Cookie Policy
1. About this Cookie Policy
1.1 This Cookie Policy ("Policy") explains how Evryone Ltd, a company registered in England and Wales, whose registered office is at [Registered office address] (the "Company", "Frame", "we", "us", "our"), uses cookies and similar technologies on the Frame.plus website and within the Frame.plus web application and platform (together, the "Service" or "Platform").
1.2 Frame.plus is the trading name, product and brand of Evryone Ltd. The Service is an AI marketing operating system that allows small businesses, founders, creators, agencies and multi-business owners to plan, generate, schedule, publish and report on their marketing.
1.3 This Policy should be read together with our Privacy Policy, which explains in fuller detail how we collect, use, share and protect personal data, the lawful bases on which we rely, your data subject rights, and our international data transfer safeguards. Where this Policy refers to processing of personal data, the Privacy Policy governs that processing. Defined terms used but not defined in this Policy have the meaning given to them in the Privacy Policy.
1.4 This Policy is provided to help you understand:
- (a) what cookies and similar technologies are;
- (b) the legal basis on which we set them, under the Privacy and Electronic Communications (EC Directive) Regulations 2003 ("PECR") and the UK General Data Protection Regulation ("UK GDPR") as supplemented by the Data Protection Act 2018 ("DPA 2018");
- (c) which categories of cookies and similar technologies we use, and why;
- (d) which cookies are first-party and which are set by third parties (including our sub-processors);
- (e) how you can manage, accept, refuse or withdraw your consent; and
- (f) how long cookies remain on your device.
1.5 We are the data controller in respect of personal data collected through cookies and similar technologies set on or through the Service. Our supervisory authority is the UK Information Commissioner's Office (the "ICO"). Evryone Ltd, trading as Frame.plus, is registered with the ICO as a data protection fee payer (registration reference ZC182890).
2. The legal framework: PECR and the UK GDPR
2.1 The use of cookies and similar technologies in the United Kingdom is governed principally by two pieces of law working together:
- (a) PECR governs the act of storing information on, or gaining access to information stored on, your device (for example, reading or writing a cookie). PECR requires us to provide you with clear and comprehensive information about the technologies we use and, except for those that are strictly necessary, to obtain your consent before they are set.
- (b) The UK GDPR (and the DPA 2018) governs what happens to any personal data we subsequently collect or process by means of those technologies — for example, the lawful basis for that processing, your rights, and how we keep the data secure.
2.2 Essential / strictly necessary cookies — no consent required. PECR provides an exemption from the consent requirement for cookies and similar technologies that are strictly necessary to provide a service that you have explicitly requested. We may set these without your consent because, without them, the Service (or a specific feature you have asked for, such as logging in or maintaining a secure session) would not function. We still tell you about them in this Policy.
2.3 Non-essential cookies — prior consent required. All other cookies and similar technologies (including functional/preference cookies and analytics/performance cookies) are non-essential. We will not set non-essential cookies on your device until you have given your prior, freely given, specific, informed and unambiguous consent by a clear affirmative action, in line with the UK GDPR standard of consent. We obtain this consent through our cookie consent banner (the "Cookie Banner") when you first visit the Service, and we record your choices.
2.4 You are not required to accept non-essential cookies, and refusing them will not prevent you from accessing the core Service (although certain conveniences and analytics may be affected — see section 8). Refusing consent is as easy as giving it: the Cookie Banner allows you to reject non-essential cookies with the same prominence as accepting them.
2.5 You can change your mind at any time. Consent, once given, can be withdrawn just as easily as it was given (see section 9). Withdrawing consent does not affect the lawfulness of any processing carried out before withdrawal.
2.6 EU/EEA visitors. If you access the Service from the European Economic Area, the EU GDPR (Regulation (EU) 2016/679) and the equivalent national implementations of the ePrivacy Directive may also apply to the use of cookies. We apply a consistent consent-based approach to non-essential cookies for all visitors.
