This policy explains what cookies ProvisionIQ sets when you use the platform, why we set them, and how you can control them. We keep cookie use to a minimum: only what is necessary to run the service and, with your consent, to understand how the platform is used so we can improve it.
What are cookies?
Cookies are small text files placed on your device by a website. They allow the site to recognise your browser and remember information between page loads, for example, that you are signed in. Some cookies are deleted when you close your browser (session cookies); others persist until they expire or you delete them (persistent cookies).
Strictly necessary cookies
These cookies are required for ProvisionIQ to function. They cannot be disabled.
| Cookie name | Set by | Purpose | Duration |
|---|---|---|---|
| AUTH_SESSION_ID | ProvisionIQ (Keycloak) | Ties your browser to your authentication session on our identity server. Required to keep you signed in while you navigate the platform. | Session |
| KEYCLOAK_SESSION | ProvisionIQ (Keycloak) | Persists your login state across browser tabs and page reloads. Used for single sign-on (SSO) so you don't need to log in again when opening a new tab. | Session |
| KC_RESTART | ProvisionIQ (Keycloak) | Stores the login flow state so authentication can resume if your browser is refreshed mid-flow. | Session |
All of the above cookies are set by our Keycloak identity server, which runs on the same domain as ProvisionIQ. They are HttpOnly and SameSite=Strict, so they cannot be read by JavaScript and are not sent on cross-site requests.
Analytics cookies
Optional: requires your consentWith your consent we load Google Analytics 4 via Google Tag Manager. These cookies help us understand how the platform is used: which features are most visited and where users encounter difficulty, so we can prioritise improvements. No personally identifiable information is sent to Google.
| Cookie name | Set by | Purpose | Duration |
|---|---|---|---|
| _ga | Google Analytics | Distinguishes unique users by assigning a randomly generated client ID. Used to calculate visitor and session counts in usage reports. | 2 years |
| _gid | Google Analytics | Identifies a user session. Helps distinguish separate visits from the same device within a 24-hour window. | 24 hours |
| _ga_<container> | Google Analytics 4 | Stores and updates a unique value for each page visit, used by GA4 to maintain session state. | 2 years |
Analytics cookies are only set after you accept the cookie banner. If you decline, or simply close the banner without accepting, analytics remain disabled for your session. Google Analytics is configured with IP anonymisation enabled. For more information see Google's Privacy Policy.
Browser storage (not cookies)
ProvisionIQ also stores a small number of items in your browser's localStorage. Unlike cookies, these are never sent to our servers. They exist only in your browser and are used purely for interface preferences.
| Key | Purpose |
|---|---|
| piq_cookie_consent | Records the date you accepted the cookie banner so it is not shown again. |
| piq-theme | Stores your light or dark mode preference. |
| piq-selected-org | Remembers the last school or trust you were viewing (for users with access to multiple organisations). |
| piq-isp-layout | Saves your preferred layout mode on the ISP detail page. |
You can clear localStorage at any time via your browser settings (usually under “Site data” or “Cookies and site data”). This will reset your preferences and show the cookie banner again on your next visit.
Managing your cookie preferences
You can control analytics cookies in two ways:
- Via the cookie banner, shown on your first visit. Accepting enables analytics; closing without accepting leaves them disabled.
- Via your browser settings. All modern browsers let you block or delete cookies. Blocking strictly necessary cookies will prevent sign-in from working. See your browser's help pages for instructions.
Strictly necessary cookies cannot be disabled while using ProvisionIQ, as they are essential to the authentication flow.
Questions
If you have any questions about this policy or how we use cookies, please contact us at hello@provisioniq.co.uk.
© 2026 ProvisionIQ. All rights reserved.