// Legal HQ

Cookie Policy

BudgetFitter® Cookie Policy. Comprehensive guide to our use of essential cookies, local storage tokens, privacy-first analytics, and PECR compliance on our UK website, app, and extension.

Last updated: August 22, 2026

COOKIE POLICY & LOCAL STORAGE DISCLOSURE

This Cookie Policy explains how FozDigital LTD, trading as BudgetFitter (“Company”, “we”, “us”, or “our”), uses cookies, HTML5 local storage, session storage, and similar digital technologies across our website at https://budgetfitter.uk (the “Website”), our native mobile applications for iOS and Android (the “App”), and our privacy-first browser extension for Chromium browsers (the “Extension”).

We are a private limited company incorporated in England and Wales under Company Registration Number 13470802, with Information Commissioner’s Office (ICO) Data Protection Registration Number ZB348787 and registered UK trademark #UK00004088233, located at 124 City Road, London, EC1V 2NX, United Kingdom.

This policy details what these technologies are, why we use them, the specific categories of data they store, and your statutory rights to control or disable them under the Privacy and Electronic Communications Regulations 2003 (PECR) and the UK General Data Protection Regulation (UK GDPR).

TABLE OF CONTENTS

  1. 1. WHAT ARE COOKIES & LOCAL STORAGE TECHNOLOGIES?
  2. 2. CATEGORIES OF TECHNOLOGIES WE USE
  3. 3. DETAILED COOKIE & LOCAL STORAGE INVENTORY
  4. 4. BROWSER EXTENSION LOCAL STORAGE (MANIFEST V3)
  5. 5. MOBILE APPLICATION SECURE STORAGE
  6. 6. OUTCLICK ROUTING & THIRD-PARTY AFFILIATE COOKIES
  7. 7. GLOBAL PRIVACY CONTROL (GPC) & DO-NOT-TRACK (DNT)
  8. 8. HOW TO MANAGE, BLOCK & DELETE COOKIES
  9. 9. UPDATES TO THIS COOKIE POLICY
  10. 10. CONTACT US & PRIVACY INQUIRIES

1. WHAT ARE COOKIES & LOCAL STORAGE TECHNOLOGIES?

Cookies are small text files placed on your computer, smartphone, or tablet when you visit a website. Cookies are widely used by online services to make websites work efficiently, remember your login session, prevent cybersecurity attacks, and provide aggregated analytics.

In addition to traditional cookies, BudgetFitter utilizes modern client-side storage technologies:

  • HTML5 Local Storage (localStorage): Persistent key-value storage within your browser that remains intact until cleared. We use this strictly to save your UI preferences (such as dark/light mode) and offline deal bookmarks.
  • HTML5 Session Storage (sessionStorage): Ephemeral client storage that is automatically deleted the moment you close your active browser tab.
  • Mobile Secure Storage: Encrypted sandboxed storage (iOS Keychain and Android Keystore / EncryptedSharedPreferences) used within our native mobile apps to securely maintain your authentication session and Deal Feed subscriptions.

2. CATEGORIES OF TECHNOLOGIES WE USE

Under UK PECR and UK GDPR, we structure all tracking and storage technologies into clear functional categories:

A. Strictly Necessary Technologies (Essential)

These technologies are strictly necessary to deliver the Services, enable core navigation, ensure cybersecurity, and enforce rate-limiting. Under Regulation 6 of PECR, strictly necessary cookies do not require prior user consent. You cannot opt out of these technologies through our preference manager, but you can block them in your browser settings (which may cause parts of the Services to malfunction).

B. Functional & Preference Technologies

These technologies allow our platform to remember choices you make (such as your chosen display currency, followed merchant brands in your Deal Feed, and theme settings) to provide a tailored, seamless experience across visits.

C. Privacy-First First-Party Analytics

We believe in privacy by design. We utilize independent, first-party server-side analytics to understand aggregated traffic patterns, popular merchant factsheets, and platform performance. Our analytics do not perform cross-site behavioral profiling and do not export your data to commercial advertising networks.

