Skip to main content
Legal

Cookie Policy

Effective 9 October 2026 · Last updated 9 October 2026 · Version 2.1 · ACADEMYSHIP PTY LTD · ACN 698 283 448 · ABN 89 698 283 448

#01Summary

Academyship uses cookies and browser storage to operate and secure its website and application, maintain sessions, protect requests and retain limited functional state. Academyship also measures visits to its public website using its own first-party script. Academyship does not use Student Data for advertising. Section 05 sets out the cookies, storage and external browser services identified in Academyship's review of its public pages, and the website measurement added since. Section 06 explains the kinds of browser storage the application and portals use or may use.

Academyship's review of its public pages, published in September 2026, identified no analytics technology, advertising pixel, session-replay technology or support-chat widget in the inspected production homepage, pricing page and login page or the scripts those pages loaded. Since that review, Academyship has added its own first-party measurement of visits to its public website pages, other than its sign-in pages. It is described in section 05. Academyship has not added an advertising pixel, third-party analytics service, session-replay technology or support-chat widget to its website. Stripe’s hosted checkout is relevant only when a visitor or Institution proceeds with subscription payment.

Academyship provides a privacy preference mechanism, Privacy Choices, reachable at any time from the website footer. Choosing to use Privacy Choices records one limited first-party preference item, academyship_cookie_consent, described in section 05. Privacy Choices controls the optional technology that has been connected to it. Academyship's first-party website measurement is not currently connected to it, so choosing “Essential only” does not switch that measurement off; section 05 explains how to exclude your browser from it. If Academyship introduces third-party analytics or any marketing technology on its website, that technology will remain disabled until you permit it through Privacy Choices. Providing this control is not a statement that Academyship has begun behavioural advertising or cross-site advertising profiling; it has not.

Scope: the main table in section 05 records Academyship's review of the production responses for /, /pricing and /login, and the browser code delivered for those pages, as published in Version 2.0 of this policy on 12 September 2026. Public pages change over time, so it is a dated record rather than a live scan. The website measurement items in section 05 are those created by Academyship's measurement script. Section 06 describes the application and portals by kind of storage; it is not a complete key-by-key inventory of every module. We review this policy whenever cookies, browser storage, analytics, advertising, chat, pixels, session replay or embedded third-party technology changes.

#02What cookies and similar technologies are

Cookies are small text files stored on your device by your browser. "Similar technologies" include browser local storage and session storage, and comparable mechanisms. They can be "first party" (set by Academyship) or "third party" (set by another provider). They can last only for your session, or persist for a set period. We use the general term "cookies" in this policy to refer to these technologies.

#03Where this policy applies

This policy applies to our marketing website at academyship.com.au and to the ACADEMYSHIP web application and portals. The inventory below distinguishes cookies set by the Laravel application from browser storage created by the inspected public-page code.

The application and portals run on Academyship tenant domains and on any Institution-branded domain that Academyship operates for an Institution. Browser storage belongs to the domain that created it, so storage on a tenant or Institution-branded domain is separate from storage on academyship.com.au. This policy does not govern pages hosted by other providers, such as Stripe's hosted checkout or a calendar service you choose to add an event to. Their own policies apply there.

#04Categories we use

  • Strictly necessary — currently used. Required to operate the service, maintain a web session and protect requests. These cannot be switched off without affecting core functionality. In the application, this can include storage needed to complete a step you have started, such as passing details between the steps of a multi-step form.
  • Preferences / functional — first-party browser storage used for homepage scroll restoration, sign-up source attribution, an optional remembered username and the record of your privacy selection. In the application and portals, this also includes interface preferences, a selected campus or branch, and display preferences and drafts (section 06).
  • Analytics / performance — Academyship's own first-party measurement of visits to its public website, described in section 05. No third-party analytics service was identified. This measurement is not currently offered as a choice in Privacy Choices; the opt-out in section 05 is the control for it.
  • Advertising / marketing — none was identified in the inspected production pages or their delivered code, and none has been added since. We do not use Student Data for advertising. This category is not currently offered as a choice, because there is nothing in it to switch on or off.

The optional categories above are the only categories that would ever be presented for consent. Privacy Choices shows an optional category with its own control when technology connected to Privacy Choices is in use in that category, and that technology stays disabled until you permit it. Where no connected technology is in use in a category, the category is not shown, and no consent is sought or recorded for it. Academyship's first-party website measurement is not connected to Privacy Choices, as explained above. Strictly necessary and functional items are not presented as optional choices, because the service cannot be provided without the first and because the second are created only through a step you take yourself, such as selecting “Remember my username”.

