Legal & Policies

Cookie Policy

This Cookie Policy explains how KICKWISE LTD uses cookies and similar storage or access technologies across Kickwise, including essential platform functions, security, payments, preferences, consent records, analytics and advertising.

Last Updated: 2026-09-05

Version: 1.1

01

1. Introduction and Scope

This Cookie Policy explains how KICKWISE LTD, trading as Kickwise (“Kickwise”, “we”, “our”, or “us”), uses cookies and similar storage or access technologies when you visit or use https://kickwise.net and related Kickwise web services.

  • Company: KICKWISE LTD

  • Registered in: England and Wales

  • Company number: 17430326

  • Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

  • Privacy contact: privacy@kickwise.co.uk

This Policy should be read together with our Privacy Policy. It covers visitors, Candidates, Players, Employers, organisation representatives, contributors and other users of the Kickwise platform.

02

2. What Cookies and Similar Technologies Are

A cookie is a small text file that a website asks a browser to store and return later. Cookie rules also extend to other technologies that store information on, or access information from, a user’s device.

Depending on the feature, Kickwise or its service providers may use:

  • first-party or third-party cookies;

  • browser local storage or session storage;

  • session identifiers and security tokens;

  • scripts, tags, pixels or beacons;

  • device or browser signals used for security and fraud prevention; and

  • comparable storage or access technologies.

A technology can serve more than one technical function, but we assess its use by purpose. We do not classify a technology as “essential” merely because it is convenient or useful to us.

03

3. Legal Rules, Consent and Exceptions

In the United Kingdom, our use of storage and access technologies is governed principally by the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), as amended, including by the Data (Use and Access) Act 2025, together with the UK GDPR and Data Protection Act 2018 where personal data is involved. EU ePrivacy rules, the EU GDPR and national laws may also apply to users in the European Economic Area or other jurisdictions.

Where consent is required, we do not intentionally activate non-essential technologies before the relevant choice has been made. Consent must be capable of being refused and later withdrawn.

Consent may not be required where a valid statutory exception applies. In the UK, this can include technologies that are strictly necessary to provide a service requested by the user, technologies necessary for the transmission of communications, and—in defined circumstances—technologies used solely for eligible statistical purposes or to adapt appearance or functionality to a user’s preference. Where we rely on a statistical-purpose or appearance exception that requires a simple and free means of objecting, we provide or maintain an appropriate control.

We do not treat behavioural advertising, cross-site profiling or advertising personalisation as strictly necessary.

04

4. Categories We Use

We group technologies by their actual purpose. The labels shown in a consent interface may be slightly different, but the underlying approach is:

  • Strictly necessary / essential: authentication, session continuity, account security, fraud prevention, load balancing, checkout security, consent records and other functions required to provide a requested service safely.

  • Preferences / functionality: language, appearance and other user-selected settings. Depending on the jurisdiction and exact purpose, these may operate under consent or a lawful exception with an objection mechanism.

  • Analytics / measurement: technologies used to understand performance and service use. Some privacy-preserving analytics may not use cookies or local storage at all; other analytics technologies are controlled according to applicable law.

  • Advertising: technologies used to deliver, measure, limit or personalise advertising. These are treated as non-essential unless a narrow legal exception clearly applies to a specific function.

A single provider can support more than one category. We configure and disclose each use according to its purpose.

05

5. Essential Kickwise Platform Technologies

Kickwise uses first-party session and security technologies to make the platform work. These may support login, CSRF protection, account sessions, language routing, form submission, saved security state, purchase flow continuity and protection against abuse.

These technologies are generally session-based or short-lived, although some may remain longer where needed to remember a security state, a consent record or a user-requested setting. Blocking all such technologies can prevent login, secure forms, payments or other core functions from working correctly.

We do not use essential platform technologies for unrelated behavioural advertising.

06

6. Consent Management and Choice Records

Where a consent or preference mechanism is required, Kickwise uses a consent-management interface to record and apply user choices. The interface may store a consent string, preference identifier, timestamp, vendor choices or similar information so that the website can remember the decision and demonstrate compliance.

Users can accept, reject or manage non-essential purposes where applicable. Refusing optional technologies should not prevent access to core public content, although features that genuinely depend on a refused technology may be unavailable or operate differently.

Consent can be changed or withdrawn through the privacy/cookie settings control made available on Kickwise. Withdrawal does not make earlier lawful processing unlawful. We may ask for a fresh choice if our purposes, vendors, legal requirements or consent configuration materially change.

