This Cookie Policy explains how BugShield Ltd uses cookies and similar browser storage on bugshield.co.uk and its account services. Our Privacy Policy explains how we handle personal information.
1. What cookies and browser storage do
Cookies are small pieces of information that a website stores in your browser. They let a service recognise a signed-in session or continue a chat as you move between pages. Local storage saves information in the browser too, but it is not sent automatically with every request.
The storage you encounter depends on the features you use. Signing in, opening a support conversation, interacting with our contact form or following an affiliate link can involve different services.
2. Account sessions and website security
BugShield uses a session cookie to keep your account signed in and protect access to account features. Sessions expire after up to 72 hours, and continued account activity can renew them. Signing out ends access through that session.
Cloudflare helps protect our website against abusive traffic. When a security check is applied, Cloudflare can use cookies such as cf_clearance to remember that your browser passed a challenge. The expiry depends on the security check. See Cloudflare’s cookie information for details.
3. Live chat and contact-form protection
We use Crisp for live chat. Its crisp-client/* cookies keep your conversation connected across pages and return visits. Crisp’s default expiry is six months and is renewed when you return to a page where the chatbox loads. Read Crisp’s Cookie Policy for its storage and session details.
Google reCAPTCHA loads when you interact with our contact form and helps us distinguish genuine messages from automated spam. It sets the _GRECAPTCHA cookie when it runs. Google controls that cookie’s expiry, which you can inspect in your browser’s site-data settings. Our form uses Google’s domain, so other existing Google cookies can also be involved. See Google’s reCAPTCHA cookie explanation and Privacy Policy.
4. Affiliate referrals
If you follow a valid BugShield affiliate link, we use a bugshield_affiliate_ref cookie to associate an eligible purchase with the referring affiliate. The cookie lasts for 30 days and is shared across our website and account subdomains. A later valid affiliate click replaces the earlier referral.
This cookie supports referral attribution rather than sign-in or website security. You can block or delete it through your browser. Doing so can prevent the affiliate from receiving credit for a purchase. Our Terms of Use explain the affiliate programme.
5. Saved tool history
Our XSS2Shell checker uses local storage named bugshield:xss2shell:history to show recent results on the same browser and device. It keeps up to 50 entries from the previous seven days. Older entries are removed when the history is next read or updated, so browser data can remain on a device that does not return to the tool.
Use the tool’s clear-history control or remove BugShield’s site data in your browser to delete this local history. This does not delete any separate records retained by the scanning service.
6. Analytics and services we have removed
We use self-hosted Plausible Analytics to understand overall website use, including page visits, referral sources and actions such as following a registration link. Plausible does not set analytics cookies or use local storage to identify visitors. Read Plausible’s data policy for an explanation of its analytics approach.
Our marketing website no longer loads PostHog, Google Ads tags or the Meta Pixel. We do not use PostHog session replay. Removing a service does not automatically erase cookies or local storage left by an earlier visit; you can remove those through your browser’s site-data settings.
7. Managing cookies and site data
Your browser’s privacy settings let you inspect stored cookies, see their expiry dates, block cookies and clear site data. Local storage is removed through the site-data controls. Apply the settings to BugShield and, where needed, the third-party domains used by chat or form protection.
Blocking account cookies prevents sign-in from working correctly. Disabling third-party storage can affect chat continuity or contact-form verification. You can also contact us by email at [email protected]. Browser controls are separate from any choices provided by a third-party service.
8. Updates and questions
We will update this policy when our use of cookies or browser storage changes and revise the date shown above. For questions about this policy, email [email protected] or visit our contact page.
Cookie FAQs
Questions about cookies
What our current services store and how to manage that information.
Does BugShield use analytics cookies?
Our self-hosted Plausible Analytics does not set analytics cookies. Account sessions, live chat, form protection and affiliate referrals have separate purposes explained in this policy.
Do you use PostHog session replay, Google Ads or the Meta Pixel?
Our marketing website no longer loads PostHog, Google Ads tags or the Meta Pixel. We do not use PostHog session replay.
Why is Google reCAPTCHA still listed?
Google reCAPTCHA protects our contact form against automated spam. It is separate from Google Ads and loads when you interact with the form.
How can I delete saved scan history?
Use the XSS2Shell checker’s clear-history control or clear BugShield’s site data in your browser. The local history is specific to that browser and device.
Will blocking cookies affect my account?
Blocking account cookies prevents sign-in from working correctly. Blocking chat, form-protection or referral cookies can also affect those features.