Cookie Policy — Part-Time Quant (part-timequant.com)
Version: 0.1 (draft) Last updated: 27 August 2026 Operator: Lewis Jackson Ventures Ltd (registered in England and Wales, company number 14843004), 46 Priory Road, Reigate, Surrey, RH2 8JB, United Kingdom Contact: lewis@jackson.ventures
1. The short version
We use a small number of cookies, and only the ones the site cannot work without. We do not use advertising cookies, marketing cookies, social media pixels, or cross-site tracking of any kind. Our analytics tool (Plausible) does not use cookies at all.
Because of this, we do not show a cookie consent banner. Section 6 explains the legal reasoning behind that decision.
2. Who we are
This policy is issued by Lewis Jackson Ventures Ltd (registered in England and Wales, company number 14843004), the operator of part-timequant.com ("PTQ", "we", "us"). It covers the PTQ website and hosted web application only. The PTQ desktop application does not use cookies; see section 9.
This policy should be read alongside our Privacy Policy, which explains how we handle personal data more broadly.
3. What cookies are
Cookies are small text files a website stores on your device (computer, phone, tablet) when you visit. They let the site remember things between pages and visits — most importantly here, that you are signed in. UK law (the Privacy and Electronic Communications Regulations 2003, "PECR") also treats similar technologies the same way, including localStorage, sessionStorage, and device fingerprinting. Where this policy says "cookies", it includes those technologies.
4. Our approach
We follow one rule: strictly necessary only.
- We set cookies only where the site cannot function without them (keeping you signed in, keeping your session secure, preventing fraud at checkout).
- We do not set any cookie for advertising, marketing, retargeting, audience building, or cross-site tracking.
- We do not load any third-party advertising or social media scripts.
- Our analytics are cookieless (section 6).
5. The cookies we use
The table below lists every cookie we expect the site to set in production.
The marketing site sets no cookies at all. The cookies below are set only inside the signed-in app.
| Cookie | Set by | Purpose | Type | Duration |
|---|---|---|---|---|
__session |
Clerk (our sign-in provider), on our domain | Holds your session token so you stay signed in as you move between pages. Without it, you cannot use your account. | Strictly necessary | Length of your session. Default configuration is 7 days the lifetime configured in our authentication provider |
__client_uat |
Clerk, on our domain | Stores a timestamp of when your sign-in state last changed, so the app can keep sign-in state consistent across browser tabs. | Strictly necessary | Persistent set by our authentication provider |
__clerk_db_jwt |
Clerk | Development-only cookie used by Clerk in non-production environments. Should never appear on the live site. not used in production | Strictly necessary (dev only) | Session |
__stripe_mid |
Stripe, on our domain (only if Stripe.js is embedded on our pages) | Fraud prevention: helps Stripe detect suspicious or fraudulent payment activity. | Strictly necessary | ~1 year |
__stripe_sid |
Stripe, on our domain (only if Stripe.js is embedded on our pages) | Fraud prevention: identifies the checkout session for fraud detection. | Strictly necessary | ~30 minutes |
__cf_bm |
Cloudflare (our CDN/security provider) | Bot detection: distinguishes real visitors from automated attack traffic. Only set if the relevant Cloudflare security feature is enabled. bot and abuse protection | Strictly necessary | ~30 minutes |
Notes on the table:
- Stripe checkout. Checkout redirects you to Stripe’s own hosted payment page, so any cookies there are set by Stripe on Stripe’s domain, not ours. If checkout is a redirect to checkout.stripe.com, the
__stripe_mid/__stripe_sidrows should be removed from this table: Stripe then sets cookies on its own domain, under its own cookie policy, and we will say so in this section instead. If Stripe.js is embedded on our pages, the rows stay. - Fraud-prevention cookies as "strictly necessary". We treat Stripe's fraud-prevention cookies and Cloudflare's bot-detection cookie as strictly necessary: taking payment securely and keeping the service online against automated attacks are part of delivering the service the user asked for.
- localStorage / sessionStorage. The signed-in app also stores data in your browser’s local storage under the prefix
tos:— your risk profile, strategies, settings and consent record. This is strictly necessary for the app to work, stays on your device, and is cleared when you wipe your data in Settings.
6. Analytics without cookies — and why there is no consent banner
We use Plausible Analytics to count visits and understand which pages people read. Plausible is designed to work without cookies and without tracking individuals:
- It sets no cookies and stores nothing on your device.
- It does not use localStorage, fingerprinting, or any persistent identifier.
- It collects aggregate, anonymised page-view data (page URL, referrer, browser type, device type, country).
- IP addresses are not stored. Plausible uses a salted hash that is discarded daily, so visits cannot be linked across days or across sites.
- Data is processed in the EU. There is no cross-site tracking and no sale or sharing of data with advertisers.
Why we do not show a consent banner — our reasoning, in full:
- PECR regulation 6 requires consent for storing information on a user's device, or gaining access to information stored on it, unless the storage or access is strictly necessary for a service the user has explicitly requested (reg 6(4)).
- Every cookie we set (section 5) is strictly necessary in that sense: session cookies so sign-in works, fraud and bot-protection cookies so payment and the service itself are secure. Strictly necessary cookies are exempt from the consent requirement, and the ICO's guidance does not require a banner for exempt cookies alone.
- Plausible does not store anything on the device and does not read stored information from it, so regulation 6 is not engaged by our analytics at all. The residual processing of personal data involved in receiving a page-view request (IP address in transit, user-agent) is covered by UK GDPR, for which our lawful basis is legitimate interests (understanding site usage), documented in a legitimate interests assessment.
- Because no non-exempt storage or access occurs, there is nothing to consent to, and a banner would be noise.
7. What we deliberately do not do
- No advertising or marketing cookies.
- No Google Analytics, Meta Pixel, TikTok Pixel, LinkedIn Insight Tag, or any equivalent.
- No session-recording or heat-mapping tools.
- No cross-site tracking or identity graphs.
- No selling or sharing of visitor data.
- Transactional emails (receipts, licence keys, password resets) are sent via Resend. Open-tracking and click-tracking are switched off on our transactional email.
8. Managing cookies
You can block or delete cookies in your browser settings at any time. Every major browser lets you clear cookies for a single site or all sites, and block them going forward.
Be aware: every cookie we set is one the site needs. If you block cookies for part-timequant.com you will not be able to sign in, and checkout may fail. There are no optional cookies to opt out of — opting out of the necessary ones means the service cannot work.
9. The desktop application
The PTQ desktop application is software that runs on your own machine. It is not a website and does not use browser cookies. What it stores locally (your licence key, your settings, your broker API keys — which never leave your machine) is described in the Privacy Policy and the desktop app's own documentation, not this cookie policy.
10. Changes to this policy
If we add, remove, or change a cookie, we will update the table in section 5 and the "last updated" date at the top. If we ever introduce a cookie that is not strictly necessary (we do not plan to), we will introduce a consent mechanism before setting it, as PECR requires.
11. Contact
Questions about this policy: lewis@jackson.ventures. Our Privacy Policy explains your data rights and how to exercise them, including our ICO registration details 00015214092.