#05Website cookies and storage

The table below records the first-party cookies and storage observed in Academyship's review of production responses and delivered page code, as published in Version 2.0 of this policy on 12 September 2026. Website measurement items are listed separately below the table. Cookie attributes are shown as sent in the inspected unauthenticated production responses. “Not applicable” means the item is browser storage rather than a cookie.

Where Academyship supports an Institution-controlled or custom domain, necessary first-party application cookies may be set as host-only cookies against that configured Institution-branded or Academyship tenant domain. The cookie names, purposes and attributes below otherwise remain the same.

No IndexedDB use, analytics or advertising storage, chat-widget storage, CDN cookie, load-balancer cookie or security-provider cookie was identified in that scope. Academyship's website does not store passwords, authentication credentials, TFNs or full payment-card details in browser storage. The optional remembered-username items below are created only when a User selects that preference.

Cookies and browser storage recorded in the review of the Academyship website and sign-in published in September 2026
Name Provider Domain / path Purpose Information stored Category Duration First or third party Secure / HttpOnly / SameSite Essential? Consent required? Where created / pages
laravel_sessionAcademyshipHost-only academyship.com.au, or a configured Institution-branded or Academyship tenant domain / /Maintains the server-side web session, including an authenticated session after sign-in.A session identifier only; the session data is held server-side.Strictly necessary2 hours (Max-Age 7,200 seconds)First partyYes / Yes / LaxYesNoSet by the Laravel application on Institution-branded and Academyship tenant domains. The public marketing pages (/, /pricing) and the sign-in page (/login) set no Laravel cookies: the sign-in broker behind /auth-api is stateless by design, and the authenticated session is created on your institution's own Academyship domain when the sign-in hand-off completes.
XSRF-TOKENAcademyshipHost-only academyship.com.au, or a configured Institution-branded or Academyship tenant domain / /Supports cross-site-request-forgery protection for protected requests.A CSRF token.Strictly necessary2 hours (Max-Age 7,200 seconds)First partyYes / No / LaxYesNoSet by the Laravel application on Institution-branded and Academyship tenant domains. The public marketing pages (/, /pricing) and the sign-in page (/login) set no Laravel cookies: the sign-in broker behind /auth-api is stateless by design, and the authenticated session is created on your institution's own Academyship domain when the sign-in hand-off completes.
hpScrollY (sessionStorage)Academyshipacademyship.com.au origin / not applicableRestores the visitor’s scroll position on a homepage refresh.The vertical scroll position as a number.Preferences / functionalBrowser-tab sessionFirst partyNot applicable / Not applicable / Not applicableNoNoCreated by homepage code on /.
academyship_signup_source (sessionStorage)Academyshipacademyship.com.au origin / not applicablePasses the selected sign-up entry point to the pricing page.A non-sensitive source label for the selected sign-up path. It does not contain a password, authentication credential, TFN, payment-card detail or sign-up form content.Preferences / functionalBrowser-tab session; removed when the pricing page consumes itFirst partyNot applicable / Not applicable / Not applicableNoNoCreated by the shared navigation where a User starts sign-up; consumed on /pricing-plan.html.
academyship_signup_ref_v1 (sessionStorage)Academyshipacademyship.com.au origin / not applicableLets the pricing page show live progress while a new workspace is being set up.An opaque signup reference number issued by the Academyship platform. It does not contain a password, authentication credential, TFN, payment-card detail or sign-up form content.Preferences / functionalBrowser-tab session; removed when setup completes or failsFirst partyNot applicable / Not applicable / Not applicableNoNoCreated after a sign-up is submitted on /pricing-plan.html; used to poll setup status.
academyship_utm_v1 (sessionStorage)Academyshipacademyship.com.au origin / not applicableRecords which campaign link brought the visitor, so a sign-up or enquiry can be attributed to it.The utm_source, utm_medium and utm_campaign values from the address bar, if present. It does not contain a password, authentication credential, TFN, payment-card detail or sign-up form content.Preferences / functionalBrowser-tab sessionFirst partyNot applicable / Not applicable / Not applicableNoNoCreated when a page is opened from a campaign link; attached to sign-up and enquiry submissions.
acsh.remember.staff, acsh.remember.student and acsh.remember.sub (localStorage)Academyshipacademyship.com.au origin / not applicableOptionally remembers the username entered for the relevant staff, student or subscriber login form.A versioned, expiry-bound username value and expiry timestamp. It does not contain a password, authentication credential, TFN or payment-card detail.Preferences / functional30 days; cleared when the preference is deselected, invalid or expiredFirst partyNot applicable / Not applicable / Not applicableNoNo; created only after the User selects “Remember my username”Created by the relevant form on /login after sign-in or multi-factor progression.
academyship_cookie_consentAcademyshipacademyship.com.au / /Records your privacy selection so the Privacy Choices panel is not shown again on every page, and so any optional technology stays disabled unless you have permitted it.Four values only: a schema version number, the date and time the selection was made, and a true/false value for the analytics and marketing categories. It contains no name, email address, IP address, account information, student information, form submission, USI, authentication information or marketing profile information.Preferences / functional182 days (Max-Age 15,724,800 seconds) from the date the selection is madeFirst partyYes on HTTPS / No — it is read by the website’s own privacy script, so it is not HttpOnly / LaxNo, but it is the record of a privacy choice and is not used for any other purposeNo — it is created only after you make a selection, and only records that selectionCreated by script/academyship-consent.js on the Academyship website when you choose an option in Privacy Choices. Where a browser cannot store cookies for the page, for example during local file-based development, the same record is held in first-party localStorage instead.

