V
VaxiGo
Legal

Cookie Policy

This policy explains how VaxiGo uses cookies and similar technologies on vaxigo.co.uk, and how you can manage your choices.

Last updated: 14 July 2026

This Cookie Policy explains how VaxiGo uses cookies and similar technologies on our website at vaxigo.co.uk (the “Site”). VaxiGo is an online platform where members of the public search for and book vaccination appointments at pharmacies and travel clinics across the UK. Because our service involves the processing of special category (health) data, we apply a high standard of care to how we use cookies. This policy supplements, and should be read together with, our Privacy Policy.

Introduction

Cookies are small text files that a website places on your device (computer, tablet or phone) when you visit it. They are widely used to make websites work, to make them work more efficiently, and to provide information to the site’s operator.

We also use similar technologies that do not rely on traditional cookies but perform comparable functions, including:

  • browser local storage, which allows small amounts of information to be stored in your browser and kept until it is cleared; and
  • browser session storage, which stores information only for the duration of a single browsing session and is cleared when you close the tab or browser.

Throughout this policy, references to “cookies” include these similar technologies unless we say otherwise.

Legal basis and consent

Our use of cookies is governed by the Privacy and Electronic Communications Regulations 2003 (PECR) and, where cookies involve the processing of personal data, the UK General Data Protection Regulation (UK GDPR).

Under PECR, cookies that are strictly necessary to provide a service you have requested are exempt from the requirement to obtain consent. We set strictly necessary cookies without asking for your consent, because without them the Site cannot function and you would be unable to sign in or complete a booking.

For all other categories of cookie, we set them only with your prior, informed and granular consent. This means:

  • we do not set non-essential cookies until you have chosen to allow them;
  • we tell you what each category of cookie does before you decide; and
  • you can consent to some categories and refuse others, rather than having to accept or reject everything together.

When you first visit the Site, we present a cookie banner that gives equal prominence to an “Accept all” option and a “Reject non-essential” option, so that accepting and rejecting are equally easy. The banner also gives you access to a preferences centre, where you can review each category and make granular choices.

You can withdraw or change your consent at any time using the Cookie settings link in the footer of every page. Withdrawing consent is as easy as giving it. We will also re-request your consent at least every 13 months, so that your choices are refreshed and remain current.

Cookies and similar technologies we use

The tables below list the cookies and similar technologies we use, grouped by category. Each table shows the name, provider, purpose, category and duration.

Strictly necessary — authentication (first-party, set by VaxiGo)

These cookies keep you securely signed in and protect sign-in actions. On our live HTTPS site these cookies carry the __Secure- or __Host- prefixes, which instruct the browser to apply additional security protections.

NameProviderPurposeCategoryDuration
__Secure-authjs.session-tokenVaxiGoEncrypted session token that keeps a signed-in user logged inStrictly necessaryUp to 30 days
__Host-authjs.csrf-tokenVaxiGoCross-site request forgery protection for sign-in actionsStrictly necessarySession (expires on browser close)
__Secure-authjs.callback-urlVaxiGoStores the page to return the user to after sign-inStrictly necessarySession
__Secure-authjs.pkce.code_verifier, __Secure-authjs.state, __Secure-authjs.nonceVaxiGoTransient security tokens used only during Google/Apple sign-inStrictly necessaryShort-lived (approx. 15 minutes)

Strictly necessary — consent management (first-party)

This cookie records the cookie choices you make so that we can honour them.

NameProviderPurposeCategoryDuration
vaxigo-consentVaxiGoRecords the user’s own cookie consent choices (as JSON, with a version and timestamp)Strictly necessary395 days (approx. 13 months)

Strictly necessary — payment and fraud prevention (third-party, set by Stripe)

These cookies are set by Stripe on the .stripe.com domain and are loaded only on the booking/payment page. They help prevent fraudulent transactions.

NameProviderPurposeCategoryDuration
__stripe_midStripeStripe fraud prevention, persistent device identifierStrictly necessaryApprox. 1 year
__stripe_sidStripeStripe fraud prevention, session identifierStrictly necessaryApprox. 30 minutes

Functional — browser local and session storage (first-party, not shared with third parties)

These items are stored in your browser’s local or session storage to remember your preferences and improve your experience. They are not shared with third parties.

