1. About this policy
This Cookie Policy explains how myProfile247 (the "Service"), operated by eTech Consulting (Australia) at https://myprofile247.com, uses cookies and similar on-device storage technologies. myProfile247 is a user-owned attribute wallet: you store facts about yourself ("attributes"), each with a confidence score and trust tier, and selectively disclose them to people and organisations you choose. The technologies described here exist mainly to sign you in securely and to render your profile in your browser.
This policy supplements, and should be read together with, our Privacy Policy, which explains in full what personal information we collect, the legal bases we rely on, how your data is encrypted, how we anchor a non-identifying integrity hash to a public blockchain, your privacy rights under Australian, EU/UK and Californian law, and how to exercise them. Where this policy refers to your rights or to international data transfers, the detail lives in the Privacy Policy. The data controller is eTech Consulting (ABN [ABN / ACN — TO BE COMPLETED]; registered address [REGISTERED BUSINESS ADDRESS — TO BE COMPLETED]).
This is general information and transparency, not legal advice. We may update this policy from time to time as described in section 8.
2. Cookies & local storage explained
A range of technologies let a website or app store small amounts of data on your device. We describe the ones relevant to myProfile247 below.
- Cookies
- Small text files a website asks your browser to store and send back on later requests. A cookie can be marked HttpOnly (not readable by page scripts, which reduces the risk of theft) and Secure (only sent over an encrypted HTTPS connection). Cookies can be short-lived (a "session" cookie) or persist for a set period.
- Local storage (localStorage)
- A larger key/value store kept in your browser that persists until it is cleared. It is readable by page scripts and is never automatically transmitted to a server, so we use it only for non-secret information.
- Session storage (sessionStorage)
- Similar to local storage, but cleared automatically when you close the browser tab. We do not rely on session storage for anything described in this policy.
- Secure device storage (mobile apps)
- Our mobile apps keep sensitive tokens in the operating system's protected key store (Expo SecureStore) and keep non-sensitive metadata in ordinary app storage (AsyncStorage). This is not a browser cookie, but we mention it for completeness.
3. The cookies & storage we use
The table below lists what myProfile247 stores on your device through the web app. All of our cookies are first-party (set by myprofile247.com). We do not set third-party advertising cookies.
| Name | Type | Purpose | Storage & duration |
|---|---|---|---|
mp_access | HttpOnly, Secure cookie (strictly necessary) | Carries your short-lived access token so each request can be authenticated. Without it you would have to re-authenticate on every page. | First-party cookie; expires after roughly 30 minutes. |
mp_refresh | HttpOnly, Secure cookie (strictly necessary) | Lets the app quietly obtain a fresh access token so you stay signed in without re-entering your credentials. | First-party cookie; expires after roughly 30 days. |
mp_session | Browser localStorage (non-secret UI mirror) | A non-secret copy of your basic profile details (such as your user id, email, names, handle, role, UI colour, directory code and the API base URL) so the app can render your account without an extra round-trip. It contains no passwords, no tokens and no attribute values. | Persists in your browser until you sign out or clear site data. |
mp_theme | Browser localStorage (preference) | Remembers your light or dark theme choice. | Persists in your browser until you change it or clear site data. |
| OpenPanel analytics (on-device identifier + analytics pipeline) | First-party analytics storage and server-side event logging | Our self-hosted analytics records, from the web client, page and screen views, outgoing link clicks, and configured attributes. In addition, our servers emit one analytics event per HTTP request that carries the HTTP method, the route template, the raw request path (which can embed identifiers), the status code, the duration, your signed-in user id if any, your full (unhashed) client IP address and your User-Agent. All of this is sent to our self-hosted OpenPanel. The web client capture is gated by a server configuration flag and a build-time client id. Please note that the server-side event is emitted on the server and is not controlled by any browser cookie or storage setting. | First-party, served from and stored on our own infrastructure (stats.assetofthings.com). The on-device OpenPanel identifier is held in browser localStorage and persists until you clear site data. Analytics events are retained for up to 14 months and then deleted or irreversibly aggregated into non-identifying statistics. |
To be clear about the server-side event mentioned above: it is emitted by our servers for every request and records the HTTP method, both the route template and the raw request path, the status code, the duration, your user id if signed in, your full (unhashed) client IP address and your User-Agent. That is server-side logging rather than a cookie, it cannot be switched off from your browser, and it is described further in the Privacy Policy.
4. Strictly necessary vs analytics
We distinguish two categories, because they are treated differently under EU/UK ePrivacy rules.
Strictly necessary
The mp_access and mp_refresh authentication cookies are strictly necessary: they exist solely to deliver the sign-in functionality you have asked for. Under the EU ePrivacy Directive and the UK Privacy and Electronic Communications Regulations (PECR), strictly necessary cookies are exempt from prior consent. We consider themp_session UI mirror and the mp_theme preference to be functional storage that you set in motion by signing in or choosing a theme.
Analytics
Our analytics is provided by self-hosted OpenPanel running on our own infrastructure under the "Asset of Things" name. There are no third-party advertising or marketing trackers on myProfile247: no Google Analytics, no Meta or Facebook Pixel, and no third-party error-tracking service is currently in use. We do not sell or share your information for cross-context behavioural advertising.
