Cookies and device storage
Cookie and device storage notice
Last updated: 23 August 2026
Website use
The eServUK website uses first-party, strictly necessary technology to maintain a secure Laravel session and protect forms against cross-site request forgery. These functions are required for account, Marketplace, Operations and enquiry workflows.
Website cookies used
- Session cookie: maintains authenticated or form session state, validation feedback and other necessary workflow state. The site is currently configured with a 120-minute session lifetime, although browser and server behaviour can end it sooner.
- XSRF-TOKEN, where issued: supports cross-site request-forgery protection for compatible requests.
Mobile secure storage
The native eServUK mobile app does not use browser cookies for Marketplace authentication. It stores the Marketplace authentication token and app installation identifier using the device's secure credential storage. Authentication tokens are environment-scoped and expire according to the server's configured token policy. The raw installation UUID is not stored by the Laravel server.
What is not currently in use
The current implementation contains no analytics or marketing cookies, advertising trackers, or application use of browser localStorage or sessionStorage for Marketplace authentication. A cookie consent banner is therefore not shown for the current strictly necessary website technology. This must be reviewed before adding non-essential cookies, analytics, advertising or comparable tracking technology.
Browser and device controls
You can block cookies in your browser, but blocking strictly necessary cookies may prevent secure forms and account sessions from working. Removing the mobile app or clearing its secure credentials can sign the device out of the Marketplace.
Changes
This notice and the consent approach must be reviewed whenever cookies, embedded services, analytics, advertising, browser storage or mobile credential-storage behaviour changes.