This policy explains how VaxiGo uses cookies and similar technologies on vaxigo.co.uk, and how you can manage your choices.
This Cookie Policy explains how VaxiGo uses cookies and similar technologies on our website at vaxigo.co.uk (the “Site”). VaxiGo is an online platform where members of the public search for and book vaccination appointments at pharmacies and travel clinics across the UK. Because our service involves the processing of special category (health) data, we apply a high standard of care to how we use cookies. This policy supplements, and should be read together with, our Privacy Policy.
Cookies are small text files that a website places on your device (computer, tablet or phone) when you visit it. They are widely used to make websites work, to make them work more efficiently, and to provide information to the site’s operator.
We also use similar technologies that do not rely on traditional cookies but perform comparable functions, including:
Throughout this policy, references to “cookies” include these similar technologies unless we say otherwise.
Our use of cookies is governed by the Privacy and Electronic Communications Regulations 2003 (PECR) and, where cookies involve the processing of personal data, the UK General Data Protection Regulation (UK GDPR).
Under PECR, cookies that are strictly necessary to provide a service you have requested are exempt from the requirement to obtain consent. We set strictly necessary cookies without asking for your consent, because without them the Site cannot function and you would be unable to sign in or complete a booking.
For all other categories of cookie, we set them only with your prior, informed and granular consent. This means:
When you first visit the Site, we present a cookie banner that gives equal prominence to an “Accept all” option and a “Reject non-essential” option, so that accepting and rejecting are equally easy. The banner also gives you access to a preferences centre, where you can review each category and make granular choices.
You can withdraw or change your consent at any time using the Cookie settings link in the footer of every page. Withdrawing consent is as easy as giving it. We will also re-request your consent at least every 13 months, so that your choices are refreshed and remain current.
The tables below list the cookies and similar technologies we use, grouped by category. Each table shows the name, provider, purpose, category and duration.
These cookies keep you securely signed in and protect sign-in actions. On our live HTTPS site these cookies carry the __Secure- or __Host- prefixes, which instruct the browser to apply additional security protections.
| Name | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
| __Secure-authjs.session-token | VaxiGo | Encrypted session token that keeps a signed-in user logged in | Strictly necessary | Up to 30 days |
| __Host-authjs.csrf-token | VaxiGo | Cross-site request forgery protection for sign-in actions | Strictly necessary | Session (expires on browser close) |
| __Secure-authjs.callback-url | VaxiGo | Stores the page to return the user to after sign-in | Strictly necessary | Session |
| __Secure-authjs.pkce.code_verifier, __Secure-authjs.state, __Secure-authjs.nonce | VaxiGo | Transient security tokens used only during Google/Apple sign-in | Strictly necessary | Short-lived (approx. 15 minutes) |
This cookie records the cookie choices you make so that we can honour them.
| Name | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
| vaxigo-consent | VaxiGo | Records the user’s own cookie consent choices (as JSON, with a version and timestamp) | Strictly necessary | 395 days (approx. 13 months) |
These cookies are set by Stripe on the .stripe.com domain and are loaded only on the booking/payment page. They help prevent fraudulent transactions.
| Name | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
| __stripe_mid | Stripe | Stripe fraud prevention, persistent device identifier | Strictly necessary | Approx. 1 year |
| __stripe_sid | Stripe | Stripe fraud prevention, session identifier | Strictly necessary | Approx. 30 minutes |
These items are stored in your browser’s local or session storage to remember your preferences and improve your experience. They are not shared with third parties.
| Name | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
| vaxigo:lastArea (local storage) | VaxiGo | Remembers the user’s last searched area to prefill search | Functional | Persistent until cleared |
| vaxigo:lastCountry (local storage) | VaxiGo | Remembers the last viewed travel destination for personalisation | Functional | Persistent until cleared |
| vaxfinder_clinic_type (local storage) | VaxiGo | Remembers the selected clinic type (travel vs pharmacy) | Functional | Persistent until cleared |
| vaxigo:geoAsked (session storage) | VaxiGo | Ensures the location permission prompt is only shown once per session | Functional | Clears when the tab closes |
Some features of the Site load services provided by third parties. Those third parties may set their own cookies on their own domains, which are governed by their own cookie and privacy policies. We provide links to those policies below.
VaxiGo does not currently use any analytics, advertising or marketing cookies, and we do not run any paid advertising.
Our preferences centre includes “Analytics” and “Marketing” categories, which are reserved for potential future use. If we decide to introduce any such technologies, we will only activate them where you have given your consent, and we will update this policy first so that you know what will be used before it is switched on.
You can manage or withdraw your consent at any time in the following ways:
Please note the effect of disabling cookies: strictly necessary cookies are required for the Site to work. If you block strictly necessary cookies, you will be unable to sign in or complete a booking. Disabling functional storage will not prevent you from using the Site, but some conveniences (such as remembering your last searched area) will no longer work.
Some browsers offer a “Do Not Track” (DNT) setting or a Global Privacy Control (GPC) signal that tells websites you do not wish to be tracked. There is currently no agreed industry standard for how websites should respond to these signals. Because we do not use tracking, analytics, advertising or marketing cookies, our approach to consent and non-essential cookies is the same whether or not you send a DNT or GPC signal. If we introduce technologies that would respond to these signals in future, we will explain our approach in this policy.
Some of the third-party providers referred to in this policy (for example, Vercel, Stripe, Google and Apple) may process data outside the UK. Where personal data is transferred outside the UK, we and those providers rely on appropriate safeguards to protect your data. Specifically, we rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the UK International Data Transfer Agreement (IDTA) or the International Data Transfer Addendum to the EU Standard Contractual Clauses, as set out in each provider’s data processing terms. Further information about international transfers is set out in our Privacy Policy.
We may update this policy from time to time, for example to reflect changes in the cookies we use, changes in the law or updated ICO guidance. When we make material changes, we will update the “Last updated” date at the top of this policy and, where appropriate, we will notify you through the Site or by re-requesting your consent. We encourage you to review this policy periodically.
If you have any questions about this policy or about how we use cookies, please contact our Data Protection Officer:
George Harris, Data Protection Officer
Email: dpo@vaxigo.co.uk
VaxiGo is registered with the Information Commissioner’s Office (ICO) under registration number ZC177441. You also have the right to complain to the ICO, the UK supervisory authority for data protection issues, if you are concerned about how we handle your personal data. You can contact the ICO at ico.org.uk.