Cookie policy

Last updated 6 October 2026

This policy covers the EdCal website (edcal.co.uk) and the EdCal application that institutions use to publish course calendars.

In short: we don't use cookies or browser storage to track you, to build a profile of you or for advertising. The website stores nothing in your browser. The application uses one essential cookie on its sign-in service, and stores only what it needs to keep you signed in and to remember a few display choices you make.

The website

The EdCal website sets no cookies and uses no local or session storage. We measure how the site is used, such as which pages are visited, without cookies, storage or identifiers, so we can't use it to identify you. Our privacy notice explains this in more detail.

The EdCal application

Everything listed below is essential: it's needed to sign you in and provide the service, or it remembers a choice you've made.

Cookies

Cookie Type Set by How long What it's for
__Host-edcal-origin Essential Our sign-in service (id.edcal.co.uk) 30 days Remembers which institution's EdCal service you last signed in through, so if you go to the sign-in address directly you're sent back to it. It holds that service's web address only, nothing about you

Browser storage

The application uses your browser's local storage and session storage for the items below. Local storage stays until you sign out, clear it, or the application replaces it. Session storage is cleared when you close the browser tab.

Item Where What it's for
AccessToken, RefreshToken Local storage Keep you signed in. Removed when you sign out
pkce_pending_verifiers Local storage A one-time check that protects your sign-in. Each entry is removed once used, or after 10 minutes
code_verifier, pkce_exchanged_codes Session storage The same sign-in check, for the current tab
calendar-view-type, calendar-start-date, calendar-end-date Local storage Remember the calendar view and dates you last looked at
adminPermissionsPageSize, orgUnitHierarchyPageSize Local storage Remember how many rows an administrator chose to see in a report
hideAdminVideo Local storage Remember whether an administrator hid the introductory video
edcal.versionReload, edcal.staleBuildReload Session storage Reload the page once after we release an update, without looping

If the application meets an error, it sends us a technical error report so we can fix the problem. Error reporting is set up to use no cookies and no browser storage, and it identifies you only by an internal account number, never by your name or email address.

Signing in with Microsoft or Google

You sign in to the application through your institution's Microsoft or Google account. Microsoft and Google set their own cookies on their own sign-in pages. Those cookies are covered by their policies, not ours.

Why we don't show a cookie banner

The UK's Privacy and Electronic Communications Regulations 2003 (regulation 6) require consent before a website stores information on your device, except where that storage is strictly necessary to provide a service you've asked for.

Everything this policy lists falls within that exception. We don't use cookies or browser storage for analytics, marketing or advertising, and we don't use any third-party tracking. So there's nothing to ask your consent for, and we don't show a cookie banner.

If we ever add anything that isn't essential, we'll ask for your consent first and update this policy.

Removing stored items

Signing out removes the sign-in items. You can remove everything by clearing this site's data in your browser settings. You'll need to sign in again, and the application will forget your display choices.

Contact

Questions about this policy: enquiries@edcal.co.uk. EdCal Ltd, company number 16186215, 128 City Road, London EC1V 2NX.