3. What are cookies and similar technologies?
3.1 Cookies. A cookie is a small text file that a website or web application places on your computer, smartphone, tablet or other internet-enabled device when you visit it. Cookies allow the Service to recognise your device, remember information about your visit (such as your sign-in session, your preferences and your settings), keep your session secure, and understand how the Service is being used so that we can improve it.
3.2 Cookies can be categorised in several ways:
- (a) By who sets them:
- First-party cookies are set by Frame.plus (the domain you are visiting).
- Third-party cookies are set by a domain other than Frame.plus — for example, by one of our sub-processors or service providers whose technology is embedded in or called by the Service (such as a payment page hosted by our payment processor).
- (b) By how long they last:
- Session cookies are temporary and are deleted automatically when you close your browser or when your session ends.
- Persistent cookies remain on your device for a defined period (or until you delete them) and are reactivated each time you visit.
3.3 Similar technologies. In addition to cookies, we (and our service providers) may use other technologies that store information on, or access information stored on, your device, and which are treated in the same way as cookies under PECR. These include:
- (a) Local storage and session storage (often called "Web Storage" or "HTML5 storage") — used by the web application to store data such as session tokens, authentication state, your active business selection and interface preferences locally in your browser. Local storage typically persists until cleared; session storage is cleared when the tab or browser is closed.
- (b) IndexedDB and other in-browser databases — used, where applicable, to cache application data so that the Platform loads and performs efficiently.
- (c) Software Development Kits (SDKs) and tags — code provided by third-party providers that may read or write identifiers.
- (d) Pixels, web beacons and tracking technologies in emails — small transparent images or tracking links embedded in emails. The use of these in marketing and outreach email is addressed in our Privacy Policy and in our Outreach and email documentation, and is governed by PECR as it relates to electronic communications. This Policy focuses on technologies used on the Service itself.
3.4 References in this Policy to "cookies" should be read as including all of the similar technologies described above, except where the context requires otherwise.
4. How we obtain your consent
4.1 When you first visit the Service, you will be presented with our Cookie Banner. Strictly necessary cookies will already be active because they are required for the Service to work. No non-essential cookies will be set until you have made a choice.
4.2 The Cookie Banner allows you to:
- (a) Accept all non-essential cookies;
- (b) Reject all non-essential cookies (essential cookies remain); or
- (c) Manage preferences / choose which categories of non-essential cookies you wish to allow, on a granular, category-by-category basis.
4.3 We record your consent choices (for example, which categories you accepted or rejected, and the date and version of the Cookie Banner shown to you) so that we can honour your preferences, demonstrate compliance, and avoid asking you again unnecessarily. The cookie used to remember your choice is itself a strictly necessary cookie (see the consent-record row in the table at section 6).
4.4 We will re-seek your consent periodically and whenever there is a material change to the cookies we use, the purposes for which they are used, or the third parties that set them.
5. Categories of cookies we use
We group the cookies and similar technologies we use into the following categories. Section 6 lists the technologies currently used on the marketing site and the Frame web application.
5.1 Strictly necessary cookies (always on — no consent required). These cookies are essential for the Service to function and for you to move around it and use its features. They include cookies that:
- keep you authenticated and signed in after you complete passwordless email sign-in (one-time codes), by storing a signed session token;
- maintain the security and integrity of your session (for example, protecting against cross-site request forgery and detecting session tampering);
- enable load balancing and routing, so that requests are directed to the correct server and the Service remains available and performant; and
- record your cookie consent preferences, so that we respect your choices.
Because these cookies are strictly necessary to provide a service you have explicitly requested, we set them without consent. If you block them via your browser, parts of the Service will not work.
5.2 Functional / live-chat technologies (non-essential — consent required). If you enable this category, we load the Coffey support-chat widget. The widget uses persistent browser storage to recognise the device and retain its configuration so that the chat feature can work across page visits. If you do not consent, the rest of the Service remains available and you can still contact support by email or through the support page.
