Key information
- Operator and data controller
- SUPER BASIC LIMITED, company number 16274977
- Registered office
- CF5 The Terrace, Grantham Street, Lincoln, England, LN2 1BD
- Policy applies to
- superbasic.net and each Super Basic website or app that links to this policy, including QR8.to, Linkads.to, Bookin.to, Entry.to, Justinvoice.to and Payup.to
- Privacy contact
- support@superbasic.net
- Support contact
- support@superbasic.net
- Cookie settings
- The Cookie Settings or Privacy Settings link displayed in the footer, account area or consent panel of the relevant website or app
- Related document
- Privacy Notice at superbasic.net/legal/privacy
- Policy URL
- superbasic.net/legal/cookies
- Version and effective date
- 14 June 2026
Plain-English summary
- We use essential storage and access technologies to operate accounts, protect security, remember choices and provide features that a visitor requests.
- Optional analytics, advertising and third-party technologies will not be used unless we have a valid legal basis under the Privacy and Electronic Communications Regulations 2003, including consent where required.
- Where we rely on the statistical or appearance exceptions rather than consent, we provide clear information and a simple, free way to object.
- You can change optional choices at any time through Cookie Settings. Rejecting optional technologies should not prevent use of the core service, although some optional features may not work.
- The exact technologies in use can differ between apps. The live Cookie Settings panel for each domain is part of this policy and should contain the current names, providers, purposes and durations.
1. About this policy
1.1 This Cookie Policy explains how Super Basic uses cookies and other technologies that store information on, or access information from, a visitor's device. It applies to the public websites, account areas, dashboards, customer pages and end-user pages that link to it.
1.2 In this policy, "cookies" is used as a convenient collective term. The legal rules can also apply to local storage, software development kits, pixels, tracking links, scripts, tags, device identifiers, fingerprinting and similar storage or access technologies.
1.3 This policy should be read with our Privacy Notice. The Privacy Notice explains how we use personal data, our lawful bases, sharing, international transfers, retention and individual rights.
1.4 A Super Basic customer may publish a page using one of our Apps. That customer may be responsible for additional technologies or embedded content that it chooses to add. Where this happens, the customer must give its visitors any additional information and choices required by law.
2. What cookies and similar technologies do
2.1 Cookies are small data files stored by a browser or device. They can help a service recognise a session, keep a user signed in, remember settings, secure a checkout, measure service performance or support third-party content.
2.2 Some technologies operate only during a browser session and disappear when the browser closes. Others remain for a stated period or until the user removes them.
2.3 First-party technologies are set or controlled through the domain being visited. Third-party technologies are provided by another organisation, such as a payment, hosting, fraud-prevention, analytics or embedded-content provider. The legal treatment depends on the purpose and operation, not simply whether a technology is labelled first-party or third-party.
3. When we ask for consent
3.1 We do not need consent where a technology is used solely to transmit a communication or is strictly necessary to provide a service expressly requested by the user. Examples can include authentication, session management, load balancing, security, fraud prevention, checkout operation and remembering a cookie choice.
3.2 UK law also contains limited exceptions for technologies used solely for statistical purposes to improve a service, or to adapt its appearance or functionality to a user preference. Where we rely on either exception, we will provide clear information and a simple, free means of objecting.
3.3 We will request prior consent for non-exempt purposes. This normally includes behavioural advertising, cross-service tracking, individual visitor profiling, advertising conversion tracking, session replay used beyond security, social-media tracking and optional third-party technologies that use information for their own purposes.
3.4 Consent is optional, specific to the purposes shown and can be withdrawn at any time. Refusing or withdrawing consent does not affect the lawfulness of use before withdrawal.
4. Categories of technology we may use
Each category below lists its typical purpose, the legal approach under PECR, a typical duration and whether it can be disabled. The live Cookie Settings panel for each domain holds the authoritative current detail.
Essential service and session
- Typical purpose
- Operate requested pages, route traffic, maintain sessions, process forms and provide core functionality.
- Legal approach (PECR)
- Communication or strictly necessary exception.
