Legal
Cookie Policy
For the LLCR Platform (llcr-app.uk) and LLCR Marketing Website (llcr.uk)
Last updated: 18 August 2026
Download this policy as a PDF1. What Are Cookies?
1.1 Cookies are small text files that are placed on your device (computer, phone, or tablet) when you visit a website. They are widely used to make websites work, improve your experience, and provide information to the website owner.
1.2 We also use similar technologies such as localStorage and sessionStorage (which store data in your web browser) for the same purposes described in this Policy. When we refer to “cookies” in this Policy, we include these similar technologies.
2. Who We Are
2.1 This website is operated by LLCR Technologies Ltd, a company incorporated in England and Wales under company number 17167813, with its registered office at 28 Beaufort Court Admirals Way, London, United Kingdom, E14 9XL.
2.2 For data protection enquiries, email us at [email protected].
3. The Law on Cookies
3.1 The use of cookies is regulated by the Privacy and Electronic Communications Regulations 2003 (PECR), as amended by the Data (Use and Access) Act 2025. Where cookies process personal data, the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 also apply.
3.2 Under PECR, we must:
(a) tell you clearly and comprehensively what cookies we use and why; and
(b) obtain your consent before placing non-essential cookies on your device.
3.3 Cookies that are “strictly necessary” for the operation of the website, or that are stored only to give effect to something you have asked for, do not require your consent. We explain below which cookies fall into each category. One item on our Platform does require consent: the affiliate referral identifier described in section D. We ask for your consent before it is stored.
4. Cookies We Use
We use a small number of cookies and browser storage items. We do not use any advertising cookies.
A. Strictly Necessary Cookies
These cookies are essential for the Platform to function. Without them, you would not be able to log in or use the Service. We do not need your consent to use these cookies, but we tell you about them so you know what they do.
| Cookie name | Provider | Type | Duration | Purpose |
|---|---|---|---|---|
| sb-*-auth-token | Supabase | HTTP cookie | Session | Authenticates your session so the Platform knows you are logged in. Contains an encrypted token: we never store your password in this cookie. Where the token is large, it may be split across several cookies with the same name and a numbered suffix. |
| sb-*-auth-token-code-verifier | Supabase | HTTP cookie | Session | Used during the login process to verify your identity securely (PKCE flow). Deleted after login completes. |
| llcr_pw_reset | LLCR (first party) | HTTP cookie | 10 minutes | Set only when you start a password reset, to complete the reset securely. It cannot be read by scripts in the page and expires automatically. |
We also use an error-monitoring library (Sentry) that may store diagnostic session data in your browser while you use the Platform. When an error occurs, this lets us see what happened in the session so that we can fix the fault. It is used only to keep the Service working reliably and securely, and is not used for advertising or cross-site tracking.
B. Preference Cookies
These items remember choices you make to improve your experience. Under PECR, preferences stored in direct response to your own choice are exempt from the consent requirement.
| Name | Provider | Type | Duration | Purpose |
|---|---|---|---|---|
| llcr-theme | LLCR (first party) | localStorage | Persistent | Stores your light/dark mode preference so the correct theme is applied immediately when you open the Platform, without a visual flash. |
| llcr_font_size | LLCR (first party) | localStorage | Persistent | Stores your chosen dashboard text size. |
C. Functional Storage
These items exist only to deliver a feature you opened or to protect work you have started. They do not require consent because they store nothing beyond what is needed to do the thing you asked for.