5.3 Usage analytics (non-essential — consent required). If you enable this category, Frame records first-party website usage events such as page views, navigation clicks, advertising campaign parameters and whether a visitor later starts or completes sign-up. For advertising links, we retain the click-ID type and a one-way hash rather than storing the raw click ID. We create a random first-party visitor identifier only after consent. We do not use advertising profiles, session replay, device fingerprinting or analytics before consent.
5.4 Marketing measurement technologies (non-essential — consent required). If you enable this category, we load the Pinterest and TikTok tags to measure visits and selected calls to action associated with Frame's advertising campaigns. The tags may create or access cookies and local storage and communicate with Pinterest or TikTok. We do not pass an email address or other enhanced-match identifier to either tag. Neither tag loads and no advertising-measurement event is sent unless you consent to this category.
6. Cookie table — specific cookies and similar technologies
6.1 The table below lists the cookies and similar technologies currently used, by category. Providers may change their technology over time, so we review and update this table when our implementation changes.
6.2 Strictly necessary cookies (no consent required)
| Name / item | Provider / type | Purpose | Duration |
|---|---|---|---|
frame_cookie_consent | frame.plus (first-party localStorage) | Records the categories you accepted or rejected, the consent version and the date of your choice so that we can honour it. | 6 months, then we ask again; earlier if our purposes or providers materially change |
frame.auth (app session token) | app.frame.plus (first-party; browser localStorage, not a cookie) | Keeps you signed in to the Frame app after passwordless email sign-in by storing your signed session token in your browser's localStorage; used to authorise your requests to the Platform. | Persists until you sign out or the token expires |
| Security / service integrity | app.frame.plus (first-party; strictly-necessary technology) | Maintains the security and integrity of the Service (for example, protecting the authenticated session and detecting tampering). | For the duration of your session |
The marketing site uses local storage for the consent record. This storage is strictly necessary to remember and demonstrate your privacy choice.
6.3 Functional / live-chat technologies (consent required)
| Name / item | Provider / type | Purpose | Duration |
|---|---|---|---|
coffey-device:<workspace> | Coffey / frame.plus first-party localStorage, created by the Coffey widget | Provides a device identifier required to establish and resume the requested support-chat session. | Persistent until you clear site data |
coffey-widget-config:<workspace> | Coffey / frame.plus first-party localStorage, created by the Coffey widget | Caches the chat widget's display and workspace configuration. | Persistent until you clear site data |
| Embedded chat session | Coffey (api.coffey.cx and app.coffey.cx) / third-party script and iframe | Provides the live-chat feature after you enable functional technologies. | Session and provider-controlled storage; see Coffey's applicable privacy information |
6.4 Usage analytics (consent required)
| Name / item | Provider / type | Purpose | Duration |
|---|---|---|---|
frame_website_visitor_id | frame.plus (first-party localStorage) | Links consented page views and clicks to one anonymous visitor record and lets us attribute an app sign-up that follows an outbound link. | Up to 180 days; deleted when you clear site data or withdraw analytics consent |
| Website analytics event | Frame server (first-party HTTPS request) | Stores consented page, click, referral and sign-up funnel events, including the request IP address and country code supplied by the hosting edge. | 180 days, then automatically deleted or aggregated |
6.5 Marketing measurement technologies (consent required)
| Name / item | Provider / type | Purpose | Duration |
|---|---|---|---|
Pinterest tag (s.pinimg.com/ct/core.js) | Pinterest / third-party marketing-measurement technology | Measures page visits associated with Frame's Pinterest campaigns after marketing consent. It may use identifiers including _pin_unauth, _epik and related Pinterest storage. | Pinterest states that tag cookies may remain for up to 1 year; you can withdraw consent sooner at any time |
TikTok Pixel (analytics.tiktok.com/i18n/pixel/events.js) | TikTok / third-party marketing-measurement technology | Measures consented page visits and selected calls to action associated with Frame's TikTok campaigns. It may use TikTok advertising identifiers and related browser storage. | Controlled by TikTok's applicable retention settings; you can withdraw consent sooner at any time |
6.6 AI sub-processors that power product features (for example OpenAI, Anthropic, DeepSeek, Seedance and Pexels) operate server-side via our backend and do not set cookies in your browser through ordinary use of the marketing website. Our use of those providers is described in the Privacy Policy.