Website measurement

Academyship measures visits to its public website pages, other than its sign-in pages, with its own first-party script. The script records which pages are viewed, where a visit came from (including campaign labels in the link), general device and browser characteristics such as screen size, language and time zone, use of the links and buttons Academyship has chosen to measure, downloads and links followed to other websites, how far a page is scrolled, active time on a page, page loading performance and technical errors, and whether a form was started, failed or completed. It never records what you type into a form. It sends this information only to Academyship's own measurement service on the same website. That service also receives your IP address and browser details with each request, as any website does, and may use them to estimate approximate location and device type and to filter out automated traffic. The information is used to understand and improve the website. It is not used for advertising and is not shared with advertisers or third-party analytics providers.

The measurement script creates the items below. The identifiers are random values; they are not derived from your name, account, IP address or device.

Cookies and browser storage created by Academyship's website measurement script
NameTypePurposeInformation storedDurationCategoryParty and attributes
acsh_vidCookie, host-only for the website domain, path /Recognises a returning visitor.A random visitor identifier.365 days, renewed on each visit to a measured pageAnalytics / performanceFirst party; Secure on HTTPS; not HttpOnly; SameSite Lax
acsh.bidlocalStorageRecognises the same browser across visits.A random browser identifier.Until you clear site dataAnalytics / performanceFirst party
acsh.sid and acsh.sid.seenlocalStorageGroups page views into a visit.A random visit identifier and the time of the last activity.Until you clear site data; a new visit identifier is used after 30 minutes without activityAnalytics / performanceFirst party
Items beginning acsh.q. (one set per open tab)localStorageHolds measurement events until they are sent, so they are not lost when a page closes.The measurement events described above. No form field values.Removed once the events are sentAnalytics / performanceFirst party
acsh.handoffsessionStoragePasses unsent events to the next page opened in the same tab.A reference to the queued events and a time.Removed when the next page reads itAnalytics / performanceFirst party
academyship_analytics_opt_outlocalStorage and cookieRecords that you have excluded this browser from measurement.The value 1.Cookie: 10 years. localStorage: until you clear site data or opt back in.Preferences / functionalFirst party; created only if you opt out

How to exclude your browser. Open any public Academyship website page with ?analytics_opt_out=1 added to the end of the address, for example https://academyship.com.au/?analytics_opt_out=1. Your browser then stores the opt-out record above, and from then on the measurement script stops before it creates identifiers or sends anything. To be measured again, use ?analytics_opt_out=0. The opt-out applies only to the browser and device you use it on. It does not delete identifiers already stored. To remove those, clear site data for academyship.com.au and then set the opt-out again, because clearing site data also removes the opt-out record. Privacy Choices does not currently switch this measurement on or off.

