Cookie policy

The two cookies we set, what each one does, how long it lasts, and how to control them.

Last updated: 29 September 2026

This policy explains the small files that Breed Right stores on your device when you use this website, breedright.co.uk (the “Site”). It tells you what each one is called, what it does, how long it lasts and how you can control it. It sits alongside our privacy policy, which explains everything else we do with personal data, and it forms part of our terms of use.

1. Who we are

Breed Right is a trading name of Whelpy Ltd, a company registered in England and Wales.

  • Registered company name: Whelpy Ltd
  • Company number: 17436550
  • Place of registration: England and Wales
  • Registered office: Unit 3 Factory 3 Valhalla, Dobles Lane, Holsworthy, England, EX22 6HN
  • Address for correspondence: Unit 3 Factory 3 Valhalla, Dobles Lane, Holsworthy, England, EX22 6HN
  • Email: hello@breedright.co.uk
  • ICO data protection register: ZC238509

References to “we”, “us” and “our” in this policy are to Whelpy Ltd. References to “you” and “your” are to the person using the Site. We are the data controller for the personal data described here, and for anything in this policy you can reach us at hello@breedright.co.uk or through our contact page.

2. What a cookie is, and what the law covers

A cookie is a small text file that a website asks your browser to store on your device, and that your browser sends back on each later request. It is how a website can tell that two page requests came from the same person, which is what makes signing in possible.

The rules are in regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”) and the exceptions to it in Schedule A1 (regulation 6 as substituted, and Schedule A1 as inserted, by the Data (Use and Access) Act 2025 from 5 February 2026). They apply to storing information on your device, or gaining access to information already stored there, so they cover more than cookies: local storage, session storage, tracking pixels, device fingerprinting and similar techniques all count. We use none of those. Cookies are the only such technology on the Site, and there are two of them. Where a cookie also involves personal data, the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 apply as well, and our privacy policy explains that side of it.

3. The cookies we set

Name What it is for How long it lasts Type
brsess Set by us, on this domain The session cookie. It holds one randomly generated reference number and nothing else. That number is how our server recognises that two page requests came from the same visit, which is what keeps you signed in, what lets us check the one-time security tokens that protect every form on the Site against cross-site request forgery, and what gets a short status message such as “your enquiry has been sent” back to the right person. The contact and enquiry forms can be used without an account, so this cookie is set on your first visit whether or not you ever sign in. Until you close your browser. No expiry date is set on it, so your browser discards it at the end of the session. A signed-in session also ends after 2 hours of inactivity. Strictly necessary
br_remember Set by us, on this domain The “keep me signed in” cookie. It is set only if you tick “Keep me signed in for 30 days” when you sign in. It holds two random values: a reference we use to find the matching record, and a secret. We store the secret only as a one-way hash, so our database cannot be used to sign in as you, and the secret is replaced with a new one every time the cookie is used, so a copy of it stops working. 30 days from the day it is issued. Signing out deletes it and cancels it on our side as well. Changing your password cancels it on every device. Strictly necessary for the feature you asked for (see section 6)

How both cookies are protected. Both are marked HttpOnly, so no script running in your browser can read them. Both are marked SameSite=Lax, so they are not sent from another site’s pages. Both are marked Secure whenever the page is served over HTTPS, so they are never sent over an unencrypted connection. Neither contains your name, your email address, or anything else that is readable: each one holds random values that mean something only to our server.

4. What we do not use

There is nothing else. To be specific, the Site has:

  • no analytics of any kind, first party or third party;
  • no advertising, retargeting or profiling cookies, and no advertising on the Site at all;
  • no social media buttons, share widgets, embedded videos, maps or comment systems, which are the usual way third-party cookies arrive on a page;
  • no local storage, session storage or fingerprinting. Our JavaScript does not read or write browser storage at all;
  • no tracking pixels in our pages or in the emails we send you; or
  • no third-party cookies. Nobody else sets a cookie through this Site.

We also host our own fonts, images, stylesheets and scripts. Everything a page needs is served from breedright.co.uk, so loading a page here does not send your IP address or anything else to any other company. We do not sell personal data and we do not share it with advertisers or data brokers.

5. Card payments and Stripe

When card payments go live, we will use Stripe. Paying will send you to Stripe’s own secure checkout page, hosted by Stripe on its own website (checkout.stripe.com), where you enter your card details and are then returned here. Any cookies Stripe sets are set by Stripe, on Stripe’s own domain, and are governed by Stripe’s cookie notice, not by this policy. No Stripe code runs on breedright.co.uk, so Stripe sets nothing on our domain and your card details never touch our servers. If that ever changes, we will update this page before it does.