Being self-hosted and first-party does not make analytics "strictly necessary". Under the ePrivacy Directive and PECR, analytics storage is generally a non-essential technology that would require prior consent from EU/UK visitors. We state this plainly rather than mislabelling analytics as essential.
For the storage and access involved in analytics, we acknowledge that no ePrivacy or PECR consent has yet been obtained, because the consent banner described in section 5 is not yet built. The legal basis we currently rely on under the EU/UK General Data Protection Regulation (Article 6) for the personal data the analytics collects (such as your client IP, User-Agent and signed-in user id) is set out in the Privacy Policy, which also carries the Australian Privacy Principle 5 collection notice for that data. We do not assert consent as that basis.
5. Consent & ePrivacy posture
We want to be straightforward about where we are today. A dedicated cookie-consent banner is not yet implemented on myProfile247. This means our analytics currently runs without a consent gate. We are disclosing this rather than implying a consent mechanism exists.
A few important points follow from that honesty:
- We do not claim to be cookie-consent compliant under the EU/UK ePrivacy regime, and we do not assert that analytics has been consented to.
- Analytics is first-party and self-hosted, and the operator can disable it entirely through server configuration (it is gated by an environment flag and a build-time client id).
- Building a consent banner with proper analytics gating for EU/UK visitors is a committed, recommended follow-up. In the meantime, please be aware that our main analytics is the server-side per-request event described in section 3, which runs on our servers and cannot be switched off from your browser. Today the only true ways to stop that server-side analytics are not to use the Service, or for the operator to disable analytics in its server configuration. The browser controls described in section 6 manage the data stored on your device (such as
mp_session,mp_themeand the OpenPanel on-device identifier); they do not stop the server-side logging.
For Australian visitors, the Privacy Act 1988 (Cth) does not impose a standalone cookie-consent banner requirement, but our collection-notice obligations under Australian Privacy Principle 5 still apply and are addressed in the Privacy Policy.
6. Managing cookies & storage
You are in control of what your browser stores. Every major browser lets you view, block and delete cookies and clear site data; check your browser's help pages for exact steps. In general you can:
- Block or delete cookies for myprofile247.com specifically, or for all sites.
- Clear local storage by using your browser's "clear site data" or "clear browsing data" tools, which will remove
mp_session,mp_themeand the OpenPanel on-device identifier. - Use a private or incognito window, which discards cookies and storage when the window is closed.
If you block our strictly necessary cookies, you cannot stay signed in. The mp_access and mp_refresh cookies are what keep your session active, so blocking or deleting them will sign you out and prevent you from accessing your attributes and selective-disclosure controls until you sign in again.
Clearing local storage is harmless: mp_session is only a non-secret display mirror and mp_theme is only a preference, so the app will simply rebuild them the next time you sign in or choose a theme. On our mobile apps, you can clear stored tokens by signing out or clearing the app's data through your device settings.
These browser tools control the data stored on your device. They do not stop the server-side per-request analytics event described in sections 3 and 5, because that event is emitted on our servers rather than from your browser.
7. Do Not Track & opt-out signals
Some browsers can send a "Do Not Track" (DNT) signal or a Global Privacy Control (GPC) signal expressing a preference not to be tracked. Because we do not operate any cross-context behavioural advertising and do not sell or share personal information for such advertising, there is no ad tracking on myProfile247 for a DNT or GPC signal to switch off. We do not currently process DNT or GPC signals, because there is no "sale" or "sharing" of personal information for such a signal to act on. Should the Service ever sell or share personal information in the future, we would honour a valid GPC signal as an opt-out of that sale or sharing, and we would update this policy accordingly.
On the question of controlling our analytics: as explained in sections 3, 5 and 6, the main analytics is a server-side per-request event that your browser cannot switch off. Browser tools (clearing or blocking site data, or a private window) only affect the data stored on your device, such as mp_session, mp_theme and the OpenPanel on-device identifier. Because our analytics is served first-party from our own domain (stats.assetofthings.com), generic third-party tracker blockers may not stop it either. The only true ways to stop the server-side analytics today are not to use the Service, or for the operator to disable analytics through its server configuration (the environment flag and build-time client id referenced in section 5).
8. Changes to this policy
We may update this Cookie Policy as the Service evolves, for example when we add a cookie-consent banner, change our analytics configuration, or adjust how long cookies last. When we make a material change we will update the version and last-updated date shown at the top of this page. We encourage you to review this policy periodically. Your continued use of myProfile247 after an update takes effect indicates that you have read the current version.
9. Contact us
If you have questions about this Cookie Policy, about how we use cookies and on-device storage, or about your privacy choices, please contact our privacy team at privacy@myprofile247.com. Our full contact details, including our registered address ([REGISTERED BUSINESS ADDRESS — TO BE COMPLETED]) and ABN ([ABN / ACN — TO BE COMPLETED]), and the mechanisms for exercising your privacy rights and lodging a complaint, are set out in the Privacy Policy. Your use of myProfile247 is also subject to our Terms & Conditions.
This document is provided for general information and transparency. It is not legal advice. myProfile247 is operated by eTech Consulting (Australia). Questions? Contact privacy@myprofile247.com.