Stripe hosted checkout

External payment service relevant to Academyship subscriptions
ServiceProviderPurpose and information sentPages / when it runsCookie or storage identifier and durationParty and categoryConsent position
Stripe CheckoutStripeProvides hosted card checkout for subscription-payment processing. Payment-card details are entered on Stripe’s hosted service, not stored in Academyship browser storage.Only when the visitor or Institution proceeds to Stripe’s hosted checkout.No Stripe cookie or browser-storage key is set by the Academyship pages reviewed for this policy. Stripe controls browser processing on its hosted domain.Third party / strictly necessary for the visitor-requested payment flowNo Academyship consent is used for the visitor-requested payment flow; Stripe’s own controls apply on its hosted service.

Google services

External Google services observed on Academyship public pages in the review published in September 2026
ServiceProvider and domainPurpose and information sentPages / when it runsCookie or storage identifier and durationParty and categoryConsent position
Google FontsGoogle LLC; fonts.googleapis.com and fonts.gstatic.comDelivers the Bricolage Grotesque, Manrope and Urbanist web fonts on the production homepage and Inter on the production /login page. Loading a font causes the browser to make a standard request to Google that includes technical request information such as IP address and browser headers; it does not send sign-in form entries merely by loading the font.Loads automatically when a visitor opens the homepage or /login.No Google cookie or browser-storage key was identified in the inspected font-CSS response or Academyship page code. Google controls its own browser processing and cache behaviour on its domains.Third party / functional presentation serviceNo Academyship cookie-preference control applies to this no-cookie font request. Google’s own terms and controls apply to its service.
Google Maps JavaScript API and Places AutocompleteGoogle LLC; maps.googleapis.comProvides address autocomplete on the production homepage. The script loads automatically and sends standard technical request information such as IP address and browser headers to Google. When a visitor uses address autocomplete, the typed address query and selected address are sent to Google to provide that function.Loads automatically on the homepage; address-query processing occurs only when the visitor uses the address field.No Academyship-controlled Google cookie or browser-storage key is set by the inspected page code. Google controls any cookie, browser-storage or cache behaviour on its domains; that behaviour requires a browser-session review before this policy can represent a complete inventory.Third party / functional address serviceNo Academyship Google Maps preference control was identified in the inspected page code. Google’s own terms and controls apply to its service.

Other public pages

Some other public pages, such as video and documentation pages, load fonts from Google Fonts or video images from YouTube, which is a Google service. Loading them sends standard technical request information, such as your IP address and browser headers, to Google. If a page offers an embedded YouTube video and you play it, YouTube may set its own cookies or browser storage under Google's terms and controls.

#06Application and portals

The inspected public responses establish the Laravel session and CSRF cookies above. They do not establish the complete post-authentication cookie inventory for the application or for student and guardian portals. The optional remembered-username localStorage items are described above; they are preference records, not authentication credentials. Academyship does not use Student Data for behavioural advertising or cross-site advertising profiles.

Kinds of browser storage the application uses or may use

Depending on the modules an Institution uses, the application and portals use, or may use, the kinds of first-party browser storage below. This section describes kinds of storage rather than every individual item, and what a module stores can change between versions of the application.

Kinds of first-party browser storage in the Academyship application and portals
KindExamples of where it is usedWhat it may containHow long it usually lastsCategory
Interface preferencesTables and lists in modules such as library, homework, behaviour, front office and fees; shared layouts.Your choice of table columns and views, filters, collapsed or expanded panels, the tab you last used, theme, text size and sidebar settings. Some preferences can include the names of the views or labels you use.Usually local storage, which remains until you reset the preference or clear site data. Some are kept in session storage for the current tab.Preferences / functional
Selected campus or branchModules that work across more than one campus or branch, such as the canteen.The campus or branch you selected and whether to remember it.Local storage, until you change it or clear site data.Preferences / functional
Multi-step form handoffsBooking and event-registration flows.Details you entered on one step that the next step needs. This can briefly include personal details, such as a parent's or student's email address.Session storage, until the next step reads it. If you leave the flow early, it can stay in that tab's session storage until the tab's session ends.Strictly necessary for the step you started
Payment-screen display preferences and draftsFee and payment screens.Display choices and recently used options on those screens, and drafts of details you have entered so that they are not lost if the page reloads.Session storage or local storage, depending on the screen.Preferences / functional
Temporary screen stateDocument and signing screens, and other screens that reload.Whether a page has just reloaded and similar short-lived display state.Session storage for the current tab.Strictly necessary or functional

Session storage, local storage and shared devices

  • Session storage belongs to one browser tab. It is normally cleared when the tab's session ends, but browsers that restore tabs or a previous session can restore it, and duplicating a tab can copy it.
  • Local storage stays in the browser until it is cleared. Signing out ends your session on Academyship's servers, but it may not remove every preference item from the browser.
  • On a shared or public device, use a private or guest window where possible, do not select “Remember my username”, sign out, close all tabs for the site and clear site data for the Academyship and Institution domains you used. Anyone who uses the same browser profile may be able to see items left in browser storage.