6. Why you have not seen a cookie banner

We do not ask for cookie consent because we do not set any cookie that needs it. Regulation 6 of PECR stops a website storing information on your device unless your consent or an exception in Schedule A1 applies. The strictly necessary exception in paragraph 4 of Schedule A1 covers storage that is “strictly necessary for the provision of an information society service requested by the subscriber or user”. Both of our cookies are within that exception: one is what keeps you signed in and protects the forms you submit, and the other is set only when you actively ask for it.

A consent banner that asked you to agree to cookies we are entitled to set anyway would be a box to click for no purpose, so we do not show one. That is a considered position rather than an oversight.

The “keep me signed in” cookie is always your choice. The box is unticked by default. If you would rather not have a cookie stored on your device for 30 days, leave it unticked and sign in as normal. A stricter reading of the strictly necessary exception might treat staying signed in as a convenience rather than something strictly necessary. On that reading you have consented anyway, as paragraph 2 of Schedule A1 allows: the box starts unticked, and this page tells you the cookie’s name and how long it lasts before you tick it. You can withdraw that consent at any time by signing out, which deletes the cookie and cancels it on our side.

If we ever add anything non-essential. Analytics is the obvious example. We would have to do all of the following first: update this page to name the cookie, its purpose and its lifetime; ask you for consent before setting it, with refusing made as easy as accepting; keep a record of what you chose and let you change your mind; and make sure the Site still works properly if you say no. Nothing non-essential is set unless and until you have said yes. There is no analytics account, tag manager or advertising pixel waiting behind a switch.

7. How to control cookies in your browser

You do not need our permission, and you do not need an account, to manage cookies. Every browser lets you see the cookies a site has set, delete them, block them for one site or block them everywhere. The menus move around between versions, so rather than give you steps that go out of date, the general route is:

  • Chrome and Edge: Settings, then Privacy and security, then Cookies and site data (or third-party cookies).
  • Firefox: Settings, then Privacy & Security, then Cookies and Site Data.
  • Safari on a Mac: Safari, then Settings, then Privacy. Safari on iPhone or iPad: the Settings app, then Apps, then Safari.
  • Any browser: clearing your browsing data removes both of our cookies. Private or incognito windows discard them when you close the window.

Deleting br_remember from your browser stops that device signing you in automatically the next time you visit. To cancel it on our side as well, use Sign out, which deletes our record of it too. The Information Commissioner’s Office publishes plain-English guidance on cookies at ico.org.uk.

8. What stops working if you block our cookies

We would rather tell you than let you find out:

  • Browsing still works. You can read every stud dog, litter, breeder profile and guide on the Site without cookies and without an account.
  • You cannot sign in. Without the session cookie there is no way for the Site to know that the page you are on belongs to the same visit as the one where you entered your password.
  • Forms will be refused. The contact and enquiry forms carry a one-time security token held in your session. With cookies blocked the token cannot be checked, so the Site cancels the submission and asks you to try again.
  • “Keep me signed in” will not work, and you will be asked to sign in again each time.

Blocking cookies never costs you money, never affects a membership you have already paid for, and never deletes anything you have listed.

9. Things that are not cookies

For completeness, two things people often expect to find in a cookie policy. Neither involves storing anything on your device.

  • Server logs. Like every website, our server records the requests it receives: IP address, browser user-agent, the page requested and the time. We keep these for no longer than 90 days, for security and for fixing faults. Records of failed sign-in attempts, which exist to slow down anyone guessing passwords, are cleared automatically once they are more than 24 hours old. None of it is used to build a profile of you or to follow you between websites.
  • Your account. If you are signed in, what you do on the Site is associated with your account on our server rather than with a cookie. Our privacy policy sets out what we hold, why, and for how long.

10. Changes to this policy

We will update this page whenever the cookies we set change, and the “Last updated” date at the top shows when it was last revised. If we ever propose to set a cookie that is not strictly necessary, this page will be updated before that cookie is set, and we will ask for your consent at the time.

11. Contact us and your rights

Nothing in this policy reduces your legal rights. If anything here differs from your legal rights, your legal rights win. For detailed information about your rights, contact your local Citizens Advice or Trading Standards office.

If you have a question about cookies, or you think this page does not match what the Site actually does, email hello@breedright.co.uk or use our contact form and we will be happy to help. Our full details are in section 1.

If you are unhappy with how we have handled your personal data, you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113, although we would welcome the chance to put it right first.

Privacy policy · Terms of use · Contact us