#01Summary
Academyship uses cookies and browser storage to operate and secure its website and application, maintain sessions, protect requests and retain limited functional state. Academyship does not use Student Data for advertising. The current cookies, storage and external browser services identified in the production review are set out below.
No analytics technology, advertising pixel, session-replay technology or support-chat widget was identified in the inspected production homepage, pricing page, login page or the scripts those pages load. Stripe’s hosted checkout is relevant only when a visitor or Institution proceeds with subscription payment.
Scope: this policy covers the inspected production responses for /, /pricing and /login, and browser code delivered for those pages. It does not represent an authenticated-only cookie inventory. We review this policy whenever cookies, browser storage, analytics, advertising, chat, pixels, session replay or embedded third-party technology changes.
#02What cookies and similar technologies are
Cookies are small text files stored on your device by your browser. "Similar technologies" include browser local storage and session storage, and comparable mechanisms. They can be "first party" (set by Academyship) or "third party" (set by another provider). They can last only for your session, or persist for a set period. We use the general term "cookies" in this policy to refer to these technologies.
#03Where this policy applies
This policy applies to our marketing website at academyship.com.au and to the ACADEMYSHIP web application and portals. The inventory below distinguishes cookies set by the Laravel application from browser storage created by the inspected public-page code.
#04Categories we use
- Strictly necessary — currently used. Required to operate the service, maintain a web session and protect requests. These cannot be switched off without affecting core functionality.
- Preferences / functional — first-party browser storage used for homepage scroll restoration, sign-up source attribution and an optional remembered username.
- Analytics / performance — none was identified in the inspected production pages or their delivered code.
- Advertising / marketing — none was identified in the inspected production pages or their delivered code. We do not use Student Data for advertising.
#05Current cookies and storage
The table below records the exact first-party cookies and storage observed in the inspected production responses and delivered page code. Cookie attributes are shown as sent in the inspected unauthenticated production responses. “Not applicable” means the item is browser storage rather than a cookie.
Where Academyship supports an Institution-controlled or custom domain, necessary first-party application cookies may be set as host-only cookies against that configured Institution-branded or Academyship tenant domain. The cookie names, purposes and attributes below otherwise remain the same.
No IndexedDB use, analytics or advertising storage, chat-widget storage, CDN cookie, load-balancer cookie or security-provider cookie was identified in that scope. Academyship does not store passwords, authentication credentials, TFNs or full payment-card details in browser storage. The optional remembered-username items below are created only when a User selects that preference.
| Name | Provider | Domain / path | Purpose | Information stored | Category | Duration | First or third party | Secure / HttpOnly / SameSite | Essential? | Consent required? | Where created / pages |
|---|---|---|---|---|---|---|---|---|---|---|---|
| laravel_session | Academyship | Host-only academyship.com.au, or a configured Institution-branded or Academyship tenant domain / / | Maintains the server-side web session, including an authenticated session after sign-in. | A session identifier only; the session data is held server-side. | Strictly necessary | 2 hours (Max-Age 7,200 seconds) | First party | Yes / Yes / Lax | Yes | No | Set by the Laravel application in inspected responses for /, /pricing and /login, or the corresponding configured domain. |
| XSRF-TOKEN | Academyship | Host-only academyship.com.au, or a configured Institution-branded or Academyship tenant domain / / | Supports cross-site-request-forgery protection for protected requests. | A CSRF token. | Strictly necessary | 2 hours (Max-Age 7,200 seconds) | First party | Yes / No / Lax | Yes | No | Set by the Laravel application in inspected responses for /, /pricing and /login, or the corresponding configured domain. |
| hpScrollY (sessionStorage) | Academyship | academyship.com.au origin / not applicable | Restores the visitor’s scroll position on a homepage refresh. | The vertical scroll position as a number. | Preferences / functional | Browser-tab session | First party | Not applicable / Not applicable / Not applicable | No | No | Created by homepage code on /. |
| academyship_signup_source (sessionStorage) | Academyship | academyship.com.au origin / not applicable | Passes the selected sign-up entry point to the pricing page. | A non-sensitive source label for the selected sign-up path. It does not contain a password, authentication credential, TFN, payment-card detail or sign-up form content. | Preferences / functional | Browser-tab session; removed when the pricing page consumes it | First party | Not applicable / Not applicable / Not applicable | No | No | Created by the shared navigation where a User starts sign-up; consumed on /pricing-plan.html. |
| acsh.remember.staff, acsh.remember.student and acsh.remember.sub (localStorage) | Academyship | academyship.com.au origin / not applicable | Optionally remembers the username entered for the relevant staff, student or subscriber login form. | A versioned, expiry-bound username value and expiry timestamp. It does not contain a password, authentication credential, TFN or payment-card detail. | Preferences / functional | 30 days; cleared when the preference is deselected, invalid or expired | First party | Not applicable / Not applicable / Not applicable | No | No; created only after the User selects “Remember my username” | Created by the relevant form on /login after sign-in or multi-factor progression. |
