Version 1.0 · in force from 2026-09-06
Effective date: 5 September 2026
Who we are
CELCO GROUNDWORKS & CONSTRUCTION LIMITED, trading as CostTakeoff, operates the CostTakeoff service at costtakeoff.com.
- Company number: 823396 (Ireland)
- Registered office: 40 Bay Meadows Avenue, Dublin 15, D15 Y66T, Ireland
- Contact: info@costtakeoff.com
The short answer
We use no analytics, no advertising and no tracking of any kind. Nothing on our website or in the application follows you, builds a profile of you, or reports what you look at to anybody.
Everything listed below is there because the Service cannot work without it: to sign you in and keep you signed in, to protect the sign-in service against abuse, to hold the work you have in progress on your own device, and to remember the way you have set your own screen up. Under regulation 5(5) of S.I. No. 336 of 2011, storage of this kind is exempt from the consent requirement, because it is strictly necessary to provide a service you have explicitly asked for. So there is no cookie banner, and you are not asked to agree to anything. This policy exists to tell you what is there and why, which is a separate duty and one we owe you whether consent is required or not.
If that changes — if we ever add something that is not strictly necessary — we will ask you first, and this policy will say so before it happens.
What "cookie" means here
A cookie is a small file a website stores in your browser. Browsers also offer two other stores that work the same way for this purpose: local storage, which survives until it is cleared, and session storage, which is emptied when you close the tab. This policy covers all three, because the law is concerned with what is stored on your device rather than with which mechanism stores it.
Everything below was read from a real browser session on costtakeoff.com, signed out and signed in.
What is set before you sign in
| Name | Set by | What it is for | Where | How long |
|---|---|---|---|---|
__client | Clerk, our sign-in provider, on clerk.costtakeoff.com | Identifies your browser to the sign-in service, so a session can be created and resumed | Cookie | 400 days |
__client_uat, __client_uat_… | Clerk | Records that a signed-in session exists, so the page knows whether to try to resume one. Each holds a single digit | Cookie | 400 days |
__cf_bm | Cloudflare, which sits in front of the sign-in service, on clerk.costtakeoff.com and — once the sign-in screen has loaded the icons it displays — on img.clerk.com | Tells automated traffic from real visitors, so the sign-in service can be protected from abuse | Cookie | 30 minutes |
_cfuvid | Cloudflare | Separates one visitor's requests from another's for rate limiting | Cookie | Until you close the browser |
__clerk_environment | Clerk | A cached copy of the sign-in service's own configuration, so every page does not have to fetch it again | Local storage | Until cleared |
ct.chain.step | Us | Which step of the illustration on the home page you had reached, so it resumes rather than restarting. A single number | Local storage | Until cleared |
clerk.costtakeoff.com is a name on our own domain that our sign-in provider operates for us. Your browser treats it as first party; the service behind it is Clerk's.
What is added when you sign in
| Name | Set by | What it is for | Where | How long |
|---|---|---|---|---|
__session, __session_… | Clerk | The token your browser sends with each request to prove who you are. The token inside is short-lived and is replaced continually | Cookie | Up to 1 year |
__refresh_… | Clerk | Obtains a fresh session token when the current one expires | Cookie | Up to 1 year |
clerk_active_context | Clerk | Which account is the active one | Cookie | Until you close the browser |
costtakeoff-storage | Us | Your own work in progress — the projects, drawings and measurements you have open — held on your device so the screen survives a reload and a brief loss of connection | Local storage | Until cleared |
costtakeoff-outbox | Us | Changes you have made that have not yet reached our server, queued on your device so nothing is lost if the connection drops | IndexedDB | Until the changes are saved |
costtakeoff-tree-sort, costtakeoff-tree-view | Us | How you chose to sort and view the drawing list | Local storage | Until cleared |
boq.… (a group of entries, added as you use the screen) | Us | How you left the bill-of-quantities screen and its export panel: which sections are open, which template and columns you chose. Each is a small setting; how many exist depends on how much of the screen you have used | Local storage | Until cleared |
boqDetachSeen:… | Us | That you have already seen a one-time hint on a particular job | Local storage | Until cleared |
costtakeoff-v2-migrated | Us | That a one-time upgrade of locally held work has already run, so it is not offered again | Local storage | Until cleared |
ct-chat-open, ct-chat-opened-at | Us | Whether the support panel is open, so it stays open as you move between screens | Session storage | Until you close the tab |
ct-perf-paint | Us | A diagnostic switch, set only if you add a diagnostic parameter to the address yourself | Session storage | Until you close the tab |
Two more are set only at the moment they are needed and expire in an hour:
| Name | Set by | What it is for | Where | How long |
|---|---|---|---|---|
ct_invite | Us | Carries an invitation from the link you followed through the sign-up steps, so the invitation is not lost while you create your account | Cookie | 1 hour |
ct_legal_consent | Us | Carries the confirmation you gave on the sign-up screen through to your account record. It is signed, so it cannot be forged | Cookie | 1 hour |
None of the entries we set holds an advertising identifier, and none is shared with anybody. The ones that hold your work — costtakeoff-storage and costtakeoff-outbox — hold your own content and stay on your device until it reaches our server.
Two things that look like storage and are not
The application uses a broadcast channel named costtakeoff-mutations and a browser lock named costtakeoff-outbox-flusher so that two open tabs do not save the same change twice. Neither stores anything: both exist only while the tabs are open and disappear with them. They are named here because you may see them in a browser's developer tools and wonder what they are.
When you buy: the payment page
Payments are handled by Paddle.com Market Limited, our Merchant of Record. When you open a checkout, the payment window is Paddle's own, served from Paddle's domain, and what it stores is set by Paddle and its payment processor rather than by us. In a real checkout window we observed:
- a Cloudflare bot-management cookie on
paddle.com, lasting 30 minutes; - a cookie named
monm.stripe.com, set by Stripe, Paddle's card processor, used for fraud prevention; - storage inside Paddle's own window used by Paddle for the state of that checkout, by a translation service to hold your language and a count of visits, and by an error-reporting service.
Some of that is not strictly necessary in the sense described above — a visit count and error reporting are not needed to take a payment. We are telling you because you should know, not because we have a choice about it: it is set by Paddle, in Paddle's own window, on Paddle's own domains, under Paddle's own cookie and privacy policies, at the moment you choose to open a checkout. We cannot set it, read it or switch it off, and Paddle is the seller of record for that payment, answering for its own window. Paddle's policies are linked at the foot of it, and that is the place to look before you buy.
Nothing of Paddle's is set anywhere on costtakeoff.com unless you open a checkout, and nothing we set changes when you do.
What we do not do
- We run no analytics product. We do not know which pages you visit, in what order, or for how long.
- We run no advertising and place no advertising or social-media tags.
- We do not sell, rent or share anything about you, and there is nothing here to sell.
- No third party sets a cookie on our pages except Cloudflare's two named above, which protect the sign-in service and are set on our sign-in provider's own hostnames.
Controlling them
Every browser lets you see, block and delete cookies and clear local and session storage; the settings are usually under Privacy. Because everything we set is strictly necessary, blocking or clearing it does not give you a quieter version of the Service — it signs you out, and it discards work held on your device that has not yet reached our server. Clearing storage while you have unsaved work is the one case where you can lose something.
Your browser's private or incognito mode works normally with the Service and clears everything when you close the window.
Changes to this policy
If we add anything that is not strictly necessary, we will ask for your consent before it is set and this policy will be updated first. Otherwise we update this policy when what we set changes, and the effective date above shows when the current version came into force.
Contact
Questions about this policy: info@costtakeoff.com