing administrator session. Public informational pages remain available without accepting optional cookies because none are used.

12. International processing

The website is hosted using Google Firebase App Hosting. Firebase Authentication and related Google services may process request, authentication and technical information outside the United Kingdom, including in the United States.

Where a restricted transfer occurs, Cully Express relies as applicable on UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, the UK International Data Transfer Agreement, the UK Addendum to approved Standard Contractual Clauses, or another lawful transfer mechanism.

13. Data-protection rights

Subject to applicable conditions and exemptions, individuals may request access, correction, erasure, restriction or portability of qualifying personal data and may object to processing based on legitimate interests. A complaint may also be made to the Information Commissioner’s Office.

Further information appears in the Privacy Policy.

14. Updates to this policy

We may update this policy if the website, its providers, or the law changes. The displayed version and last-updated date identify the current notice. Optional technology will not be activated merely by updating this text; the required technical controls and consent must exist first.

15. Contact and company information

Cookie or data-protection questions may be sent to support@cullyexpress.com.

Cully Express (a trading name of A&S Signatures Ltd) Company number: 15693230 Registered office: The Collar Factory 112 St Augustine Street Taunton TA1 1QN United Kingdom

Cookie Policy | Cully Express