Zuno Cookie Policy

    Biscuit Policy, if you insist.

    Last updated: September 2026

    Version: 2026-09

    This Cookie Policy explains what Zuno Group Ltd ("Zuno") stores on your device when you visit zuno.uk.com and what services loaded by the site store on their own. It covers cookies and the equivalent browser storage that the UK Privacy and Electronic Communications Regulations treat the same way, including localStorage and sessionStorage.

    1. Cookies and browser storage that Zuno sets to run the site

    The following are used to keep you signed in, keep pages responsive, keep the site secure against forged requests, and remember the choice you made on the cookie banner. All are first party and are not shared with any other website. Under PECR they are treated as strictly necessary or functional to provide the service you have asked for, so the banner does not turn them off.

    1.1 Session cookies

    Three cookies bind a request to the right server-side account record. Without them Zuno cannot know who is logged in.

    • zuno_app_session. Customer and operative sessions. Signed. Lifetime 30 days.
    • zuno_admin_session. Admin sessions. Signed. Lifetime 12 hours, extending on activity up to a fixed ceiling.
    • zuno_substitute_session. Set only while a substitute operative is standing in for an assigned one. Signed. Lifetime 30 days.

    1.2 CSRF cookie

    • csrf-token. A random token that Zuno's server uses to check every state-changing request came from a page Zuno served. Lifetime 24 hours.

    1.3 The cookie-consent record

    • zuno_cookie_consent in localStorage. Stores your choice from the cookie banner, either accepted or rejected. Kept in your browser only, per browser and per device. Retained until you clear it.

    1.4 Browser storage used by the app

    The browser's own storage APIs are used the same way as cookies for legal purposes. All seven values below are first party, stored only in your own browser, and are not sent to any other website.

    • zuno.auth.user in sessionStorage. A local copy of your account row so pages render without a spinner between requests. Cleared when the tab closes and when you log out.
    • zuno_last_sign_in_method in localStorage. Records which sign-in method you last used, so the login page can offer it again next time. Stores the method word only, never an identifier. Retained until you clear it.
    • lastProblemPromptTime in localStorage. A timestamp used to prevent the "report a problem" prompt reappearing within sixty seconds. Retained until you clear it.
    • zuno:chunk-reload-at in sessionStorage. A timestamp used to recover safely if Zuno releases new code while you have a page open. Cleared when the tab closes.
    • zuno:admin-access-return-at in sessionStorage. Set only on the Zuno staff admin pages. A timestamp recording that the browser was sent to the staff sign-in service, so it is not sent there twice in a row if that does not work. Cleared when the tab closes.
    • zuno.identity-disclosure. followed by a reference, in sessionStorage. Records that you have already been shown a particular notice about a change to your vehicle's details, so the same notice is not repeated at you. Cleared when the tab closes.
    • zuno.popstateTrace in localStorage. A short diagnostic log of how the browser's back button behaved during a booking, kept so that a fault reported on a phone can be investigated. It records the steps of the booking flow you moved between and nothing you typed. Retained until you clear it.

    2. First-party analytics, only if you accept

    Zuno sets no analytics cookies. If you choose Accept on the cookie banner, Zuno turns on first-party analytics for the current visit: two values are written to your browser's sessionStorage, and each page you visit is recorded to Zuno's own server. If you choose Reject, none of this happens. All of it is first party, held on Zuno's own systems, and is not shared with any other website.

    The two sessionStorage values, both first party, both cleared when the tab closes, and neither leaves your device on its own:

    • zuno_session_id. A random identifier used to group pageviews within a single visit.
    • zuno_utm_params. Any utm_source, utm_medium or utm_campaign from the URL you arrived on, recorded once for the visit.

    Each page view is sent to Zuno's own server at /api/analytics/event with the session identifier above, the path visited, the referring website's category (search engine, social network, direct or other), the browser Zuno sees you on, and the UTM parameters if present. Zuno uses this to see which pages are used and to improve the site.

    3. Third-party services Zuno loads on specific pages

    Three third-party services are loaded by Zuno to make the site work. Cloudflare Turnstile loads on the specific pages listed below. Stripe and Google Fonts load on every page. Their own privacy notices apply, and where one of them sets something on your device it is named below.

    3.1 Cloudflare Turnstile

    Loaded on the sign-in, sign-up, password-reset, booking-tracking, data-deletion and payment pages from challenges.cloudflare.com. Cloudflare's bot-detection challenge, used to keep automated abuse off Zuno. Cloudflare classifies its Turnstile cookies as strictly necessary. Third party.

    3.2 Stripe

    Loaded on every page from js.stripe.com and m.stripe.com, not only where you pay, because the payment library is part of the code the whole site is built from. Stripe collects the payment and runs fraud-detection checks.

    Stripe sets two cookies, __stripe_mid and __stripe_sid, which it uses to recognise a browser and a visit for fraud detection. They are stored under zuno.uk.com rather than under Stripe's own domain, so your browser treats them as first party even though Stripe controls what is in them. They are set on every page, including pages with no payment on them such as this one, and they are set before you answer the cookie banner. Zuno does not read them.

    3.3 Google Fonts

    Loaded across the site from fonts.googleapis.com and fonts.gstatic.com to serve the fonts Zuno uses. Google states that Google Fonts does not set cookies; the request does disclose your IP address to Google. Third party.

    4. What Zuno does not set

    • No advertising cookies of any kind.
    • No third-party analytics vendor. Zuno does not load Google Analytics, the Meta pixel, TikTok Pixel, or any comparable script.
    • Nothing Zuno sets follows you to other websites.
    • Zuno does not build an advertising profile of you.

    5. What the banner does

    Choosing Accept writes accepted to zuno_cookie_consent, closes the banner, and turns on the first-party analytics described in section 2. Choosing Reject writes rejected, closes the banner, and leaves the analytics off. No analytics cookie is set on your device either way.

    You can change your mind at any time by clicking Cookie preferences in the site footer. That reopens the banner so you can pick again.

    6. Managing preferences

    The choice recorded from the banner is stored only in the browser you made it on. It is not carried across devices, and it is not carried across different browsers on the same device. Clearing site data in your browser removes it.

    Every browser also lets you delete cookies and site data for a given site directly. Doing so for zuno.uk.com clears the session cookies listed above, which logs you out.

    7. Retention

    The lifetimes above are the maximum. A cookie or storage value ends earlier when you log out, when you clear your browser data, or when the tab is closed for values kept in sessionStorage.

    8. Changes to this policy

    Zuno will update this Cookie Policy when what the site sets changes. The version number and the date at the top of the page track the current version. Bumping the version does not require you to accept again.

    9. Contact and complaints

    For questions, email [email protected].

    You have the right to complain to the Information Commissioner's Office. Their contact details are at ico.org.uk.