Cookies and browser storage
Version 1.0 · Last updated 6 September 2026
The short version
- We run no analytics, no advertising pixels and no cross-site tracking. Not on the website, not in the app, not in the customer portal. There is nothing here that profiles you or follows you to another site.
- The website sets no cookies at all. It stores one small value in your browser's own local storage, described in §2: a note that you dismissed the storage notice.
- The app and the customer portal set exactly two cookies, both first-party and both needed to sign you in safely. There is no "remember me" cookie.
- The public booking page stores nothing whatsoever.
- Nothing we store anywhere requires your consent. Every item in this policy is either strictly necessary or a record of a choice you made yourself, so there is no consent banner to click through and nothing to withdraw.
- We never sell personal data and never share it for advertising.
1. What this policy covers
The law here is not limited to cookies. It applies to any storing of information on, or reading of information from, your device — cookies, localStorage, sessionStorage and similar technologies. This policy therefore lists all of them, not only cookies.
Two categories are used throughout:
- Strictly necessary — required to deliver a service you explicitly asked for (signing in, keeping a form you are typing, protecting a form against forgery), or storing nothing but a choice you yourself made. These do not require your consent.
- Consent required — everything else, including anything that serves our commercial purposes rather than yours.
We apply the EU/Irish test everywhere, including for visitors in the UK. UK law (PECR as amended by the Data (Use and Access) Act 2025) allows three further exceptions — statistical/analytics, appearance and functionality, and emergency location — which Irish law does not. Applying the stricter test uniformly means one rule, one behaviour, and no visitor gets a weaker standard than another.
2. The marketing website (Field 2 Service)
Cookies set: none. The website has one server-side endpoint (the contact form) and it is deliberately session-free; nothing in the site's code writes a cookie.
Third-party resources loaded: none. Every font, stylesheet, script and image is served from our own domain. No content delivery network, no embedded video, no social widget, no hosted font service. Nothing about your visit is disclosed to another company by the act of loading a page.
The site stores one value in your browser's local storage. Local storage stays on your device — it is never transmitted with page requests the way a cookie is.
| Name | Type | Party | Purpose | Lifetime | Classification |
|---|---|---|---|---|---|
rfp_cookie_ok | localStorage | First party | Remembers that you dismissed the storage notice, so it is not shown again | Until you clear your browser storage | Strictly necessary — stores only your own choice |
Nothing else is written, and nothing is written for our benefit. If you arrive on a partner or campaign link containing ?ref= or ?promo=, that code stays in the web address as you move between pages on this site and is read from the address at the moment you submit the sign-up form, so the partner who introduced you is credited. It is not stored in your browser, and if you never submit the form it is never recorded at all.
A visitor arriving at Field 2 Service — directly, from a search result or from a partner link — has nothing at all written to their device except rfp_cookie_ok, and only then if the notice is dismissed.
3. The Field 2 Service application (your staff)
These apply to people signed in to the application: your own staff and administrators.
3.1 Cookies
| Name | Type | Party | Purpose | Lifetime | Classification |
|---|---|---|---|---|---|
ci_session | HTTP cookie | First party | Keeps you signed in and carries confirmation and error messages between pages | 2 hours; the session identifier is rotated every 5 minutes while you are active | Strictly necessary |
csrf_cookie_name | HTTP cookie | First party | Cross-site request forgery token — proves that a form submission came from a page we served, not from another site acting as you | 2 hours | Strictly necessary |
Both are set with HttpOnly (unreadable by scripts), SameSite=Lax (not sent on cross-site requests) and, in production, Secure (sent over HTTPS only). Neither is used for tracking, and neither survives a sign-out.
There is no "remember me" cookie, no analytics cookie and no advertising cookie anywhere in the application. These two are the only cookies the software sets.
3.2 Local storage — settings and working state
All first-party. None of it is transmitted to us as a cookie would be; it stays in the browser it was written in, on that one device.
| Name | Purpose | Lifetime | Classification |
|---|---|---|---|
rk-theme, rfs_hub_theme | Light or dark appearance you chose | Until cleared | Strictly necessary — your own choice |
rfs-sidebar-collapsed-{user id}, rk-plat-sidebar-collapsed | Whether you collapsed the sidebar | Until cleared | Strictly necessary — your own choice |
rfs_disp_view, rfs_disp_tray_open, rfs_ops_filter | The dispatch/operations view, tray state and filter you last selected | Until cleared | Strictly necessary — your own choice |
rfs_cols_{list} | Column order and widths you set on a list page | Until cleared | Strictly necessary — your own choice |
rfs-palette-recent-{user id} | Your recently used command-palette entries | Until cleared | Strictly necessary — your own choice |
rfs-dismiss:{banner} | A banner you dismissed. The key contains the figure and date it referred to, so the banner reappears when either changes | Until the underlying figure or day changes | Strictly necessary — your own choice |
fldraft:{form}, fldraft::pending | An unsaved form you are typing, so a refresh or a failed save does not lose your work. Excludes passwords, file uploads and the security token. May contain customer details you have typed | 7 days, enforced in the script | Strictly necessary — supports the function you requested |
rfs_ai_convo_v3_{user id} and its _ts timestamp | Your recent AI assistant conversation, so it survives moving between pages. Capped at the most recent 24 messages. May contain customer details returned by the assistant | Cleared automatically after 10 minutes of inactivity, and on sign-out | Strictly necessary — supports the function you requested |
Every item in this table is strictly necessary. The staff application stores nothing in your browser that requires your consent.
