Apollo Cookie Policy
Last updated: 3 July 2026
This Cookie Policy explains how APOLLOUI LTD (Apollo, we, us, our) uses cookies and similar technologies on our website and application in accordance with applicable UK law, including rules on cookies and similar technologies under the Privacy and Electronic Communications Regulations (PECR) and UK data protection law.
This policy should be read with our Privacy Policy. It does not mean Apollo is “GDPR compliant” or “PECR compliant” as a marketing badge.
Related documents:
- Privacy Policy — how we handle personal data
- Terms and Conditions — contract for use of Apollo
- Data Processing Agreement — tenant processor processing (cross-reference only)
- Disclaimer — platform scope and limits
1. About this Cookie Policy
1.1 This Cookie Policy describes:
- what cookies and similar technologies are;
- how Apollo uses them;
- the choices you have on our public marketing website;
- cookies and storage used when you sign in and use the workspace or client portal.
1.2 Scope. The cookie consent banner and Cookie settings control described in sections 10–11 apply to our public marketing pages and the signed-out home page (/). They do not currently appear on workspace, client portal, login, signup, or invite routes.
1.3 Third-party sites. If you follow a link to Mailchimp, Stripe, or another third party, that site’s own cookie and privacy policies apply there — not this policy.
1.4 We may update this Cookie Policy from time to time. The “Last updated” date at the top shows when it was last revised.
2. Who we are
Apollo is operated by:
APOLLOUI LTD
A private limited company registered in England and Wales
Company number: 17093007
Registered office: 38 Mercer Avenue, Ebbsfleet Valley, Swanscombe, England, DA10 1BR
General contact: hello@apolloui.co.uk
Privacy contact: hello@apolloui.co.uk
3. What cookies and similar technologies are
3.1 Cookies are small text files placed on your device when you visit a website. They are widely used to make sites work, remember preferences, or understand how a site is used.
3.2 Similar technologies include:
- localStorage and sessionStorage in your browser — data stored locally on your device;
- scripts loaded from third-party domains (for example marketing tools);
- authentication tokens held by the browser or application libraries.
3.3 Cookies may be first-party (set by Apollo) or third-party (set by a provider such as Mailchimp).
3.4 Cookies may be session cookies (deleted when you close your browser) or persistent cookies (remain for a set period or until you delete them).
4. How Apollo uses cookies
4.1 We use cookies and similar technologies to:
- operate and secure the Apollo website and application;
- remember your sign-in session;
- remember optional preferences (for example display theme or selected portal context);
- ask for your consent before loading non-essential marketing scripts on our marketing website;
- support early-access marketing only where you consent on our site.
4.2 We do not currently use a third-party cookie consent management platform (CMP). Consent is handled by Apollo’s own banner and preference tools on marketing pages.
4.3 We do not currently use third-party analytics cookies (for example Google Analytics) on our marketing website unless we update this policy to say otherwise.
5. Cookie categories we use
We group cookies and similar technologies into the categories below. This matches the choices in our marketing cookie banner where applicable.
| Category | Purpose | Can you opt out on marketing pages? |
|---|---|---|
| Essential | Security, authentication, basic delivery of the site/app | No — required for operation |
| Preferences / functionality | Remember choices that improve your experience (theme, portal context, view filters) | Partially — preferences toggle in banner; some app cookies apply only after sign-in |
| Marketing | Mailchimp connected-site popup on our marketing pages | Yes — default off until you accept |
Rejecting marketing cookies does not stop you using our website, and it does not stop you joining our early-access list via the external Join early access link (see section 8 and 12).
6. Essential cookies and storage
6.1 Essential cookies and storage are necessary for security, authentication, or core operation. They cannot be turned off through Apollo’s marketing cookie preference tool because the site and application would not work properly without them.
6.2 Examples include:
- the
**__session** cookie when you sign in (see section 13); - hosting and security processing by our infrastructure providers (which may involve technical cookies or logs at the network edge).
6.3 Essential cookies may be set when you use login, the workspace, or the client portal, even though the marketing cookie banner is not shown on those routes.
7. Preference cookies and storage
7.1 Preference technologies remember choices that make Apollo easier to use. They are not strictly required for every page to load, but they improve your experience.
7.2 On our marketing website, the banner includes a Preferences toggle in Manage preferences. Default behaviour on first visit: marketing off; preferences choice is stored when you save a selection (see apollo_cookie_consent_v1 in section 13).
7.3 Theme / display mode. Apollo uses next-themes with default browser localStorage key **theme** (values such as light, dark, or system) to remember light/dark display preference. This is first-party storage on your device.
7.4 Signed-in application preferences (not controlled by the marketing banner):
**apollo_portal_context** — remembers your last selected client portal account context (HttpOnly cookie, path/client, max-age 30 days in code);**apollo_connection_lens** — remembers your connection filter on orders/dashboard surfaces when you have multiple connections (HttpOnly cookie, max-age 30 days in code).
These are preference-only; the server always re-validates your access.
7.5 Disabling preferences in the marketing banner does not currently disable theme localStorage or signed-in app preference cookies — those serve signed-in or display use cases.
8. Marketing cookies and Mailchimp
8.1 On our marketing website only, we may use marketing cookies/scripts to support an optional Mailchimp connected-site popup for early-access conversion.
8.2 Consent-gated loading (as implemented):
- Marketing cookies/scripts default to off.
- The Mailchimp script from
**chimpstatic.com** loads only if you accept marketing cookies (Accept all, or Save preferences with Marketing enabled). - If you reject non-essential cookies, that script does not load on our site.
- We use a module-level guard so the script is injected once per browser session where consent applies.