3. DETAILED COOKIE & LOCAL STORAGE INVENTORY

The table below provides a comprehensive breakdown of the specific cookies and local storage tokens deployed across BudgetFitter:

Identifier / Key Type & Technology Duration / Expiry Purpose & Description
bf_auth_token Strictly Necessary (Cookie/JWT) Session (Persistent if “Remember Me” selected) Maintains your authenticated login session across page navigations via Google Firebase Identity Platform.
bf_consent_state Strictly Necessary (Cookie) 12 months Records your cookie preference and privacy banner consent choices under UK PECR.
__cf_bm / cf_clearance Strictly Necessary (Cloudflare Cookie) 30 minutes to 1 year Deployed by Cloudflare to manage edge security, mitigate malicious bot traffic, and prevent DDoS attacks.
bf_theme_preference Functional (localStorage) Persistent (Client-side) Remembers your selected UI display mode (Dark Mode or Light Mode).
bf_deal_feed_cache Functional (localStorage) Persistent (Client-side) Caches your followed merchant list locally to accelerate Deal Feed rendering on page load.
bf_currency_choice Functional (localStorage) Persistent (Client-side) Remembers your preferred currency display setting (GBP, USD, EUR).
bf_subid Performance / Attribution (URL Token / Session) 30 days Pseudonymous click routing identifier generated upon outbound link click to reconcile performance affiliate commissions.

4. BROWSER EXTENSION LOCAL STORAGE (MANIFEST V3)

The BudgetFitter Chromium Browser Extension operates strictly in accordance with Google Chrome Web Store Developer Policies and the Manifest V3 architecture:

  • Client-Side Storage Only: The Extension uses sandboxed chrome.storage.local strictly to cache our public directory of merchant domain names and remember user UI preferences (such as notification dismissals).
  • Zero Cookies & Zero History: The Extension DOES NOT read, set, or modify cookies on third-party websites, nor does it record or store your browsing history.

5. MOBILE APPLICATION SECURE STORAGE

Our native iOS and Android Mobile Applications do not use standard web tracking cookies. Instead, mobile app preferences and authentication state are managed through encrypted, device-level sandboxed storage:

  • Authentication Tokens: Stored securely within the Apple iOS Keychain or Android Keystore via Firebase Authentication.
  • Followed Brands & Saved Deals: Stored locally on your device within encrypted app data storage (AsyncStorage) and synchronized with our secure server only when you are signed in.

6. OUTCLICK ROUTING & THIRD-PARTY AFFILIATE COOKIES

When you click an offer, deal card, or “Activate Reward” button on BudgetFitter, you are routed through our redirection gateway (/go/{id}/). During this transition, a pseudonymous tracking identifier (bf_subid) is passed via query parameters to the partner merchant’s affiliate network (such as Awin, CJ, Impact, Rakuten, or Partnerize).

Merchant Domain Cookies: Once you land on the third-party merchant’s website, that merchant and their affiliate network may drop a performance tracking cookie on your device under their own domain. This cookie records that you originated from BudgetFitter so that the merchant can credit qualifying purchases and validate Ally Rewards missions. Third-party merchant cookies are governed entirely by the individual merchant’s own cookie and privacy policies.

7. GLOBAL PRIVACY CONTROL (GPC) & DO-NOT-TRACK (DNT)

BudgetFitter natively honours the Global Privacy Control (GPC) browser signal. If your browser or privacy extension transmits the GPC signal (Sec-GPC: 1) or standard Do-Not-Track header (DNT: 1), our platform automatically suppresses non-essential first-party analytics and respects your privacy preferences by default.

8. HOW TO MANAGE, BLOCK & DELETE COOKIES

You have the absolute right to decide whether to accept or reject cookies. You can exercise your preferences through several mechanisms:

A. Browser-Level Controls

Most modern web browsers allow you to view, manage, block, and delete cookies through their settings interfaces. Please visit the official help documentation for your specific browser:

Please note that blocking all cookies (including strictly necessary cookies) may prevent you from logging into your BudgetFitter account or maintaining Deal Feed synchronisation.

9. UPDATES TO THIS COOKIE POLICY

We may update this Cookie Policy from time to time to reflect operational, technological, or regulatory developments. Any modifications will become effective immediately upon updating the “Last updated” date at the top of this page.

10. CONTACT US & PRIVACY INQUIRIES

If you have any questions or concerns regarding our use of cookies, local storage, or data protection practices, please contact our Data Protection Officer:

FozDigital LTD (t/a BudgetFitter)
Attn: Data Protection Officer (DPO)
124 City Road, London, EC1V 2NX, United Kingdom
Email: [email protected]
Privacy Support: [email protected]
Web Contact: https://budgetfitter.uk/contact-us/