Cookie policy
This site runs on a short list of cookies: the handful needed to make pages work and, only if you agree to it, a privacy-first analytics pair. There is no advertising or cross-site tracking here at all.
Last updated 14 August 2026
What this policy covers
This policy explains the cookies and similar storage set by the public website at smspro.agency, operated by SMSPro Communications Ltd, registered in Gibraltar under company number 118472 at Suite 4, Watergardens Block 6, Waterport Road, Gibraltar GX11 1AA. It sits alongside our privacy policy, which explains what we do with personal data once we hold it.
A cookie is a small text file a site asks your browser to store and send back on your next request. Related technologies such as local storage and session storage do a similar job without the network round trip. Where we use those, we treat them as cookies for the purposes of this policy and of consent.
Our approach
Essential cookies are set because the site cannot function without them. Everything else is off until you say otherwise. When you first arrive you are asked a plain question with a genuine reject option, and rejecting is one click, exactly like accepting. We do not treat continued scrolling as agreement and we do not re-ask on every visit.
We set no advertising cookies, no retargeting pixels, no social network trackers and no cross-site identifiers. We sell to a few hundred licensed operators, not to a mass consumer audience, so behavioural ad tracking would buy us nothing and cost our visitors their privacy. Fonts and scripts are served from our own domain rather than a third-party content network, so simply loading a page does not hand your IP address to anyone else.
Essential cookies
These are strictly necessary to deliver a service you have asked for, so they do not require consent and cannot be switched off from the banner.
- sp_session - keeps your request continuity across pages, including form state if you are part way through an enquiry. Expires when you close the browser.
- sp_csrf - a rotating token that proves a form submission came from this site and not from a third party trying to submit on your behalf. Session only.
- sp_consent - records the cookie choice you made so we do not ask again on every page. Stores nothing but your preference and its date. Expires after twelve months, or immediately if you withdraw consent.
- sp_locale - remembers the language and number formatting you selected. Expires after twelve months. Only set if you change the default.
Analytics cookies
Set only after you agree, and removed as soon as you withdraw that agreement. We use them to understand which pages help operators evaluate us and which ones lose people halfway down.
- _sp_id - a random identifier that lets us count a returning visitor once rather than five times. It contains no name, email or account reference and is never matched to a client account or to a message recipient. Expires after thirteen months.
- _sp_ses - marks the current visit so page views can be grouped into a single session. Expires after thirty minutes of inactivity.
Analytics data is aggregated, IP addresses are truncated before storage so location resolves no more precisely than country, and reports are retained for fourteen months. The analytics provider is a sub-processor acting on our instructions and is contractually barred from using the data for its own purposes or from combining it with data from other sites.
The messaging platform is separate
The SMSPro console and API are a separate authenticated application on a different subdomain, and this policy does not describe them. That application sets only strictly necessary cookies: an encrypted session cookie, a CSRF token, and a device recognition token used to decide when to re-prompt for multi-factor authentication. It runs no analytics, no advertising tags and no third-party scripts of any kind.
Nothing set by the marketing site follows you into the platform, and nothing set by the platform is readable here. Data handled inside the console belongs to the client operator and is governed by the data processing agreement and by our privacy policy, not by a cookie banner.
The SMS messages we deliver on behalf of clients contain no cookies, no tracking pixels and no open beacons. An SMS cannot carry one. Where a message contains a shortened link, the redirect is logged by the client for click attribution under the client's own privacy notice.
How to control cookies
- Use the banner. Accept or reject analytics on your first visit. To change your mind later, clear the sp_consent cookie for this site and the question is asked again on your next page load.
- Use your browser. Every major browser lets you block or delete cookies for a specific site. In Chrome and Edge look under Settings, Privacy and security, Third-party cookies and site data. In Firefox look under Settings, Privacy and Security. In Safari look under Settings, Privacy, Manage website data.
- Signal it once. We honour the Global Privacy Control signal. If your browser or extension sends it, analytics stays off and you are not asked again.
- Block scripts entirely. Private browsing and content blockers work normally here. Blocking everything still leaves the site fully usable.
Blocking essential cookies is your right, but forms on this site depend on the CSRF token, so an enquiry may fail to submit if that cookie is refused.
Lawful basis
Essential cookies are set on the basis of our legitimate interest in providing a secure, working website. Analytics cookies are set on the basis of your consent, which you can withdraw at any time without any effect on your dealings with us. The personal data behind each is described in the privacy policy.
Changes to this policy
If we add a cookie, we update this page and, where the addition is not strictly necessary, we ask for consent again before it is set. The date at the top of the page always reflects the current version. Questions go to hello@smspro.agency.