| Name | Provider | Type | Duration | Purpose |
|---|---|---|---|---|
| llcr.property_wizard.draft.v1 | LLCR (first party) | sessionStorage | Current tab | Preserves a part-completed add-property form if you navigate away, so you do not lose your work. |
| ava_messages_v2 (and per-user variants) | LLCR (first party) | localStorage | Persistent | Keeps your recent Ava assistant conversation in your browser so it is continuous between pages. |
| ava_auto_opened_ and ava_property_detail_intro_ | LLCR (first party) | localStorage | Persistent | Remember that Ava's one-time introductory messages have already been shown, so they are not repeated. |
| ava_widget_session, ava_widget_session_user, ava_session_id, ava_session_user, ava_active_conversation | LLCR (first party) | sessionStorage | Current tab | Keep track of your current Ava session and which conversation is open. |
| llcr_referral_via_seen | LLCR (first party) | sessionStorage | Current tab | Notes that you arrived through a partner referral link in this tab, so we know to show you the referral choice described in section D. |
| llcr_referral_consent | LLCR (first party) | localStorage | Persistent | Records whether you allowed or declined the referral identifier in section D, so we do not ask you again and can honour your choice. |
D. Referral Cookies (Consent Required)
If you arrive at LLCR through one of our partners’ referral links, we would like to record which partner referred you, so that we can pay them a commission if you later subscribe. This is done by our affiliate platform, Rewardful.
| Name | Provider | Type | Duration | Purpose |
|---|---|---|---|---|
| Rewardful referral identifier | Rewardful (third party) | Cookie and/or localStorage, set by Rewardful's script | Set by Rewardful | Records which partner referred you, so that we can attribute your subscription to them and pay them correctly. |
This is the one item that requires your consent, because it exists for our benefit rather than to deliver something you asked for. It works like this:
(a) If you arrive through a partner referral link, we ask you before anything is stored. Rewardful's script is not loaded at all unless you agree.
(b) If you agree, your choice is recorded (section C) and the referral identifier is stored.
(c) If you decline, no referral identifier is stored, and this has no effect on your access to the Platform, the features available to you, or the price you pay.
(d) You can withdraw your consent at any time in your account settings.
E. Analytics
Our product analytics (PostHog, EU Cloud) run in cookieless mode. They do not place cookies or persistent identifiers on your device. If we ever change this, we will update this Policy and ask for your consent before any analytics cookie is placed.
F. Advertising and Tracking Cookies
We do not use advertising or tracking cookies. We do not share cookie data with advertisers. We have no plans to do so.
5. Third-Party Cookies
5.1 The third-party items on our Platform are the Supabase authentication cookies listed in section A, which exist solely to manage your login session, and the Rewardful referral identifier described in section D, which is stored only with your consent.
5.2 When you make a payment, you are redirected to Stripe's payment page. Stripe may place its own cookies on that page, which are governed by Stripe's own cookie policy. We do not control Stripe's cookies.
5.3 Our error monitoring (section A) is provided by Sentry, and any diagnostic data it stores in your browser is used only for fault diagnosis as described above.
6. How to Manage Your Cookies
6.1 We do not show a general cookie banner, because almost everything we store is strictly necessary, a preference you chose, or functional storage for a feature you opened. The one consent we need, for the referral identifier in section D, is asked for specifically when you arrive through a partner referral link, and you can change that choice at any time in your account settings.
6.2 You can delete or block cookies at any time through your browser settings. Here is how to do it in the most common browsers:
Google Chrome: Settings > Privacy and security > Cookies and other site data
Mozilla Firefox: Settings > Privacy & Security > Cookies and Site Data
Safari: Preferences > Privacy > Manage Website Data
Microsoft Edge: Settings > Cookies and site permissions > Manage and delete cookies
6.3 Please note that if you delete or block the Supabase authentication cookies, you will be logged out of the Platform and will need to log in again.
6.4 To remove the preference and functional items listed above, you can clear your browser's site data for llcr-app.uk (localStorage and sessionStorage, usually found in your browser's settings or developer tools). Doing so will reset your theme and text size to their defaults, clear any saved Ava conversation from your browser, and discard any part-completed property form.
7. Changes to This Policy
7.1 We will update this Policy if we change the cookies we use. If we introduce further non-essential cookies that require your consent, we will ask for your consent before placing them and, where appropriate, notify you by email.
7.2 We will update the “Last updated” date at the top of this Policy whenever we make changes.
8. More Information
8.1 For more information about how we process your personal data, please see our Privacy Policy at llcr.uk/privacy.html.
8.2 If you have any questions about our use of cookies, please contact us at [email protected].
8.3 For independent advice about cookies and online privacy, you can visit the Information Commissioner’s Office (ICO) at ico.org.uk.