Cookie Policy
Last updated: 12 August 2026
This Cookie Policy explains how BARRA AI LIMITED ("Barra", "we", "us" or "our") uses cookies and similar technologies across the services and technologies described below. It should be read with our Privacy Policy and any additional notice presented on a particular service or at the point of collection.
BARRA AI LIMITED is registered in England and Wales under company number 17014429. Our registered office is 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF. Contact us at hello@barra.ai.
1. Where this policy applies
Applies to: Anyone who visits, accesses, receives, interacts with or uses a Barra-controlled service or communication, or a customer service on which Barra technology is deployed. This includes current and future websites, blogs, applications, dashboards, portals, forms, downloads, communications, emails, events, communities, support channels and customer-deployed technologies.
1.1 Barra-controlled digital services
This policy covers cookies and related technologies used on any digital property or service that Barra owns, operates or controls and that links to or refers to this policy. Current examples include www.barra.ai, its blog, forms, downloads and legal pages, and app.barra.ai, including its signup, authentication, onboarding, account, workspace, billing, support and administration areas. It also covers any current or future Barra website, subdomain, application, dashboard, portal, digital product, mobile or browser-based experience, event platform or online community that uses cookies or similar technologies.
1.2 Communications, forms, events, communities and support
This policy also covers pixels, link tracking, embedded content, tags and similar technologies used in or alongside Barra emails, newsletters, blog subscriptions, content downloads, forms, surveys, webinars, in-person or online events, community spaces, customer research, service messages, chat and other sales, marketing, success or support communications.
1.3 Barra technologies on customer services
This policy covers all current and future Barra-provided scripts, widgets, tags, software development kits (SDKs), APIs, integrations, plug-ins, modules and related technologies that a customer deploys, embeds, connects or enables on a website, application or other digital service. The Barra toolbar and its install script are current examples. Such technologies may use browser storage, load code, communicate with Barra or supported third parties, and send event or diagnostic information.
The customer controls whether, where and how a Barra technology is installed and configured and is normally responsible for its own visitor notice, lawful basis and consent choices. This policy describes Barra's role and technology so customers and visitors can understand it. The customer's own privacy and cookie notices may provide additional information about its deployment and other technologies that it uses.
1.4 Current examples, not an exhaustive list
References to the website, blog, App, dashboard or toolbar, and the inventories below, describe important current examples. They do not limit this policy to those named services, domains, products, providers, identifiers or technical formats. This policy also applies when a service is renamed, replaced, moved to another domain, delivered through another interface, or extended with a new feature or technology, provided that Barra links to or otherwise makes this policy available for that context.
1.5 Additional notices
We may provide a banner, preference centre, in-product explanation, form notice, email notice, customer-facing technical documentation or other just-in-time notice for a particular service, feature, deployment or jurisdiction. Those additional notices supplement this policy and may give more specific information or choices for that context. If an additional notice gives a more specific choice or commitment, we will apply it to the relevant context.
1.6 Worldwide users
We apply UK Privacy and Electronic Communications Regulations (PECR) requirements as our operational baseline and respect mandatory local rules. Consent and opt-out requirements vary by location.
2. What cookies and similar technologies are
Applies to: All audiences.
2.1 Cookies
Cookies are small text records stored by a browser. Session cookies normally expire when the browser session ends. Persistent cookies remain until their expiry date or until they are deleted.
2.2 Local and session storage
Local storage can retain identifiers, preferences or cached configuration without using a traditional cookie. Session storage normally lasts for the current browser tab or session. Laws governing cookies may also apply to these technologies.
2.3 Tags, pixels, SDKs and connected technologies
Tags, pixels, software development kits, APIs, scripts, widgets, plug-ins, embedded content, device identifiers and similar code can collect device and interaction data, measure pages, applications and emails, load other providers or communicate with a service. They may work with or without a traditional cookie.
3. Categories we use
Applies to: All Barra-controlled services and communications and all customer services on which Barra technology is deployed.
3.1 Strictly necessary
These technologies are needed for a service you request or for essential security, authentication, load balancing, fraud prevention, consent recording or network transmission. Where the law provides a strictly necessary exemption, we do not ask for consent, but we still explain their use.
3.2 Functional
These remember choices, maintain user interface state, cache configuration or enable optional support and integration features. Consent may be required depending on the technology and local law.
