IAP Exchange
Legal

Cookie policy

What we store on your device, why, and how you control it — under the UK GDPR and the Privacy and Electronic Communications Regulations.

Last updated: 21 August 2026

1. What cookies are

Cookies are small files stored by your browser. We also use closely related technologies such as local storage. In this policy “cookies” covers both. Some are set by us (first party), others by suppliers acting as our processors (third party).

2. Strictly necessary cookies

These are required for the site and the control centre to work — authentication, security and remembering your cookie choice. They are set under the PECR “strictly necessary” exemption, so we do not ask for consent, and they cannot be switched off without breaking the service.

CookieVendorPurposeDuration
sb-<project>-auth-tokenSupabase (data processor)Keeps you signed in to the IAP Exchange control centre and refreshes your session token.Session / up to 7 days
sb-<project>-auth-token-code-verifierSupabase (data processor)Short-lived value that secures the sign-in exchange against interception.A few minutes
__cf_bm / cf_clearanceCloudflare (data processor)Distinguishes human visitors from bots and mitigates abuse of the site.30 minutes to 12 months
iap-cookie-preferencesIAP Exchange (first party)Remembers your cookie choices so we do not ask again on every visit.12 months

3. Optional cookies

These are set only if you accept them. Declining has no effect on the pages or features available to you.

CookieVendorPurposeDuration
Product analytics identifiersLovable Analytics (data processor)Aggregated page views and navigation paths so we can see which pages institutional and investor visitors find useful. Not used for advertising.Up to 13 months
Error and performance diagnosticsIAP Exchange (first party)Records client-side errors and load timings with a random session identifier so we can reproduce and fix faults.Session

4. Managing your preferences

When you first visit, we ask whether to enable optional cookies. Until you accept, only strictly necessary cookies are set. You can change your mind at any time:

  • clear the iap-cookie-preferences value in your browser’s site settings to be asked again;
  • block or delete cookies for this site in your browser settings (Chrome, Safari, Firefox and Edge all offer per-site controls);
  • enable a Global Privacy Control signal in your browser — we treat it as a refusal of optional cookies;
  • email privacy@iapexchange.com and we will action the change for your account.

Blocking strictly necessary cookies will sign you out of the control centre and may prevent sign-in entirely.

5. Vendors and transfers

Each vendor named above processes data on our documented instructions under a written processing agreement. Where a vendor processes data outside the UK, transfers are covered by the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum. Further detail is in our privacy notice.

6. Advertising

We run no advertising, no retargeting pixels and no cross-site tracking, and we do not sell or share personal data with data brokers.

7. Changes and contact

If we add a cookie or change a vendor we will update this page and, where consent is required, ask again. Questions go to privacy@iapexchange.com. You can complain to the Information Commissioner’s Office at ico.org.uk.