Stripe hosted checkout
| Service | Provider | Purpose and information sent | Pages / when it runs | Cookie or storage identifier and duration | Party and category | Consent position |
|---|---|---|---|---|---|---|
| Stripe Checkout | Stripe | Provides hosted card checkout for subscription-payment processing. Payment-card details are entered on Stripe’s hosted service, not stored in Academyship browser storage. | Only when the visitor or Institution proceeds to Stripe’s hosted checkout. | No Stripe cookie or browser-storage key is set by the Academyship pages reviewed for this policy. Stripe controls browser processing on its hosted domain. | Third party / strictly necessary for the visitor-requested payment flow | No Academyship consent is used for the visitor-requested payment flow; Stripe’s own controls apply on its hosted service. |
Google services
| Service | Provider and domain | Purpose and information sent | Pages / when it runs | Cookie or storage identifier and duration | Party and category | Consent position |
|---|---|---|---|---|---|---|
| Google Fonts | Google LLC; fonts.googleapis.com and fonts.gstatic.com | Delivers the Bricolage Grotesque, Manrope and Urbanist web fonts on the production homepage and Inter on the production /login page. Loading a font causes the browser to make a standard request to Google that includes technical request information such as IP address and browser headers; it does not send sign-in form entries merely by loading the font. | Loads automatically when a visitor opens the homepage or /login. | No Google cookie or browser-storage key was identified in the inspected font-CSS response or Academyship page code. Google controls its own browser processing and cache behaviour on its domains. | Third party / functional presentation service | No Academyship cookie-preference control applies to this no-cookie font request. Google’s own terms and controls apply to its service. |
| Google Maps JavaScript API and Places Autocomplete | Google LLC; maps.googleapis.com | Provides address autocomplete on the production homepage. The script loads automatically and sends standard technical request information such as IP address and browser headers to Google. When a visitor uses address autocomplete, the typed address query and selected address are sent to Google to provide that function. | Loads automatically on the homepage; address-query processing occurs only when the visitor uses the address field. | No Academyship-controlled Google cookie or browser-storage key is set by the inspected page code. Google controls any cookie, browser-storage or cache behaviour on its domains; that behaviour requires a browser-session review before this policy can represent a complete inventory. | Third party / functional address service | No Academyship Google Maps preference control was identified in the inspected page code. Google’s own terms and controls apply to its service. |
#06Student and guardian portals
The inspected public responses establish the Laravel session and CSRF cookies above. They do not establish the complete post-authentication cookie inventory for student and guardian portals. The optional remembered-username localStorage items are described above; they are preference records, not authentication credentials. Academyship does not use Student Data for behavioural advertising or cross-site advertising profiles.
#07Analytics, advertising and pixels
No advertising pixel, advertising cookie, analytics tag, session-replay technology or support-chat widget was identified in the inspected production pages or their delivered code. Stripe Checkout is a payment service on Stripe’s hosted domain, not advertising or analytics technology. Academyship does not use Student Data for advertising. If Academyship adds non-essential technology for which consent is required, it will provide an effective preference mechanism before that technology loads.
#08Consent and preferences
Strictly necessary cookies are used to provide and secure the service requested by the User. The first-party functional storage listed above is created through the visitor’s use of the relevant preference, sign-up or checkout flow. No analytics, advertising or other consent-managed technology was identified in the inspected scope, so no Academyship cookie-preference centre is used for that scope. You can clear or block cookies and browser storage using your browser controls. If Academyship introduces non-essential cookies or technology requiring prior consent, it will provide controls to accept, reject, withdraw or change that consent before the technology loads.
#09Managing cookies
You can control cookies through your browser settings — for example, to block or delete cookies, or to be warned before cookies are set. Browser help pages explain how to manage cookies for your specific browser. You can also clear local storage and session storage through your browser. Google provides its own controls for Google Fonts and Google Maps, and Stripe provides its own controls for its hosted services.
#10Blocking essential cookies
If you block strictly necessary cookies, core features may not work — for example, you may be unable to sign in, stay signed in or submit secure forms. If you clear functional storage, the homepage scroll position, selected sign-up source or an optional remembered username may not be retained.
#11Data disclosures
Information processed through cookies and browser storage is handled as described in this policy and the Privacy Policy. Academyship does not sell this information. The Stripe Checkout disclosure above identifies the third-party payment service relevant to Academyship subscriptions.
#12Changes and review
We review this policy at least annually and whenever cookies, browser storage, analytics, advertising, chat, pixels, session replay or embedded third-party technology changes. We update the “Last updated” date when we change it. Prior versions can be requested from legal@academyship.com.au.
#13Change history
| Version | Date | Summary of changes |
|---|---|---|
| 2.0 | 12 September 2026 | Records the inspected production cookie and browser-storage inventory and the Stripe hosted-checkout position for subscription payments. |