Effective date: March 2026
Last updated: March 2026
Version: 1.1
Cookies are small text files that are placed on your device (computer, phone, or tablet) when you visit a website. They are widely used to make websites work more efficiently, remember your preferences, and provide information to the website owner.
Similar technologies include local storage, session storage, and pixel tags. When we refer to "cookies" in this policy, we mean all of these technologies.
We use cookies on our website (omniwo.com) and dashboard (app.omniwo.com) for the purposes described below. We categorise cookies into four groups:
These cookies are essential for the website to function. They cannot be disabled.
| Cookie | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
__session |
Firebase Auth | Maintains your login session on the dashboard | Session | First-party |
firebase:authUser |
Firebase Auth | Stores authentication state for single-page app | Session | First-party |
__stripe_mid |
Stripe | Fraud prevention during checkout | 1 year | Third-party |
__stripe_sid |
Stripe | Checkout session identification | 30 minutes | Third-party |
csrf_token |
Omniwo | Cross-site request forgery protection | Session | First-party |
cookie_consent |
Omniwo | Remembers your cookie preferences | 1 year | First-party |
Legal basis: These cookies are exempt from consent under PECR Regulation 6(4) because they are strictly necessary for the service you have requested.
These cookies remember your preferences and enhance your experience. They are set only with your consent.
| Cookie | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
locale |
Omniwo | Remembers your language/locale preference | 1 year | First-party |
ui_prefs |
Omniwo | Stores UI preferences (e.g., sidebar collapsed state) | 1 year | First-party |
wearable_state |
Omniwo | Remembers which wearable connection view to show | Session | First-party |
Legal basis: Consent (PECR Regulation 6).
These cookies help us understand how visitors use our website. All analytics data is anonymised — we never include health data, biomarker values, or personal health information in analytics.
| Cookie | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
_ga |
Google Analytics 4 | Distinguishes unique visitors (anonymised) | 2 years | Third-party |
_ga_[ID] |
Google Analytics 4 | Maintains session state | 2 years | Third-party |
_gid |
Google Analytics 4 | Distinguishes visitors within 24h | 24 hours | Third-party |
What we track: Page views, session duration, device type, browser, general location (city level). What we NEVER track: Health data, biomarker values, test results, wearable data, personal identifiers.
IP anonymisation: Google Analytics is configured with IP anonymisation enabled. Your full IP address is never stored.
Legal basis: Consent (PECR Regulation 6).
These cookies are used only if you have opted in to marketing communications. They help us measure the effectiveness of our marketing campaigns.
| Cookie | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
__kla_id |
Klaviyo | Tracks email campaign engagement | 2 years | Third-party |
_fbp |
Meta Pixel | Measures ad performance (Phase 2 only) | 90 days | Third-party |
_gcl_au |
Google Ads | Conversion tracking (Phase 2 only) | 90 days | Third-party |
Note: Meta Pixel and Google Ads cookies are planned for Phase 2 and are not active at launch. They will only be enabled if you give explicit marketing consent.
Legal basis: Explicit consent (PECR Regulation 6).
Some cookies are set by third-party services that appear on our pages. We do not control these cookies. Please refer to the relevant third party's privacy policy for more information:
| Provider | Privacy Policy |
|---|---|
| Google Analytics | policies.google.com/privacy |
| Stripe | stripe.com/privacy |
| Klaviyo | klaviyo.com/legal/privacy |
When you first visit omniwo.com, you will see a cookie consent banner asking for your preferences. You can:
You can change your cookie preferences at any time by:
If you reject non-essential cookies:
Your cookie preferences are stored in the cookie_consent cookie for 1 year.
We never store health data in cookies.
Your blood test results, biomarker values, health insights, wearable data, Overall Status, and any other health-related information are stored exclusively in Firestore (our secure, encrypted database hosted on Google Cloud Platform in the UK).
Cookies contain only technical identifiers (session tokens, preference flags, analytics identifiers). No cookie on our site will ever contain your health information.
You can also control cookies through your browser settings. Here's how:
| Browser | Instructions |
|---|---|
| Chrome | Settings → Privacy and Security → Cookies and other site data |
| Firefox | Settings → Privacy & Security → Cookies and Site Data |
| Safari | Preferences → Privacy → Manage Website Data |
| Edge | Settings → Cookies and site permissions → Manage and delete cookies |
| iOS Safari | Settings → Safari → Clear History and Website Data |
Note: Blocking all cookies may prevent you from logging in to your dashboard or completing checkout.
Some browsers send a "Do Not Track" (DNT) signal. We respect DNT signals by disabling analytics cookies when this signal is detected.
We may update this Cookie Policy from time to time. When we make changes:
If you have questions about our use of cookies:
| Method | Details |
|---|---|
| privacy@omniwo.com | |
| Post | Data Protection, Omniwo Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ |
For broader privacy concerns, please see our Privacy Policy.
Version: 1.1
Last updated: March 2026
Regulation: Privacy and Electronic Communications Regulations 2003 (PECR) + UK GDPR