Last updated: September 2026
ForgeFox is operated by ForgeFox Ltd, a company registered in England and Wales (company no. 17271363). Registered office: 124 City Road, London, EC1V 2NX. This page lists every cookie and similar technology (such as browser local storage) that ForgeFox uses. We do not use advertising cookies, ad networks or tracking pixels, and we never sell your data.
This website sets no cookies and stores nothing on your device — no cookies, no local storage and no session storage.
We count visits without cookies. Each page view (and a click through to the demo or sign-up) sends the page address, the website you came from, any campaign tag in the link, your country and your device type to our own server. We do not store your IP address: it is combined with your browser type and the date and turned into a one-way code, so we can count unique visitors per day but cannot identify you or follow you from one day to the next. These records are deleted after 180 days and are never shared or used for advertising.
The website’s fonts are loaded from Google Fonts, so your browser asks Google’s servers for them. Google Fonts does not set cookies.
The app (app.forgefox.uk) and the booking pages it powers only store what is strictly necessary for the service to work, or to remember a choice you made. These cannot be turned off without breaking the feature, so they do not need consent.
| Name | Type | Purpose | Duration |
|---|---|---|---|
| sb-…-auth-token (Supabase) | Cookie | Keeps you signed in — operators in the app, and members who sign in to a member area | Until you sign out (your browser keeps it for up to 400 days) |
| ff_oauth_next | Cookie | Remembers which page to return you to while you sign in or sign up | Up to 1 hour; cleared when sign-in finishes |
| ff_ig_oauth_nonce | Cookie | Security check while an operator connects their Instagram account | Up to 1 hour; cleared when the connection finishes |
| ff-pwa-dismissed:… | Local storage | Remembers that you dismissed (or accepted) the “add to home screen” prompt on a booking page | Until you clear it |
| ff:calendar:ios-hint-dismissed | Local storage | Remembers that you dismissed the calendar tip | Until you clear it |
| ff_member_bio_id | Local storage | Only if you turn on fingerprint / face unlock in a member area: identifies the passkey on this device (no biometric data is stored) | Until you turn it off or clear it |
A few other items are kept in the browser only while you use a specific screen of the operator app (for example an unsaved draft in the social post maker). They are never used for tracking.
When you pay, the payment page is run by the operator’s payment provider (such as Stripe or Square), and the booking form may show a Cloudflare Turnstile check to stop spam bots. These services may set their own strictly necessary security and fraud-prevention cookies, covered by their own policies.
Inside the operator app only (the dashboard, admin, sign-up, log-in, onboarding and welcome screens) we use PostHog (hosted in the EU) to understand how the product is used and to diagnose faults, including session recording of the operator screens (never the admin console) with form inputs masked. It runs in memory only: it sets no cookies and stores nothing on your device, and it never loads on this website or on the booking, gift card, member or other pages your customers see. PostHog acts as our data processor; it is also listed in our Privacy Policy.
Older versions of the app did set a PostHog cookie; the app now deletes it automatically the next time you visit.
You can clear or block cookies and local storage at any time through your browser settings — note that clearing the sign-in cookie will sign you out, and clearing local storage will bring back any prompts you dismissed.
Questions about cookies: info@forgefox.uk