8.3 External Join early access link. Our Join early access / register-interest button links to a Mailchimp-hosted form (for example mailchi.mp/apolloui.co.uk/website). That is a deliberate click that takes you to Mailchimp’s website. It works without accepting marketing cookies on Apollo’s site. Mailchimp may set its own cookies on their site under their privacy notice.
8.4 Mailchimp cookie names and durations on our site (after consent) are controlled by Mailchimp and may change.
8.5 Mailchimp lawful basis, DPA, and international transfers are addressed in our Privacy Policy.
9. Analytics cookies
9.1 We do not currently use third-party analytics cookies or similar tracking on our public marketing website (for example Google Analytics, Meta Pixel, or Hotjar).
9.2 If we introduce analytics in future, we will update this Cookie Policy and, where required, ask for your consent before non-essential analytics run.
10. Cookie consent on Apollo marketing pages
10.1 On public marketing pages (for example /, /tour, /pricing, /faq, /about, /contact, /register-interest) and the signed-out home page, we show a cookie banner on your first visit until you make a choice.
10.2 The banner explains that we use essential cookies and that marketing cookies are optional. It offers three equally visible actions:
- Accept all — enables marketing cookies/scripts (including Mailchimp popup loader where configured);
- Reject non-essential — keeps marketing cookies/scripts off;
- Manage preferences — opens a modal with category toggles.
10.3 Reject is as easy as Accept — both are shown with equal prominence.
10.4 Your choice is stored in browser localStorage under key **apollo_cookie_consent_v1** (JSON: version, marketing boolean, preferences boolean, updatedAt timestamp).
10.5 No third-party CMP is used. Implementation is Apollo’s own cookie banner and preferences modal.
10.6 The banner does not appear on **/login**, **/signup**, **/invite/accept**, workspace routes, or the client portal. Essential and application cookies may still apply there when you use those parts of Apollo.
11. Changing your cookie preferences
11.1 On marketing pages, click Cookie settings in the website footer to reopen the preferences modal and change your choices at any time.
11.2 In the modal, you can adjust Preferences and Marketing toggles (Essential is always on and cannot be disabled). Actions include Save preferences, Accept all, and Reject non-essential.
11.3 Withdraw marketing consent. Choose Reject non-essential or turn off Marketing and save. We will stop loading the Mailchimp popup script on future visits to our marketing pages. We may not be able to delete cookies already placed on your device by third parties; you can clear site data in your browser settings.
11.4 Clear all choices. You can clear **apollo_cookie_consent_v1** (and other site data) via your browser settings. The banner will appear again on your next visit to marketing pages.
11.5 For broader data protection rights, see our Privacy Policy and contact hello@apolloui.co.uk.
12. Third-party websites and Mailchimp
12.1 Mailchimp register-interest. When you click Join early access, you may leave Apollo’s site and open Mailchimp. Mailchimp’s privacy and cookie practices apply on their domain.
12.2 Stripe. If you subscribe or manage billing via Stripe-hosted pages, Stripe’s policies apply there.
12.3 Google sign-in. If you choose Google to authenticate, Google’s policies apply to that sign-in flow.
12.4 We are not responsible for third-party sites’ cookies or privacy practices. We encourage you to read their notices.
13. Detailed cookie and storage table
The table below lists technologies used in Apollo’s website and application, plus Mailchimp where consent applies.
| Name / key | Type | Category | Purpose | Duration | When set / notes |
|---|---|---|---|---|---|
**apollo_cookie_consent_v1** | localStorage (JSON) | Consent record | Stores your cookie banner decision: version, marketing, preferences, updatedAt | Until you change preferences, clear site data, or we change the key version | Marketing pages + signed-out / after banner interaction; marketing defaults false |
**__session** | HttpOnly cookie | Essential | Authenticated session (Firebase session cookie bridge) | 5 days (maxAge in /api/auth/sync) | When you sign in; path=/; SameSite=Lax; Secure in production |
**apollo_portal_context** | HttpOnly cookie | Preference / functionality | Remembers last selected client portal context; server re-validates allow-list | 30 days | Client portal users when context is saved; path=/client |
**apollo_connection_lens** | HttpOnly cookie | Preference / functionality | Remembers connection lens filter (workspace or portal orders/dashboard) | 30 days | Users with multiple connections when lens preference saved; path=/ |
**theme** | localStorage | Preference | Light / dark / system display mode (next-themes default key) | Until cleared or changed | Marketing and app shell when theme toggle used |
Mailchimp / chimpstatic.com script (#mcjs) | Third-party script (+ possible cookies) | Marketing | Connected-site popup for early access | Controlled by Mailchimp | Only after marketing consent on Apollo marketing pages |
| Firebase Auth client persistence | Browser storage (typical Firebase SDK behaviour) | Essential | Keeps Firebase client auth state for sign-in | Per Firebase SDK defaults | When using email/password or Google sign-in |
| Hosting / CDN (Vercel) | Server logs / edge processing | Essential / operational | Deliver website and application | Per provider configuration | All requests |
Not used: Third-party analytics cookies; third-party CMP cookies.
14. Updates to this Cookie Policy
We may update this Cookie Policy to reflect changes in law, our services, or our use of cookies. We will post the updated version with a revised Last updated date. Where changes are material, we may provide additional notice (for example on our website or by updating the cookie banner text).
If we add analytics or other non-essential categories, we will update this policy and our consent mechanism before or when they go live, as required by law.
15. Contact us
For questions about this Cookie Policy or cookies on Apollo’s website:
Email: hello@apolloui.co.uk
Post: APOLLOUI LTD, 38 Mercer Avenue, Ebbsfleet Valley, Swanscombe, England, DA10 1BR
For broader privacy questions, see our Privacy Policy.
Related documents: Terms and Conditions · Privacy Policy · Data Processing Agreement · Disclaimer
