Data protection

Cookies

What are cookies?

  • Cookies are small text files. They are placed on your computer or smartphone to collect data. They can help make your interaction with the website faster and easier. Without them, the website may think you are a new visitor every time you move to a new page.

Cookies also tell us what information you are most interested in. In return, we can serve you the information you want. The better we understand your preferences, the better we can meet them.

We also use cookies to collect anonymous data about how you use the website. For example, which pages you have viewed and how long you have remained on our site. This helps us to identify any improvements we need to make to the website.

Disabling cookies

Your preference might be to disable cookies, and we respect that. If you do allow our cookies onto your computer, be aware they have got a lifespan. This ranges from a few minutes to one year before they expire.

Cookies used on our site

Our website (harrow.gov.uk) uses the cookies below.

Cookie  Cookie function Expiry
PHPSESSID

This cookie identifies you as a unique user while you are browsing the website. No personal information is stored. It enhances your experience by letting us remember that you are logged in.

Expires when you close the browser
visitedPages

This cookie stores a list of pages you have visited on the site, up to a maximum of 20. If you visit more than 20 pages the oldest page visit is discarded from the cookie.

Expires within 1 year
location

This cookie stores your device location if you share it. It does so in the form of latitude and longitude coordinates. This helps us provide you with information relevant to your location.

Expires within 1 year
TestCookie

Used to test whether your browser can accept cookie.

Expires when you close the browser
cfduid

This cookie is set by Cloudfare. It speeds up page loads and detects bots on the site.

Expires when you close the browser

MyHarrow Account

MHA is our online account for residents and businesses. Once signed in, you can view and manage your council accounts.  It uses the cookies below.

Cookie Cookie function Expiry
JSESSIONID

This cookie identifies you as a unique user while you are browsing the website. No personal information is stored. It enhances your experience by letting us remember that you are logged in. So you can browse the website without having to log in again or submit a form.

Expires when you close the browser
Lwa

Database GUID (Globally Unique ID). An encrypted value. It lets us identify the accessed environment.

Expires when you close the browser
ASP.NETSessionId

This cookie identifies you as a unique user while you are browsing the website. No personal information is stored. It enhances your experience by letting us remember that you are logged in. So you can browse the website without having to log in again or submit a form.

Expires when you close the browser

Online forms

Our online forms allow users to apply, book, and report things online. They use the cookies below.

Cookie Cookie function Expiry
 JSESSIONID

This cookie identifies you as a unique user while you are browsing the website. No personal information is stored. It improves your experience by letting us remember you are signed in. So you can browse the website without having to log in again or submit a form.

Expires when you close the browser
ASP.NETSessionId

This cookie identifies you as a unique user while you are browsing the website. No personal information is stored. It improves your experience by letting us remember you are signed in. So you can browse the website without having to log in again or submit a form.

Expires when you close the browser
Lwa

Database GUID (Globally Unique Identifier). An encrypted value that lets us identify the accessed section.

Expires when you close the browser
cookiesDirective Identifies whether the cookie pop-up has been accepted or not. Deleted at the end of the session

Website analytics - Google Analytics (GA4)

Google Analytics is the service we use to collect analytics on the use of its websites. These cookies collect data on how visitors use our website. We use the information to help us improve the website. The data is collected anonymously. It uses the cookies below.

Cookie Cookie function Expiry
_ga

This is a first-party cookie. It tracks your visits to our website and MyHarrow Account. It helps us to know if you are a new or returning visitor and build user profiles.

Expires in 2 years
_gid  

This cookie tracks the pages you visit on our website and MyHarrow Account.  It tracks a user activity during a specific visit. It helps us understand, for example, session duration.

Expires in 2 years

Website analytics - Hotjar

We use Hotjar to better understand our users’ needs. For example, how much time they spend on pages, what they like, dislike, and so on. Hotjar uses cookies and other technologies to collect data on our users’ behaviour and devices. This includes a device's:

  • IP address. It gets processed during your session. It is stored in a de-identified form.
  • Screen size
  • Type (unique device identifiers)
  • Browser information
  • Geographic location (country only)
  • And the preferred language used to display our website.

