Cookies and device storage

Cookie and device storage notice

Last updated: 23 August 2026

Website use

The eServUK website uses first-party, strictly necessary technology to maintain a secure Laravel session and protect forms against cross-site request forgery. These functions are required for account, Marketplace, Operations and enquiry workflows.

Website cookies used

  • Session cookie: maintains authenticated or form session state, validation feedback and other necessary workflow state. The site is currently configured with a 120-minute session lifetime, although browser and server behaviour can end it sooner.
  • XSRF-TOKEN, where issued: supports cross-site request-forgery protection for compatible requests.

Mobile secure storage

The native eServUK mobile app does not use browser cookies for Marketplace authentication. It stores the Marketplace authentication token and app installation identifier using the device's secure credential storage. Authentication tokens are environment-scoped and expire according to the server's configured token policy. The raw installation UUID is not stored by the Laravel server.

What is not currently in use

The current implementation contains no analytics or marketing cookies, advertising trackers, or application use of browser localStorage or sessionStorage for Marketplace authentication. A cookie consent banner is therefore not shown for the current strictly necessary website technology. This must be reviewed before adding non-essential cookies, analytics, advertising or comparable tracking technology.

Browser and device controls

You can block cookies in your browser, but blocking strictly necessary cookies may prevent secure forms and account sessions from working. Removing the mobile app or clearing its secure credentials can sign the device out of the Marketplace.

Changes

This notice and the consent approach must be reviewed whenever cookies, embedded services, analytics, advertising, browser storage or mobile credential-storage behaviour changes.