Legal
Cookies
There is no consent banner on this site, and that is not an oversight. We set no advertising cookies, no analytics cookies and no cross-site trackers, so there is nothing to ask permission for. This page lists everything that is actually stored, on the website and in the application.
Last updated
01
This website
The marketing site sets no cookies at all. One thing is stored in your browser, and it never leaves it:
| What | Where | Purpose | Lasts |
|---|---|---|---|
| numo-banner | Session storage | Remembers that you closed the notice at the top of the page, so it does not come back on every page you open | Until you close the tab |
Session storage is not a cookie: it is not sent to our server with any request, and it is deleted when the tab closes. Nobody can read it but the site itself, in that tab.
We do not run Google Analytics, advertising pixels, heat-mapping, session recording or any third-party tag. If that changes, this page changes first and a consent request appears with it, because those would need one under the Privacy and Electronic Communications Regulations.
02
The application
Signing in to Numo Law needs cookies, and those are strictly necessary: without them there is no way to stay signed in from one page to the next. Strictly necessary cookies do not require consent, but they should still be listed.
| Cookie | Purpose | Lasts |
|---|---|---|
| numo_session | Keeps a professional signed in, and carries the token that proves who is asking on every request | Until it expires or you sign out |
| numo_applicant_session | The same, for the separate application a firm's client signs into | Until it expires or you sign out |
| Supabase auth cookies | Hold and refresh the authentication token issued when you signed in | Until they expire or you sign out |
The application also keeps a small amount in the browser’s own storage for things like the last page you were on and whether a panel was open. None of it is personal data about anybody other than you, and none of it is sent anywhere.
Signing out clears the session cookies immediately. Closing the browser does not, which is why a shared device should be signed out rather than just closed.
03
Services you connect
When a professional connects their own Google, Dropbox or Calendly account, the consent screen for that connection is that service’s own page, on its own domain, under its own cookie policy. We never see the credentials entered there.
The place finder loads mapping and imagery from Google Maps Platform, which sets its own cookies when it does. That is Google’s processing, described in their terms, and it happens only on the pages where a map is actually shown.
04
Controlling them
Every browser can block or clear cookies and site data, usually under privacy settings. Blocking them for this website costs you nothing: the site works the same either way, except the notice at the top will come back.
Blocking them for the application means you cannot sign in, because the session cookie is how it knows the request is yours.
Anything else about what we hold and why is in the privacy policy. Questions to support@numolaw.com.