Hotjar stores this data for us in a pseudonymised user profile. Hotjar is contractually forbidden to sell any of the data.

Maps

The map resource provides interactive maps embedded in our web pages. They use the cookies below.

Cookie Cookie function Expiry
_ga Google marketing cookie Expires after 2 years
_gid Google cookie to store and count page views Expires after 1 day
_hjSessionUser Cookie is set when a user first lands on a page and persists a unique Hotjar User ID for that site, ensuring data from subsequent visits to the same site are attributed to the same user ID. Duation of 365 days and stored in JSON
visid_incap Incapsula DDoS Protection and Web Application Firewall: cookie for linking certain sessions to a specific visitor (visitor representing a specific computer). In order to identify clients that have already visited Incapsula. Expiration after 364 days, 2 hours

Planning portal

This database holds all submitted planning applications. It uses the cookies below.

Cookie Cookie function Expiry
ASP.NETSessionId

This cookie identifies you as a unique user while you are browsing the website. No personal information is stored. It enhances your experience by letting us remember that you are logged in.

Expires when you close the browser
PHPSESSID

This cookie is for continuity as you navigate the website. It enables us to keep you logged in to the site or to submit a form.

Expires when you close the browser
visitedPages

This cookie stores a list of pages you have visited on the site, up to a maximum of 20. If you visit more than 20 pages, the oldest page visit is discarded from the cookie.

Expires within 1 year
WTFPC

This is a first-party cookie that tracks your visits across our website. It helps us to know if you are a new or returning visitor.

Expires in 24 hours

Modern.Gov

The modern.gov site holds documents, meeting minutes and agendas. It uses the cookies below.

Cookie Cookie function Expiry
ASP.NETSessionId

This cookie identifies you as a unique user while you are browsing the website. No personal information is stored. It enhances your experience by letting us remember that you are logged in.

Expires when you close the browser
mglogon

This cookie identifies you as a unique user while you are browsing the website. No personal information is stored. It enhances your experience by letting us remember that you are logged in.

Expires when you close the browser

FIS 

Cookie Cookie function Expiry
SynergyAuth_{Environment Id}

A combined session state and user identification. Encrypted and “http only”. Anonymous users are not allowed general purpose session state in Synergy, and so the two are coupled in a single cookie to prevent the possibility of session state transferring from one user to another. Issued on successful login and contains: User session identifier, identity, issued date

 
EnquiryShortlist{Website Id}

A legacy cookie that stores a “shopping basket” of provider enquiries for anonymous and authenticated users. Not-encrypted but “http only”. Contains pipe delimited list of provider identifiers.

 
CONSENT NID
APISID
SAPISID
SID
__Secure-{???}PISID
HSID
SSID
Google issued cookies where pages utilise the optional google mapping features of Synergy. See: How Google uses cookies – Privacy & Terms – Google  
PELanguageCookie A legacy cookie that stores the selected language, such as English or Welsh. Not-encrypted but “http only”. Contains: Language identifier  
TribalAction (TribalActionMonitor? → Reporting / Gateway action monitor) A legacy cookie which tracks a cross tab action such as opening a reporting. Not-encrypted, not “http only”  
yPos A legacy cookie which stores the mouse y scroll position during certain actions. Logged for removal: SYN-12297 - Getting issue details... STATUS. Not-encrypted, not “http only”.  
OpenIdConnect.nonce.{Unique identifier} Utilised by the optional single sign on authentication. Nonce cookie as defined by the OpenID specification. See: https://openid.net/specs/openid-connect-core-1_0.html  
ASP.NET_SessionId A standard ASP.Net session state cookie. Issued to anonymous or authenticated users where does not already exist.   
SynergyAuth A standard ASP.Net forms authentication cookie. Issued to authenticated users on successful login.  

 

Consultations - Talk Harrow

Talk Harrow uses Granicus software for our online consultations and surveys. Please visit their Cookie policy template page for further details.