If Google advertising products are enabled for users in the EEA, the UK or Switzerland, we use a consent-management setup that is intended to meet Google’s applicable certified-CMP and IAB Transparency and Consent Framework requirements for that traffic.

07

7. Cloudflare Network Security and Turnstile

Kickwise uses Cloudflare for network delivery, security, abuse prevention and related infrastructure. Cloudflare may process technical request information and may use strictly necessary cookies or equivalent security tokens to identify legitimate traffic, maintain security state, mitigate bots, protect forms and accounts, or manage challenges.

Kickwise also uses Cloudflare Turnstile for bot and abuse prevention on selected forms or workflows. Turnstile performs browser-side security checks to distinguish legitimate users from automated traffic. Cloudflare states that Turnstile processes only data necessary for this security function and does not access form entries or user communications. Its Ephemeral ID functionality does not require cookies or local storage; depending on configuration, a Cloudflare security cookie such as cf_clearance may be created, for example when pre-clearance is used.

These security technologies are not used by Kickwise for advertising personalisation.

08

8. Cloudflare Web Analytics

Kickwise uses Cloudflare Web Analytics to understand website traffic and performance in a privacy-focused way. Cloudflare states that Web Analytics does not use cookies or localStorage to collect usage metrics and does not fingerprint individual visitors for analytics. It uses a lightweight performance beacon and reports aggregated website-performance information.

Because this service is cookie-free in its documented analytics configuration, its presence does not by itself mean that an analytics cookie has been placed on your device. We nevertheless disclose it here because scripts and browser-side measurement technologies are relevant to transparency and may be regulated differently across jurisdictions or configurations.

09

9. Stripe Payments and Fraud Prevention

Kickwise uses Stripe to process Employer payments for credits and eligible paid platform features. When a user opens or uses a Stripe-powered checkout or payment element, Stripe may use cookies, local storage, device information, IP addresses and other technical signals to operate checkout, recognise a payment session, enable supported payment methods, prevent fraud and assess transaction risk.

Examples of Stripe-controlled cookies can include fraud-prevention identifiers such as __stripe_mid; Stripe may change cookie names, purposes or retention periods as its services evolve. Payment-security technologies may be necessary for the requested transaction even when optional analytics or advertising technologies are refused.

Kickwise does not use Stripe payment cookies to build its own advertising profile of Candidates or Players. Full payment-card credentials entered into Stripe-hosted or Stripe-powered payment fields are handled by Stripe rather than stored by Kickwise.

10

10. Google Advertising and AdSense

If and when Google AdSense or related Google advertising services are enabled on Kickwise, Google and approved advertising technology providers may use cookies or similar technologies to deliver ads, measure delivery, limit frequency, detect invalid traffic, prevent fraud and—where lawful and consented—personalise advertising.

Personalised advertising may use information about prior activity to make ads more relevant. Non-personalised or limited advertising does not mean that no technology is used at all: limited storage or access may still be used for contextual selection, security, frequency controls, reporting or invalid-traffic detection where legally permitted.

For users in regions where consent is required, advertising and personalisation technologies are controlled through the applicable consent mechanism. The current vendor list and purpose details shown in that interface form part of the transparency information available to users.

11

11. Authentication and Third-Party Sign-In

Kickwise may offer sign-in through supported third-party identity providers such as Google or LinkedIn. If you choose one of these options, your browser may be redirected to, or communicate with, the provider’s domain. The provider may use its own cookies or security technologies to authenticate you, maintain its own session, prevent abuse or remember settings.

Cookies already present on a third-party provider’s domain are controlled by that provider, not by Kickwise. We receive only the information made available through the authentication flow in accordance with the permissions and settings that apply to your account.

12

12. Preferences and Functional Technologies

Kickwise may remember choices such as language, interface appearance or other user-requested settings. These technologies are used to make the service behave in the way the user has selected and are not intended for cross-site behavioural advertising.

The legal treatment of preference technologies can vary by jurisdiction. In the UK, an applicable appearance/functionality exception may be available where the statutory conditions are met and the user has a simple, free way to object. Elsewhere, consent may be required. Our preference controls are configured according to the rule that applies to the relevant purpose and user.

13

13. Embedded Content, External Links and Future Integrations

Pages may contain links to external websites or, where a feature is enabled, embedded third-party content such as media, maps or other integrations. An external site can set or access its own technologies after you open it. Embedded content can sometimes allow the third party to receive technical information as part of loading the content.