7. First-party vs third-party cookies, and our sub-processors
7.1 The strictly necessary consent record and application session storage are first-party. The optional Coffey chat widget and Pinterest and TikTok tags are third-party technologies and are loaded only for the category you enable.
7.2 A limited number of third-party technologies may be invoked by our service providers and sub-processors, most notably:
- (a) Coffey, when you consent to and use the support-chat widget;
- (b) Pinterest and TikTok, when you consent to marketing measurement;
- (c) Stripe, on payment and checkout pages, for secure payment processing, subscription billing and fraud prevention. Stripe is an independent controller for the payment data it processes;
- (d) Amazon Web Services (AWS), for content delivery, performance and security of the web application; and
- (e) Zernio, where social-account-connection, publishing/scheduling or ads-connection components are loaded.
7.3 The infrastructure that hosts the Service and stores data (including Amazon Web Services — primarily the AWS Europe (London) region, eu-west-2, United Kingdom, our database provider MongoDB Atlas, and our queue/cache provider Upstash) operates server-side. These providers may set strictly necessary technical cookies (for example, AWS load-balancer cookies as noted in section 6.2) but are not used to track you across other websites.
7.4 Third-party providers process information collected via their cookies in accordance with their own privacy and cookie notices, over which we do not have full control. We encourage you to review the relevant third party's notice. For details of all our sub-processors, the purposes for which we use them, and the international transfer safeguards that apply (including UK International Data Transfer Agreements (IDTAs) / EU Standard Contractual Clauses with the UK Addendum, and the UK Extension to the EU–US Data Privacy Framework where applicable), please see our Privacy Policy and our published sub-processor list.
8. The effect of disabling or refusing cookies
8.1 You are free to refuse or disable non-essential cookies. However, please note the following effects:
- (a) Strictly necessary cookies. If you block these (for example, via your browser settings), you will not be able to sign in, your session may not be maintained, security protections may fail, and core parts of the Service may not function at all. We cannot provide a working, secure Platform without them.
- (b) Functional / live-chat technologies. If you refuse or block these, the Coffey chat widget will not load. The rest of the Service remains available, and you can still contact support by email or through the support page.
- (c) Usage analytics. If refused, we do not create the visitor identifier or send website analytics events. The site and sign-up remain available, but visits and conversion attribution will not appear in Frame Admin.
- (d) Marketing measurement technologies. If you refuse or block these, Pinterest and TikTok campaign visits and selected calls to action will not be measured through their tags. This does not affect your access to the Service.
8.2 Disabling cookies through your browser is a blunt instrument and may also affect other websites you use. Using our Cookie Banner (section 9) is the most precise way to manage cookies for the Service.
9. How to manage or withdraw your consent
9.1 Through our Cookie Banner / preferences centre. You can change your cookie choices at any time:
- (a) by re-opening the Cookie Banner or cookie preferences centre, accessible via the "Cookie settings" / "Manage cookies" link in the website footer and in your account settings; and
- (b) by toggling individual categories of non-essential cookies on or off. Your updated choices take effect immediately for cookies set going forward.
9.2 Withdrawing consent. You may withdraw your consent to non-essential cookies at any time, and doing so is as easy as giving it. When you withdraw consent for a category, we stop loading the relevant third-party technology. We also send the available consent-withdrawal commands to active advertising tags; other storage already placed on your device may remain until it expires or you delete it via your browser (see section 9.3).
