Cookie Policy
Last updated 16 August 2026
Companies House IM uses a small number of strictly necessary cookies to operate. We do not use advertising or third-party tracking cookies.
Cookies we set
- Session cookie — keeps you signed in after you use a magic link. Essential for authenticated areas.
- CSRF token — protects forms and requests against cross-site request forgery. Essential for security.
- Theme preference — remembers your light/dark choice. Stored in your browser; set only when you toggle the theme.
Cookies set by Stripe
When you visit the billing page to add or update a payment method, we load Stripe's payment library, which sets its own cookies (such as __stripe_mid and __stripe_sid) to detect and prevent payment fraud. They are necessary for taking payment securely and are not used for advertising or analytics. They are not set on pages that do not involve payment. Stripe's use of them is described in Stripe's own privacy policy.
Managing your subscription opens Stripe's customer portal, which is hosted by Stripe on its own domain and governed by Stripe's cookie and privacy policies.
Cookies set by Cloudflare
Cloudflare sits in front of the Service to protect it from attack and abuse. It sets __cf_bm, a bot-management cookie that expires after about 30 minutes, and — if a visitor is challenged — cf_clearance, which records that the challenge was passed.
These are strictly necessary for the security and availability of the Service, so they are set without asking for consent. They are not used for advertising or cross-site tracking.
Managing cookies
Because these cookies are essential to the Service, disabling them in your browser may prevent sign-in, payment, or other functionality. We do not use any advertising or analytics cookies, so no consent banner is required.
Changes
If we introduce additional cookies in future, we will update this policy and seek consent where required.