3.3 Analytics and performance
These help measure visits, toolbar interactions, product usage, experiments, errors and performance. Where law requires consent for storage or access, we use them only on the basis of a valid consent choice.
3.4 Marketing
These measure marketing campaigns, form journeys and email engagement or help understand audiences across services. They require consent where applicable. Barra does not sell personal data for money, although some laws may call certain analytics or advertising disclosures a "sale", "share" or use for "targeted advertising".
3.5 How future technologies are classified
When we introduce or materially change a technology, we assess what it stores or accesses, the data it collects, its purpose, duration, provider and whether it is essential to a requested service. We classify it under the categories above or explain a new category in an updated notice. A new provider, identifier, storage mechanism or technical implementation does not make an optional purpose strictly necessary.
4. Consent and your choices
Applies to: All audiences and covered technologies, subject to the law and controls available in the relevant service, communication, browser, application, device or customer deployment.
4.1 Barra-controlled services
Where consent is required, we use a banner, preference centre, in-product setting, device permission or other appropriate control to ask before using the relevant non-essential technology. Depending on the service and jurisdiction, you may be able to accept or reject all non-essential technologies, choose individual categories, manage a specific feature, or exercise an opt-out right. Rejecting non-essential technologies should not prevent basic access, although optional analytics, personalisation, chat, embedded content, community, event or marketing features may be limited.
4.2 Customer services
The customer operating the relevant website, application or digital service is responsible for connecting deployed Barra scripts, widgets, tags, SDKs and integrations to its consent-management approach and for deciding whether optional Barra analytics and integrations can run before consent. Use that customer's cookie notice, consent banner or settings to manage the deployment. You may also contact the customer directly.
4.3 Available control routes
Depending on the context, you can use a Barra or customer consent banner or preference centre, application or dashboard settings, operating-system or device permissions, browser controls, a supported privacy signal, an email unsubscribe or communication-preference link, a provider opt-out, or a request to Barra or the relevant customer. Not every route controls every technology: for example, an email unsubscribe does not delete browser storage, and browser deletion does not cancel an account or required service messages.
4.4 Withdrawing or changing a choice
You can withdraw consent or change an available choice at any time. The new choice applies prospectively and does not make prior consent-based use unlawful. Choices may be specific to a browser, device, account, service, communication channel or customer deployment, so you may need to update them in more than one place. Clearing browser storage can also remove a saved preference and cause the service to ask again.
4.5 Essential records
Even after rejecting optional technologies, security, load-balancing, authentication or consent-choice records may remain because they are needed to provide or protect the requested service.
5. Barra website and blog inventory
Applies to: Visitors to www.barra.ai and related Barra-controlled websites, blogs, forms, downloads, events, communities, support experiences and legal pages.
This inventory records important technologies currently used on the Barra website and related services. It is not a promise that every listed technology operates on every page, for every user or at all times. Names, technical formats and durations can change when providers update their services or when we change configuration. A wildcard such as _ga_* means the exact suffix can differ by property. Sections 1 and 10 explain how this policy applies to replacements, additions and future services.
| Provider / technology | Example name or storage | Category | Purpose | Typical duration |
|---|---|---|---|---|
| Cloudflare / HubSpot infrastructure | __cf_bm, _cfuvid |
Strictly necessary | Bot management, security, traffic integrity and load balancing. | Session to approximately 30 minutes, depending on the identifier. |
| HubSpot consent and website tools | Consent preference records and HubSpot browser storage | Strictly necessary / Functional | Record cookie choices, operate forms, prevent repeated prompts and provide requested website functions. | Session to approximately 6 months, depending on the record. |
| HubSpot analytics | hubspotutk, __hstc, __hssc, __hssrc when enabled |
Analytics / Marketing | Measure visits and form journeys and associate website activity with CRM records where lawfully permitted. | Session, 30 minutes or up to approximately 6 months. |
| Google Tag Manager | Tag container; normally does not set its own identifier | Functional / Analytics / Marketing | Load and manage approved website measurement tags. The tags loaded through it may set their own cookies. | Not applicable to the container itself. |
| Google Analytics | _ga, _ga_* |
Analytics | Distinguish browsers and measure visits, traffic sources and website interactions. | Up to 2 years, subject to property configuration. |
| PostHog | ph_*_posthog in cookies or local storage; related session storage |
Analytics / Performance | Measure journeys, product usage, performance, surveys and session behaviour where enabled. | Session storage for the session; persistent identifier up to approximately 1 year. |
| Tawk | Chat cookies or storage, such as provider connection and visitor identifiers when chat is enabled | Functional | Provide live chat, maintain a chat session and support continuity. | Session to approximately 6 months, depending on provider configuration. |
| Barra toolbar on Barra's own website | barra-sid, barra-vid, barra-cfg-v1-* and feature-state keys |
Functional / Analytics | Load Barra configuration, maintain session and visitor identifiers, measure toolbar events and remember feature state. | Session, 24 hours or persistent until cleared, depending on the key. |
6. Barra App and dashboard inventory
Applies to: Visitors and users of app.barra.ai and any related or successor Barra application, dashboard, portal or authenticated digital service.
