Cookie Policy
Cookie Policy
What cookies and similar technologies we use, what they do, and how you stay in control.
Last updated: September 2026
1. What this policy covers
This policy explains every cookie and similar technology (such as localStorage and sessionStorage, which store small pieces of data in your browser) that MediHealth Direct uses, what each one does, and how long it lasts. It should be read together with our Privacy Policy.
Cookies fall into three groups on this site: strictly necessary (always on, because the site cannot work without them), analytics (only with your permission), and marketing (advertising cookies only with your permission).
2. How consent works on this site
- The first time you visit, a banner asks for your choice. Under Advanced Consent Mode, Google Ads can send limited cookieless measurement signals before you decide or when Marketing is rejected; advertising cookies are only used with Marketing consent. Meta, Reddit, Omnisend and custom Google Tag Manager purchase/signup events remain consent-gated. All optional toggles start switched off.
- You can change or withdraw your choice at any time using the Cookie Preferences link in the footer of every page. Withdrawing consent stops the related trackers. It does not delete cookies that a provider set while an earlier consent was in place (other than the _gcl_aw cookie, which our site removes itself): those expire on the provider's own schedule, and you can remove them sooner in your browser's settings, as described under Managing or clearing cookies below.
- Your choice is stored for 12 months. After that, or if this policy changes materially, we ask you again.
- Rejecting is always as easy as accepting: Reject all appears alongside Accept all with equal prominence.
3. Strictly necessary cookies and storage
These are required for the site to function and are always active. They do not track you across other websites.
| Name | Type and provider | Purpose | Duration |
|---|---|---|---|
| mhd_session | Cookie, MediHealth Direct | Keeps you securely signed in to your account. Protected so scripts cannot read it. | 30 days |
| mhd_cookie_consent_v1 | localStorage, MediHealth Direct | Records the cookie choice you made so we do not ask on every visit. | 12 months |
| umami.disabled | localStorage, MediHealth Direct | A fixed on/off setting that keeps the page-statistics script added by our hosting provider (Replit, see Analytics below) switched off. It contains no information about you; it is one of the safeguards that stop that script running before you have chosen (the others need nothing stored on your device). | Persistent (re-set on every visit) |
4. Analytics cookies and storage (only with your consent)
Used to understand how visitors use the site so we can improve it. None of these are set or sent unless you switch Analytics on.
| Name | Type and provider | Purpose | Duration |
|---|---|---|---|
| mhd_analytics_session, mhd_analytics_landing | sessionStorage, MediHealth Direct | A random identifier and your landing page for our own anonymous measurement of pages visited and time on page. No IP address or device fingerprint is stored. | Until you close the browser tab |
| _ga and _ga_* cookies | Cookies, Google Analytics (via Google Tag Manager) | Distinguish visitors and sessions for aggregate site statistics. | Up to 2 years (set by Google) |
| Replit page statistics (no cookie or storage of its own) | Cookieless script, Replit (our hosting provider) | Counts pages visited, the site you arrived from, approximate country, browser and device type, and the same consent-gated milestones as our own measurement (for example starting a consultation). It sets nothing in your browser: visitors are counted from network (IP address) and browser details, and the count resets each calendar month. Page addresses are stripped of anything personal (order or consultation references, sign-in codes) before they are sent, page titles are not sent, only the domain of the site you arrived from is sent, and the staff area is never counted. | No storage on your device; visitor counting resets monthly |
5. Marketing cookies and advertising measurement
Used to measure our advertising campaigns and show you relevant information. Under Advanced Consent Mode, Google Ads can send limited cookieless measurement signals before you choose or when Marketing is rejected; these signals do not set advertising cookies. Advertising cookies are only used with Marketing consent. Meta, Reddit and Omnisend, and custom Google Tag Manager purchase/signup events, remain consent-gated. With Marketing consent, Reddit's base pixel sends a PageVisit on eligible homepage and medication pages. Reddit may receive the medication page address and title, which can reveal your treatment interest. Pages with query strings or fragments, and visits with unapproved referring pages, are excluded. Reddit tracking does not run on consultation, login, checkout, patient or admin pages. We do not configure Reddit conversions or advanced matching.
Existing approved conversion events contain only the minimal order ID, value and currency fields; no health or customer data is intentionally added.
| Name | Type and provider | Purpose | Duration |
|---|---|---|---|
| Google Ads measurement (no cookie before Marketing consent) | Cookieless signal and advertising cookies, Google Ads (Advanced Consent Mode) | A limited measurement signal can be sent before a choice or when Marketing is rejected. Advertising cookies are only used with Marketing consent. | No device storage before Marketing consent; cookie duration after consent is set by Google |
| _gcl_aw | First-party advertising cookie, MediHealth Direct / Google Ads | After Marketing consent, retain a Google ad click ID and timestamp so a later conversion can be attributed to that click. Our landing-page capture stores no page URL or treatment details and makes no network request. Removed by our site when Marketing consent is withdrawn. | 90 days from capture; the same click is not renewed by our capture code on reload |
| _fbp, _fbc | Cookies, Meta (Facebook) Pixel | Measure the effectiveness of our advertising on Meta platforms. | 3 months (set by Meta) |
| Reddit Pixel (provider-managed cookies, where permitted) | Pixel and advertising cookies, Reddit | Measures a PageVisit on eligible homepage and medication pages only with Marketing consent. Reddit may receive the medication page address and title, revealing treatment interest, as well as browser/network details, and may set or read advertising cookies. We do not add customer identifiers to these events. | Set by Reddit; manage or clear these cookies in your browser |
| omnisendSessionID, omnisendAnonymousID and related | Cookies, Omnisend | Recognise visits from our marketing emails so we can measure campaigns you have opted into. | Up to 12 months (set by Omnisend) |
6. Functional storage on your device
The app also keeps some information in your browser purely to make features you asked for work. This data stays on your device, is never used for tracking, and is never shared with third parties.
- Consultation and assessment drafts: your in-progress questionnaire answers (including health answers) are saved in your browser so you can finish later. They are only sent to us when you submit, and the draft is cleared after submission.
- Message drafts: an unsent message in the patient portal is kept until you send it or close the tab.
- Interface preferences: small settings such as a collapsed sidebar, image zoom level, and your recently used emoji.
7. Managing or clearing cookies
- Use the Cookie Preferences link in the footer to change your choice at any time.
- Your browser settings let you block or delete cookies and site data for any website. Blocking strictly necessary cookies will stop sign-in from working.
- For more about the third parties above, see the privacy pages published by Google, Meta, Reddit, Omnisend and Replit.
8. Changes and contact
If we change the cookies we use or how we use them, we will update this page and, where the change is material, ask for your consent again.
Questions about this policy or your data can be sent to hello@medihealthdirect.com. Our Privacy Policy explains your data protection rights in full.
This cookie policy is provided for general information only and does not constitute legal advice. Please contact us if you have any questions.