9.3 Through your browser. Most browsers allow you to view, manage, block and delete cookies, and to clear local storage. The method varies by browser. Useful links include:
- Google Chrome: Google Chrome
- Apple Safari: Safari
- Mozilla Firefox: Mozilla Firefox
- Microsoft Edge: Microsoft Edge
For mobile browsers, please refer to your device's settings and your browser's help pages. You can usually also set your browser to notify you when a cookie is being set, or to refuse third-party cookies.
9.4 "Do Not Track" and Global Privacy Control. Some browsers offer a "Do Not Track" (DNT) signal or a Global Privacy Control (GPC) signal. Because there is no consistent industry or legal standard for how these should be interpreted in the UK, we do not currently respond to DNT signals. We do, however, honour a recognised GPC signal as a request to reject any non-essential cookies, should any be introduced in future. We will update this Policy if our position changes.
9.5 Withdrawing consent or deleting cookies does not affect the lawfulness of processing carried out before you did so.
10. Retention and expiry of cookies
10.1 Cookies remain on your device for the durations set out in the table at section 6:
- (a) Session cookies are deleted automatically when you close your browser or end your session.
- (b) Persistent cookies remain until the expiry period stated, or until you delete them.
10.2 We set expiry periods proportionate to the purpose of each cookie, applying the principle of data minimisation. We do not retain cookie-derived personal data for longer than necessary for the purposes described in this Policy and our Privacy Policy.
10.3 Your cookie consent record is retained for 6 months so that we can honour your preferences and demonstrate compliance, after which you will be re-prompted via the Cookie Banner.
10.4 Personal data collected via analytics cookies is retained and then deleted or aggregated in accordance with the retention periods set out in our Privacy Policy.
11. Personal data, your rights and security
11.1 Some information collected through cookies (for example, online identifiers, IP address and usage data) may constitute personal data under the UK GDPR. Where it does, we process it as a controller in accordance with our Privacy Policy, which sets out the lawful bases on which we rely:
- (a) strictly necessary cookies and certain security functions — relying on our legitimate interests (Article 6(1)(f)) in providing a secure, functioning Service and, for the act of storage/access, the PECR strictly-necessary exemption; and
- (b) non-essential functional, usage-analytics and marketing-measurement technologies — relying on your consent (Article 6(1)(a) UK GDPR and PECR).
11.2 You have rights over personal data we hold about you, including the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent. You can exercise these rights, and find full details of how we safeguard your data and handle international transfers, in our Privacy Policy.
11.3 We protect data collected via cookies using appropriate technical and organisational measures, including encryption in transit (TLS 1.2+), signed session tokens, role-based access control, and the wider security measures described in our Privacy Policy.
12. Changes to this Cookie Policy
12.1 We may update this Policy from time to time to reflect changes in the cookies and similar technologies we use, in the third parties that set them, in our practices, or in legal or regulatory requirements.
12.2 When we make changes, we will update the "Last updated" date and the version number at the top of this Policy. Where the changes are material (for example, the introduction of a new category of non-essential cookie or a new third-party cookie), we will take appropriate steps to bring them to your attention and, where required, re-seek your consent via the Cookie Banner before setting the relevant cookies.
12.3 We encourage you to review this Policy periodically to stay informed about our use of cookies.
13. How to contact us
If you have any questions, comments or requests about this Cookie Policy or our use of cookies, please contact us:
- Privacy & data protection: privacy@frame.plus
- Data subject requests / Data Protection Lead: dpo@frame.plus (or the Data Protection Lead)
- General / legal: legal@frame.plus
- Post: Evryone Ltd (t/a Frame.plus), [Registered office address]
Company details: Evryone Ltd, a company registered in England and Wales, registered office [Registered office address]. ICO registration reference number ZC182890.
Complaints to the regulator. You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) if you are unhappy with how we have handled your personal data or used cookies:
- Website: ico.org.uk
- Helpline: 0303 123 1113
We would, however, appreciate the opportunity to address your concerns before you approach the ICO, so please contact us first.
This Cookie Policy is governed by the laws of England and Wales. It should be read together with the Frame.plus Privacy Policy and, where applicable, the Frame.plus Terms of Service.