The technologies below are important current examples. A particular App area may use only some of them, and additional strictly necessary or consented technologies may be introduced under the framework in section 10.
6.1 Authentication, security and onboarding
| Technology | Category | Purpose | Typical duration |
|---|---|---|---|
| Supabase authentication cookies | Strictly necessary | Sign-in, session continuity, token refresh and account security. Exact names are generated by the authentication provider. | Session or for the authenticated-session lifetime. |
barra_onboarding_session |
Strictly necessary | Continue the requested onboarding and domain-verification flow. | Up to 24 hours. |
| Authentication-intent storage | Strictly necessary | Preserve the intended sign-in or redirect flow securely. | Approximately 10 minutes. |
| Recovery-flow storage | Strictly necessary | Support a password or account recovery journey. | Approximately 1 hour. |
6.2 Preferences and attribution
| Technology | Category | Purpose | Typical duration |
|---|---|---|---|
| Signup company and Terms/Privacy acknowledgement state | Strictly necessary / Functional | Continue signup and remember the requested business context and acknowledgement state. | Up to 30 days. |
| Affiliate and referral storage | Functional / Marketing | Attribute a qualifying signup or purchase to a referral source. | Up to 30 days. |
| Pricing and checkout preference storage | Functional | Remember a selected plan, billing interval, currency or credit choice while moving through signup. | Up to 30 days. |
| Workspace and account selection cookies and local storage | Functional | Remember the authorised workspace and account selected in Admin. | Up to 1 year or until changed or cleared. |
6.3 App analytics and support
| Provider / technology | Category | Purpose | Typical duration |
|---|---|---|---|
| PostHog | Analytics / Performance | Measure page views, product events, journeys, page-leave events and performance where configured. | Session storage and a persistent identifier up to approximately 1 year. |
| Vercel Analytics and Speed Insights | Analytics / Performance | Measure page performance, traffic and web-vital information. These tools may operate without a traditional persistent cookie. | Provider-controlled event retention; no fixed browser cookie is required for all modes. |
| Google Analytics / Tag Manager and HubSpot tracking, where enabled | Analytics / Marketing | Measure employee, signup or marketing journeys and associate permitted business activity. | As described in the website inventory or provider configuration. |
| Userback, where enabled | Functional / Support | Provide authenticated support and feedback with page, user, browser and diagnostic context. | Provider-controlled storage and retention. |
7. Barra technologies on customer services
Applies to: Visitors to customer websites, applications and other digital services, and customers that install, embed, connect or enable any Barra script, widget, tag, SDK, API, integration, plug-in or module.
The current Barra toolbar and its install script provide the specific inventory below. The same principles apply to any current or future Barra technology deployed on a customer service. A new delivery format does not change the customer's responsibility to provide an appropriate notice, establish a lawful basis and obtain consent where required.
7.1 Current toolbar browser storage
| Name or pattern | Storage | Category | Purpose | Duration |
|---|---|---|---|---|
barra-cfg-v1-{domain} |
Local storage | Functional | Cache the published toolbar configuration for the current domain so it can load reliably and efficiently. | Approximately 24 hours. |
barra-sid |
Session storage | Analytics / Security | Associate toolbar events with one browser session. | Current browser session. |
barra-vid |
Local storage | Analytics | Distinguish a returning browser for Barra-native analytics. | Persistent until cleared; no automatic browser expiry is currently set. |
barra_heart_browser_key and barra_heart_liked |
Local storage | Functional / Analytics | Prevent or recognise repeated heart or like interactions and remember the visitor's state. | Persistent until cleared. |
barra-swipe-collapse |
Local storage | Functional | Remember a toolbar collapse preference. | Persistent until cleared. |
barra-cv-{experiment} |
Local storage | Analytics / Functional | Maintain an experiment or conversion assignment and avoid inconsistent experiences. | Depends on the experiment; may persist until cleared. |
7.2 Information sent from current customer-deployed technology
Depending on customer configuration, the toolbar may send the session or visitor identifier, account and module identifiers, page URL and path, referrer, device category, viewport, event type, experiment or goal information and timestamp. Feedback can include a sentiment, optional message and full page URL. Heart interactions can include a pseudonymous browser key and page URL. The Barra chat module can report whether a customer's existing chat provider opened or closed; Barra does not use that module to capture the chat message content.
