One cookie, and only after you sign in.
There is no cookie banner on this site because there is nothing on it to consent to. No analytics, no advertising, no third-party scripts. This page says what the one cookie is and how to get rid of it.
Last updated
The whole list
| Name | What it is for | How long | Type |
|---|---|---|---|
| salto_portal_session | Keeps a client signed in to the client portal. It holds a signed token identifying the account and the client organisation being viewed. Nothing else, and nothing about browsing. | Thirty minutes from your last request. It slides on each request and is gone when you sign out. | Strictly necessary |
That is the entire list. It is set only when a client signs in, so if you have only read the public site you have no cookies from us at all.
The cookie cannot be read by JavaScript, is sent only over HTTPS in production, and is restricted to same-site requests.
Why there is no banner
A consent banner exists to get permission for cookies and similar storage that are not needed to deliver what you asked for: analytics, advertising, embedded players, chat widgets, session recording. Under the EU and UK rules that create the requirement, storage that is strictly necessary to provide a service the user asked for is exempt.
The one cookie here is the sign-in itself. Refusing it means not being signed in, which is not a choice a banner can offer. So a banner would be asking permission for nothing, and a banner that asks permission for nothing trains people to click through the ones that matter.
We would rather this page be checkable than reassuring: open your browser's network panel on any page of this site and the list of hosts it contacts is this domain, once. If that ever stops being true, because an analytics tag, a video embed or a chat widget is added, this page changes and a consent mechanism goes in before the tag does, not after.
What we are not doing
- No analytics, of any vendor, first-party or otherwise.
- No advertising or conversion pixels, and no remarketing.
- No session recording, heatmaps or scroll tracking.
- No embedded video, maps, chat widget, scheduler or social button. Every one of those sets third-party cookies as a side effect, and none is on this site.
- No fonts, images or scripts loaded from anyone else's domain.
- No local storage or session storage on the public pages.
Turning it off
Every browser lets you block or delete cookies, under Settings and then Privacy. Blocking ours costs you nothing on the public site. On the portal it means you cannot stay signed in, because the cookie is what being signed in consists of.
Browser Do Not Track and Global Privacy Control signals are honoured by default here for the simple reason that there is nothing to apply them to.
Changes to this page
Dated 17 September 2026. The privacy page has the rest of the detail, including who else touches your information.
If something on this page contradicts an agreement you have signed with us, the agreement governs. Tell us, because one of the two is wrong and we want to know which.
Ask us about it