NameProviderPurposeCategoryDuration
vaxigo:lastArea (local storage)VaxiGoRemembers the user’s last searched area to prefill searchFunctionalPersistent until cleared
vaxigo:lastCountry (local storage)VaxiGoRemembers the last viewed travel destination for personalisationFunctionalPersistent until cleared
vaxfinder_clinic_type (local storage)VaxiGoRemembers the selected clinic type (travel vs pharmacy)FunctionalPersistent until cleared
vaxigo:geoAsked (session storage)VaxiGoEnsures the location permission prompt is only shown once per sessionFunctionalClears when the tab closes

Third-party services

Some features of the Site load services provided by third parties. Those third parties may set their own cookies on their own domains, which are governed by their own cookie and privacy policies. We provide links to those policies below.

  • Stripe (payment processing and fraud prevention) — loads only when you reach the booking/payment step. See stripe.com/gb/cookies-policy/legal.
  • Google and Apple sign-in — when you choose to sign in with Google or Apple, those providers may set cookies on their own domains (for example, accounts.google.com or appleid.apple.com) as part of the sign-in process. See Google and Apple.
  • Google Maps — used to display maps and location search on our clinic search and results pages. Google may set cookies via this service. This is a third-party functional service. Note: we are currently reviewing whether Google Maps should be gated behind consent, and will update this policy accordingly. See Google’s cookie information.
  • Vercel (website hosting and infrastructure) — our Site is hosted on Vercel’s infrastructure. Vercel may process technical data (including server logs and IP addresses) as part of delivering the Site. See Vercel’s privacy policy.

Analytics and marketing

VaxiGo does not currently use any analytics, advertising or marketing cookies, and we do not run any paid advertising.

Our preferences centre includes “Analytics” and “Marketing” categories, which are reserved for potential future use. If we decide to introduce any such technologies, we will only activate them where you have given your consent, and we will update this policy first so that you know what will be used before it is switched on.

How to manage or withdraw consent

You can manage or withdraw your consent at any time in the following ways:

  • using the Cookie settings link in the footer of every page, which opens our preferences centre where you can change your choices by category; and
  • using your browser settings, which allow you to block or delete cookies. Guidance on how to do this is usually available in your browser’s help pages.

Please note the effect of disabling cookies: strictly necessary cookies are required for the Site to work. If you block strictly necessary cookies, you will be unable to sign in or complete a booking. Disabling functional storage will not prevent you from using the Site, but some conveniences (such as remembering your last searched area) will no longer work.

Do Not Track and Global Privacy Control

Some browsers offer a “Do Not Track” (DNT) setting or a Global Privacy Control (GPC) signal that tells websites you do not wish to be tracked. There is currently no agreed industry standard for how websites should respond to these signals. Because we do not use tracking, analytics, advertising or marketing cookies, our approach to consent and non-essential cookies is the same whether or not you send a DNT or GPC signal. If we introduce technologies that would respond to these signals in future, we will explain our approach in this policy.

International data transfers

Some of the third-party providers referred to in this policy (for example, Vercel, Stripe, Google and Apple) may process data outside the UK. Where personal data is transferred outside the UK, we and those providers rely on appropriate safeguards to protect your data. Specifically, we rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the UK International Data Transfer Agreement (IDTA) or the International Data Transfer Addendum to the EU Standard Contractual Clauses, as set out in each provider’s data processing terms. Further information about international transfers is set out in our Privacy Policy.

Changes to this policy

We may update this policy from time to time, for example to reflect changes in the cookies we use, changes in the law or updated ICO guidance. When we make material changes, we will update the “Last updated” date at the top of this policy and, where appropriate, we will notify you through the Site or by re-requesting your consent. We encourage you to review this policy periodically.

Contact and complaints

If you have any questions about this policy or about how we use cookies, please contact our Data Protection Officer:

George Harris, Data Protection Officer
Email: dpo@vaxigo.co.uk

VaxiGo is registered with the Information Commissioner’s Office (ICO) under registration number ZC177441. You also have the right to complain to the ICO, the UK supervisory authority for data protection issues, if you are concerned about how we handle your personal data. You can contact the ICO at ico.org.uk.