- Typical duration
- Session or the shortest period reasonably required.
- Can it be disabled?
- No, where genuinely necessary for the requested service.
Account and authentication
- Typical purpose
- Sign in, maintain an authenticated session, support account recovery and protect access.
- Legal approach (PECR)
- Strictly necessary exception.
- Typical duration
- Session or a limited persistent period for recognised-device or security features.
- Can it be disabled?
- Not while using the relevant account feature.
Security and fraud prevention
- Typical purpose
- Detect abuse, protect accounts, prevent fraud, enforce rate limits and support incident investigation.
- Legal approach (PECR)
- Strictly necessary where proportionate and used solely for security or legal compliance.
- Typical duration
- Varies according to the security purpose and risk.
- Can it be disabled?
- Usually no, where necessary and proportionate.
Consent and privacy preferences
- Typical purpose
- Remember whether optional purposes were accepted, rejected or objected to.
- Legal approach (PECR)
- Strictly necessary or based on the user interaction with the preference mechanism.
- Typical duration
- Normally up to 12 months, then refreshed where appropriate.
- Can it be disabled?
- The preference itself can be changed, but a record may be needed to remember it.
Appearance and functional preferences
- Typical purpose
- Remember language, display, theme, accessibility or interface choices.
- Legal approach (PECR)
- Appearance exception with a simple free objection, or consent if the exception does not apply.
- Typical duration
- Session or normally up to 12 months.
- Can it be disabled?
- Yes, through Cookie Settings or the relevant feature setting.
Statistical service analytics
- Typical purpose
- Produce aggregate statistics about visits and interactions to improve the service.
- Legal approach (PECR)
- Statistical purposes exception only where all requirements are met and a simple free objection is offered; otherwise consent.
- Typical duration
- Individual-level information retained only as long as needed to aggregate; aggregate results may be retained longer.
- Can it be disabled?
- Yes, through Cookie Settings.
Payments and checkout
- Typical purpose
- Load and secure checkout, detect payment fraud and complete a payment requested by the user.
- Legal approach (PECR)
- Often strictly necessary for the requested payment service; any separate provider analytics or advertising requires its own basis.
- Typical duration
- Set by the payment provider and limited to its stated purpose.
- Can it be disabled?
- Core payment technologies may be necessary to complete payment.
Embedded or connected services
- Typical purpose
- Display maps, videos, fonts, calendars, social content or other third-party features.
- Legal approach (PECR)
- Consent unless an exception applies or the technology is activated only when the user requests the content after clear notice.
- Typical duration
- Set by the provider and shown in Cookie Settings.
- Can it be disabled?
- Usually yes, but the embedded feature may then be unavailable.
Advertising and marketing
- Typical purpose
- Measure adverts, build audiences, personalise advertising or track activity across services.
- Legal approach (PECR)
- Prior consent. The statistical and appearance exceptions do not cover online advertising.
- Typical duration
- Shown in Cookie Settings and controlled by consent.
- Can it be disabled?
- Yes.
5. The live cookie schedule
5.1 Because the Super Basic Apps are separate services and may change providers or technical components, a static list in this document can become inaccurate. The live Cookie Settings panel on each relevant domain forms part of this policy and should identify, so far as applicable:
- the cookie, local-storage key, script, pixel, tag or other technology name;
- the provider or controller;
- the purpose and category;
- whether it is essential, exempt with an objection mechanism, or consent-based;
- its duration or expiry; and
- a link or method for changing the user's choice.
5.2 We will review the live schedule when a technology, provider or purpose is added or materially changed. Optional technologies must not be enabled before the relevant consent is obtained, unless a valid exception applies.
5.3 If the live schedule and this general policy conflict about a particular technology, the more specific live schedule applies to that technology, but it cannot remove a right provided by law.
6. Analytics
6.1 We may use privacy-focused analytics to understand matters such as total visits, page use, device or browser type, broad user journeys, load performance and aggregated interactions.