3.3 Session storage — cleared when you close the tab
| Name | Purpose | Classification |
|---|---|---|
data-sidebar-size, data-bs-theme | Keeps the layout and theme consistent while the tab is open | Strictly necessary |
rfsTrialBannerDismissed | Trial banner dismissed for this tab | Strictly necessary — your own choice |
rfsGeo:{address}, rfsDir:{coordinates} | Cached map coordinates and driving paths for the dispatch map, so the same address is not looked up repeatedly | Strictly necessary — supports the map you opened, and reduces the data sent to the mapping provider |
3.4 Third parties the staff application contacts
The application itself sets no third-party storage, but loading certain screens causes your browser to request resources from these companies. Those requests disclose your IP address and browser details to them, and they may set their own storage under their own policies, which we do not control.
| Third party | What loads it | What it receives |
|---|---|---|
Google Fonts (fonts.googleapis.com, fonts.gstatic.com) | The brand wordmark typeface on every signed-in page | Your IP address and browser details |
Google Maps JavaScript & Places (maps.googleapis.com) | Address autocomplete and the dispatch map — only when your workspace has a Maps key configured | Your IP address, browser details, and the address text being looked up |
Google Maps embed (www.google.com/maps/embed) | The location map on a job page | Your IP address, browser details, and the job location shown |
These three are the only third parties the staff application contacts from your browser, and none of them appear on customer-facing pages. They are in the staff application only.
4. The customer portal (your customers)
The portal is the surface your own customers sign in to.
- Cookies:
ci_sessionandcsrf_cookie_nameonly, exactly as described in §3.1. Both strictly necessary. - Local storage:
fldraft:{form}andfldraft::pendingonly — the same 7-day form-draft protection described in §3.2, so a customer editing their contact details does not lose them to a refresh. - Third-party resources: none. The portal loads no external font, script, map, analytics or advertising resource of any kind. Nothing about a customer's visit is disclosed to another company.
5. The public booking page
The booking page a business embeds on its own website stores nothing at all: no cookie, no local storage, no session storage, and no third-party resource. It is a single self-contained page that re-displays what you typed straight from your own submission.
6. What we do not do
- No analytics, product analytics, session recording or heatmaps.
- No advertising or retargeting pixels, and no advertising networks.
- No cross-site or cross-device tracking, and no third-party tracking cookies.
- We never sell personal data and never share it for advertising.
- No profiling based on your browsing, and no automated decisions made from any of the storage listed here.
Because we set no advertising or analytics storage, there is nothing on our sites for a "Do Not Track" or Global Privacy Control signal to switch off. We do not read those signals, and we say so rather than imply a control we do not operate — the outcome the signal exists to produce is the outcome you already get. If we ever add anything such a signal would control, we will implement signal handling first.
7. How to control what is stored
- Clear it yourself, at any time. Every browser can clear cookies and site data for a single site. Doing so removes everything listed in this policy for that site.
- Block it. You may block cookies and site storage in your browser settings. The strictly necessary items cannot be replaced: with cookies blocked you will not be able to sign in to the application or the customer portal, and forms will be rejected. The marketing website and the public booking page will still work.
- There is nothing here to consent to, and so nothing to withdraw. Everything listed in this policy is either strictly necessary or a record of a choice you made yourself, so clearing your browser storage is the only control needed — and it is the control every browser already gives you.
8. Changes to this policy
If we add, remove or change anything that stores information on your device, we will update the tables above and the version and date at the top before the change takes effect.
9. Contact
Questions about this policy, or about anything listed in it: hello@field2service.com.
Field 2 Service is operated by Go Gadgets Ltd, Cupidstown, Kilteel, Co. Kildare, Ireland, company registration number 565656. Privacy contact: [[OWNER: privacy/DPO contact or statement that no DPO is required]].
If you are in the European Union or Ireland and you are not satisfied with our answer, you may complain to the Data Protection Commission (Ireland) — how to contact the DPC and how to make a complaint: www.dataprotection.ie/en/contact/how-contact-us. If you are in the United Kingdom, you may complain to the Information Commissioner's Office (United Kingdom) — helpline 0303 123 1113 · www.ico.org.uk/make-a-complaint. ICO registration number: [[OWNER: ICO registration number, if registered]].