1. About this notice
This notice explains how EBA uses cookies and similar storage or access technologies on the marketing website, demo, app and outreach properties. These technologies can store or read information on a browser or device.
The exact names, first-party provider, storage location and expiry periods used in the current deployment are shown in the Cookie settings panel. That live list forms part of this notice and must be updated whenever the deployment changes.
2. Strictly necessary technologies
These are used where essential for a service the user requests or for security. They may include:
- the first-party eba_cookie_consent cookie, which records the choice for 180 days;
- authentication and session identifiers;
- security, fraud prevention and request-protection technologies;
- load balancing and service availability;
- Stripe checkout, payment and fraud-prevention technologies; and
- essential account or accessibility preferences.
Consent is not normally required for a technology that is strictly necessary, but EBA still explains it in the settings panel.
3. Functional preferences
Functional technologies remember choices that are useful but may not be essential, such as interface preferences. Where consent is required, they remain off until the user chooses them.
4. Analytics and performance
After consent, EBA may use the first-party eba_outreach_anonymous local-browser identifier on the marketing site, the first-party eba_demo_anonymous local-browser identifier on the demo, and the opaque eba_attribution first-party cookie across EBA subdomains. Each optional item expires after 30 days. The identifiers do not contain an email address, name, organisation name or a database row ID.
These optional technologies help EBA understand limited meaningful journeys, such as marketing entry, pricing views, a demo start or completion and a signup CTA. They may help EBA preserve campaign attribution across EBA properties. Non-essential analytics are used only after the required consent. Declining analytics does not block core account, practice or billing functions.
5. Advertising and marketing technologies
EBA does not use a child’s answers, scores, practice history or inferred ability to target third-party advertising.
EBA does not use ad pixels, fingerprinting, recordings, heatmaps, session replay or full browsing-history surveillance. If EBA introduces non-essential marketing technologies for adult-facing pages, they will be listed in the settings panel and will not be activated before the required consent.
6. Outreach email links
A personalised EBA email CTA can send a random, opaque token to EBA’s server so EBA can record that a link was requested and redirect to the chosen EBA page. This is an adult recipient-linked outreach record, not a browser cookie, and it can be triggered by a security scanner. EBA treats it as low-confidence activity. The Privacy Notice explains this in more detail.
7. Stripe and external services
Stripe may use technologies needed to provide checkout, remember the payment session, prevent fraud and secure transactions. Stripe’s own notices apply to information it handles as an independent payment provider.
Following a link to another website may allow that website to use its own technologies. EBA does not control another website’s storage after the user leaves EBA.
8. Your choices
The cookie banner and Cookie settings control non-essential categories. A user can accept, decline or change choices later using the Cookie settings control on the website.
Withdrawing consent does not make earlier consent-based use unlawful. Withdrawing consent clears the optional EBA browser identifiers listed above. Browser settings can also block or delete technologies, but blocking necessary session or security technologies may stop login, checkout or account features from working.
9. Children
Child-facing areas use high-privacy defaults. Non-essential tracking must not be switched on merely because an adult accepted it on an unrelated public page. EBA does not use child learning activity for behavioural advertising or adult outreach.
10. Expiry and retention
Session technologies expire when the browser session ends or shortly afterwards. The first-party consent cookie lasts 180 days; optional local-browser identifiers and the opaque attribution cookie last 30 days. Server-side attribution sessions expire after 30 days and detailed analytics have a 180-day default retention setting. Consent choices should be refreshed when required by law or when the use changes materially.
11. Changes and contact
We update this notice and the live settings list when technologies or providers change. Questions can be sent to support@exam-bytes.co.uk.