6.2 We may rely on the statistical purposes exception only where the sole purpose is producing aggregate statistical information to improve the service, individual visitors are not tracked or profiled, individual-level information is not kept after aggregation, any third-party provider acts only on our behalf for that purpose, and users have a simple and free way to object.
6.3 Where an analytics configuration goes beyond those limits, including advertising measurement, cross-service tracking, persistent visitor profiles, conversion sharing or session replay not used solely for proportionate security, we will obtain prior consent.
7. Payments, integrations and embedded content
7.1 Some Apps use third-party payment providers, including Stripe where shown at checkout. Those providers may use technologies necessary to authenticate a payment, prevent fraud and operate the checkout requested by the user. Their own privacy information may also apply.
7.2 We may integrate services such as email delivery, calendars, maps, video players or social platforms. Where possible, we configure optional integrations not to load non-essential technologies until the user has consented or actively requested the content after receiving clear notice.
7.3 A Customer must not add unauthorised tracking technologies, pixels, scripts or embedded services to a Super Basic page. If a feature permits a Customer-controlled integration, the Customer is responsible for ensuring it is lawful and properly disclosed.
8. Advertising and Linkads.to
8.1 Linkads.to may display an interstitial, sponsor message, banner or destination link selected by a Customer. Displaying content does not by itself mean that Super Basic uses behavioural advertising cookies.
8.2 If advertising or campaign measurement uses storage or access technologies to identify visitors, measure advert interactions at individual level, share conversions, build audiences or track people across services, those technologies require prior consent unless another lawful and clearly applicable rule permits the specific use.
8.3 Customers using Linkads.to remain responsible for their advertising content, targeting instructions, disclosures and any Customer-controlled destination tracking. Super Basic may block integrations that create legal, security or privacy risks.
9. Your choices
9.1 You can use Cookie Settings to:
- accept or reject consent-based purposes;
- object to statistical or appearance technologies where we rely on an exception;
- review the current providers and durations; and
- withdraw or change a previous choice.
9.2 Reject and accept options should be presented with comparable prominence. We do not treat silence, continued browsing or a pre-ticked consent box as valid consent.
9.3 If you clear browser storage or use another browser or device, we may not recognise the earlier choice and may ask again.
9.4 Browser and device settings may also block or delete technologies. Blocking essential technologies can prevent sign-in, checkout, security controls or other requested features from working. Browser controls are not a substitute for the choices we are required to provide on our service.
10. Personal data and international transfers
10.1 Information collected through these technologies may be personal data, including an online identifier, IP address, device information, account identifier or activity connected with an identifiable person.
10.2 Our Privacy Notice explains the purposes, lawful bases, recipients, retention, international-transfer safeguards and rights that apply when personal data is processed.
10.3 Where a Super Basic Customer determines the purpose of data collected from its End Users, the Customer may be the controller and Super Basic may act as its processor. The Customer must provide its own suitable privacy information. Our Data Processing Agreement governs processing carried out on the Customer's documented instructions.
11. Retention
11.1 We keep a technology or the information it produces only for as long as reasonably necessary for its stated purpose, legal obligations, security, dispute handling or the establishment, exercise or defence of legal claims.
11.2 The live Cookie Settings panel gives the expiry period for persistent technologies. Session technologies normally expire when the session or browser closes, although server-side security records may be retained separately under the Privacy Notice and retention schedule.
11.3 Where we rely on the statistical purposes exception, we will not retain individual-level information longer than needed to produce aggregate statistical results.
12. Changes to this policy
12.1 We may update this policy when the law, guidance, Apps, providers or technical uses change. The version date at the beginning identifies the current version.
12.2 If a change introduces a new non-exempt purpose, we will obtain fresh consent before enabling it for users who have not already consented to that purpose. We may notify account holders of material changes by email, in-product message or a prominent website notice.
13. Contact and complaints
13.1 Questions or requests about this policy can be sent to support@superbasic.net. General product support can be sent to support@superbasic.net or raised through the feedback form in the relevant App.
13.2 Individuals also have the right to complain to the Information Commissioner's Office about data protection or PECR concerns. We would appreciate the opportunity to investigate and respond first.