Future scripts, widgets, tags, SDKs, APIs, integrations, plug-ins or modules may process comparable identifiers, configuration, device, interaction, event, diagnostic or content data needed for their disclosed purpose. Before introducing materially different data collection or an optional purpose, we will update the relevant inventory or additional notice and obtain consent where required.
7.3 Customer-controlled analytics and integrations
Barra-native analytics is a separate feature from the customer's own Google Analytics, data layer, chat, consent or search tools. A customer may enable, disable or configure supported integrations. The customer must ensure that optional storage and event delivery follow the visitor's consent and applicable law.
8. Email pixels and engagement
Applies to: Recipients of any Barra communication, including blog subscribers, download requesters, marketing contacts, event or community participants, research participants, support contacts and App users receiving email or other digital messages.
Emails and other digital communications sent through our marketing, event, community, support or communications providers may include pixels, embedded content or rewritten links that report delivery, opens, clicks or interactions. We use this information for deliverability, security, subscription management, support, event or community administration and campaign measurement where permitted. You can unsubscribe from marketing or use an available communication-preference control, and many email clients allow remote-image blocking. Necessary account, billing, security, support and service emails may still be sent.
9. Provider and browser controls
Applies to: All audiences.
9.1 Browser settings
Most browsers let you block, delete or limit cookies and site data. Blocking all storage may prevent authentication, onboarding, saved preferences or toolbar functions from working. Browser instructions are available from:
9.2 Provider opt-outs
Some providers offer separate opt-outs, including Google Analytics. A provider opt-out does not necessarily control other providers or first-party storage.
9.3 App, device, communication and account controls
A Barra application, dashboard, event, community, support tool or customer deployment may provide its own privacy, analytics or integration setting. Mobile devices and operating systems may also provide permissions or advertising controls. Marketing and subscription messages include an available unsubscribe or preference route where required. Account, security, billing and other requested service communications are managed separately from marketing choices.
9.4 Global Privacy Control and similar signals
Where applicable law requires us to recognise a supported browser opt-out signal, we will treat it as a request for the covered browser and device. Such a signal may not withdraw a separate account-level subscription or consent given through another device.
10. Changes, new services and evolving technologies
Applies to: All audiences.
10.1 Inventory and technical variations
The inventories in this policy describe material current examples rather than an immutable technical specification. An identifier may gain a property-specific suffix, move between cookie and browser storage, have a shorter duration, or be replaced by a functionally equivalent identifier. A provider may also change its domain, infrastructure or implementation. We will review the inventory and correct material changes.
10.2 New or changed services and providers
We may launch, rename, replace or extend a website, App, dashboard, communication channel, form, event, community, support tool or customer-deployed script, widget, tag, SDK, API or integration. We may also add, replace or remove a provider. Before using a new or materially changed technology, we assess its purpose, data, category, duration, provider, necessity and consent requirements as described in section 3.5.
10.3 Notice and consent for material changes
We may update this policy and any relevant inventory or provide an additional notice when technologies, providers, configurations, services or laws change. We will update the date above when this policy changes. We will not rely on general future-facing wording to bypass a consent requirement. If a new or changed technology introduces a materially different non-essential purpose or otherwise requires a new choice, we will present an appropriate notice and request consent before that use where required by applicable law.
10.4 Continued use and mandatory rights
Where consent is not the legal basis, continued use of a service after an update means the current version of this policy will describe the technologies used from that point. It does not waive any mandatory privacy right or turn an optional technology into a strictly necessary one.
11. Contact us
Applies to: All audiences.
Email: hello@barra.ai
Post: BARRA AI LIMITED, 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF.