Where Kickwise introduces an optional embedded service that requires non-essential storage or access, we will classify it appropriately and seek consent where required before activating it. This Policy does not control cookies placed independently when you leave Kickwise and visit another website.

14

14. Current Technology Register and Duration

  • Kickwise first-party session/security

    • Purpose: Login, secure forms, session continuity, language routing and requested platform functions

    • Category / control: Essential; generally active when needed

    • Typical duration: Usually session or short-lived; some security/preference records may persist

  • Consent-management records

    • Purpose: Remember consent, refusal, vendor and purpose choices

    • Category / control: Essential for recording and respecting choices

    • Typical duration: Persistent for an appropriate period, then refreshed or recreated

  • Cloudflare network/security

    • Purpose: Traffic delivery, bot mitigation, security and challenge state

    • Category / control: Essential where required for security

    • Typical duration: Session or short-lived in many cases; configuration-dependent

  • Cloudflare Turnstile

    • Purpose: Bot and abuse prevention on protected forms/workflows

    • Category / control: Essential security where deployed

    • Typical duration: Ephemeral by design; cf_clearance or equivalent may exist in some configurations

  • Cloudflare Web Analytics

    • Purpose: Aggregate traffic and performance measurement

    • Category / control: Privacy-focused analytics; documented without cookies/localStorage

    • Typical duration: No analytics cookie/localStorage in the documented configuration

  • Stripe

    • Purpose: Checkout, payment-session continuity, fraud and risk prevention

    • Category / control: Essential when necessary to process a requested payment; other purposes assessed separately

    • Typical duration: Provider-controlled; varies by cookie and payment feature

  • Google advertising / AdSense

    • Purpose: Ad delivery, measurement, frequency controls, invalid-traffic protection and personalisation where enabled

    • Category / control: Advertising; consent-controlled where required

    • Typical duration: Provider-controlled and purpose-dependent

  • Google / LinkedIn sign-in

    • Purpose: Authentication, provider session and security when selected by the user

    • Category / control: User-initiated authentication / essential to that selected flow

    • Typical duration: Provider-controlled and account/session-dependent

This register describes the main technology families rather than promising a fixed list of every technical cookie name. Exact names and lifetimes can change with browser behaviour, provider updates, security configuration and product changes. Where our consent interface provides a more granular live vendor or cookie list, that interface should be read together with this Policy. We periodically review the technologies deployed on Kickwise and remove or reclassify items when appropriate.

15

15. Managing, Refusing or Withdrawing Choices

Where non-essential technologies depend on consent, you can refuse them before activation and change your decision later through Kickwise’s privacy/cookie settings. Where a lawful UK exception relies on a right to object rather than prior consent, the relevant control can be used to object free of charge.

Changing a choice applies prospectively. A previously stored cookie may remain on the device until deleted or expired even after the related purpose is disabled, but we will not intentionally continue using it for a purpose that no longer has a valid basis. Some third-party providers also offer their own privacy or advertising controls.

16

16. Browser and Device Controls

Most browsers allow you to view, delete, block or limit cookies and site data. Private-browsing modes and device-level privacy controls may also affect storage. These controls are separate from Kickwise’s own preference mechanism.

Blocking all cookies or site storage can break authentication, secure forms, payment flows, security challenges, saved settings or other functions. Browser controls also cannot necessarily remove data or preferences already held by a third-party provider on its own systems.

We do not rely on continued browsing, silence or inactivity as consent where valid consent is required.

17

17. Third-Party Processing and Personal Data

Some technologies described in this Policy involve service providers processing technical or personal data. Their role, the categories of data involved, lawful bases, international transfers, retention and data-protection rights are explained more fully in the Kickwise Privacy Policy and, where relevant, the provider’s own privacy information.

A provider may act as our processor for some activities and as an independent controller for others. The fact that a cookie or script is supplied by a third party does not remove Kickwise’s responsibility to configure and disclose its use appropriately where we decide to deploy it.

18

18. Changes, Audits and New Technologies

We may update this Cookie Policy when we add or remove technologies, change providers, alter consent configurations, introduce new payment or advertising functions, or when the law or regulatory guidance changes.

We aim to audit the storage and access technologies used on Kickwise periodically, confirm their purposes, review whether they are first-party or third-party, check their expected duration and ensure the consent or objection mechanism matches the actual use. Material changes will be reflected in a revised version and a new “Last Updated” date.

19

19. Contact

For questions about this Cookie Policy, storage and access technologies, or your privacy choices, contact:

Clear choices, limited use. We use storage and access technologies only for defined purposes and give you meaningful control where the law requires it.