GP-Hubs policies
Cookies
How GP-Hubs uses cookies and browser storage. Updated 1 October 2026.
Essential storage only
This website does not currently use advertising pixels or analytics cookies. It uses storage for services you request, such as signing in and continuing an assessment. We do not offer an “accept all” banner because there are no optional trackers to accept.
If optional analytics or marketing technologies are introduced, this policy and the required choices must be available before those technologies are enabled.
Sign-in cookies
When the Hospitalnote patient portal integration is enabled, __Host-gph_portal_access keeps you signed in for up to 30 minutes and __Host-gph_portal_refresh allows the session to be renewed for up to 90 days. Both are Secure, HttpOnly cookies using SameSite=Lax. They contain session credentials, not your questionnaire answers.
Sign out through your patient portal when you finish, especially on a shared device. Sign-out clears the portal cookies and saved assessment drafts in the current tab. Blocking essential sign-in cookies can prevent access to your patient account.
Assessment drafts in this browser
gphubs-treatment-consultation-v1 uses session storage to keep your assessment answers, contact and delivery details, date of birth, treatment preferences and consultation reference while you move through the requested service. You can resume in the same tab for one hour after the last save; expired drafts are discarded when you return. It is cleared after payment confirmation, when the flow completes or stops on a safety rule, or when you clear it yourself.
gphubs-reorder-v1 entries temporarily hold details needed to start a repeat assessment and are removed when used. Session storage normally lasts for the tab session; browser session restore can retain it. Clearing browser drafts does not delete records already submitted to the clinical service.
Use the “Clear saved assessment drafts” control below to remove these drafts in this tab. Other open tabs may have their own drafts. Avoid shared devices for private health information where possible.
Development previews
Local development previews may use a session cookie called gp-hubs-design-preview for a design you selected, and gphubs-mock-portal-session session storage for demo sign-in. These are development or demonstration features, not clinical records or a live patient identity check.
Payments and other websites
Stripe-hosted checkout opens as a separate payment page. Stripe may use its own storage for payment security and fraud prevention under its policies. GP-Hubs does not store your full card number or card security code. External register links and other linked sites have their own privacy and cookie practices.
Your controls
You can delete or block cookies and site data using your browser settings. This may sign you out or remove an unfinished assessment. To request access to or deletion of records already held by GP-Hubs, contact info@gphubs.com; clinical and legal record-keeping duties may limit deletion.
Clear drafts in this tab
This removes unfinished assessment answers and repeat-request drafts stored in this tab. Other open tabs may have their own drafts.