Tenant and Institution-branded domains

The Privacy Choices panel runs on the Academyship website. It may not appear on, or govern browser storage used by, the application on an Academyship tenant domain or an Institution-branded domain, or on pages hosted by other providers. Strictly necessary and functional storage in the application is not presented as an optional choice. Your Institution may also give you its own information about the services it uses.

Calendar and payment pages you choose to open

Calendars. Some booking and event screens offer “add to calendar” options for Google Calendar, Outlook or Office 365, Yahoo Calendar, or a downloadable calendar file. These run only when you choose them. Choosing one sends the details of that appointment or event, such as its title, time, location, description or meeting link, to the calendar service you chose, or saves them in a file on your device. The calendar provider's own cookies and policies apply on its pages. A calendar link is not a connection to your calendar account, and the calendar provider is not an Academyship subprocessor.

Payments. When you choose to pay on a page hosted by Stripe, Stripe's own cookies, browser storage and policies apply on its domain. Academyship does not set or control cookies on calendar or payment providers' domains and cannot remove storage those providers create.

#07Analytics, advertising and pixels

No advertising pixel, advertising cookie, analytics tag, session-replay technology or support-chat widget was identified in the inspected production pages or their delivered code in the review published in September 2026. Since then, Academyship has added its own first-party website measurement, described in section 05. It is not an advertising technology, and the information it collects is not shared with advertisers or third-party analytics providers. Academyship has not added an advertising pixel, third-party analytics service, session-replay technology or support-chat widget. Stripe Checkout is a payment service on Stripe’s hosted domain, not advertising or analytics technology. Academyship does not use Student Data for advertising. If Academyship adds non-essential technology for which consent is required, it will provide an effective preference mechanism before that technology loads.

#08Consent and preferences

Strictly necessary cookies are used to provide and secure the service requested by the User, and are not optional. The first-party functional storage listed above is created through the visitor’s use of the relevant preference, sign-up or checkout flow, and is not presented as a consent choice for that reason.

Academyship operates its own privacy preference mechanism, Privacy Choices, on its website. It offers:

  • Essential only — no optional technology connected to Privacy Choices is permitted. This is also the position that applies before you make any selection at all.
  • Accept all — every optional category currently in use and connected to Privacy Choices is permitted.
  • Customise — each optional category currently in use and connected to Privacy Choices is listed with its own control, set to off until you turn it on, so you can permit some and not others. Strictly necessary technology is shown as “Always active” and has no control.

Privacy Choices does not currently switch Academyship's first-party website measurement on or off. Use the opt-out in section 05 for that measurement.

Optional technology that is connected to Privacy Choices does not run, load or set anything in your browser unless the corresponding category has been permitted. Declining, or making no selection, leaves it disabled. Your selection is remembered in the academyship_cookie_consent item described in section 05 so that you are not asked again on every page, and you can return to Privacy Choices at any time from the website footer to review, change or withdraw it.

Withdrawing permission stops the relevant technology from being activated again and removes the first-party browser storage that Academyship is able to remove. It cannot undo a request that was already made to a third party while permission was in force; where a third-party service was loaded before you withdrew, reloading the page ensures it is not loaded again.

At present no technology is connected to the analytics or marketing categories of Privacy Choices, so Privacy Choices does not present an optional category for either. It explains the essential and functional technology the website relies on and links to this policy. Privacy Choices runs on the Academyship website; it may not appear on, or govern technology used on, Academyship tenant domains, Institution-branded domains or pages hosted by other providers (section 06). Where Academyship introduces a materially new purpose or a new optional service, the recorded schema version changes and your preference is requested again rather than carried over, so that a past choice is never treated as permission for something you were not asked about.

#09Managing cookies

Use the permanent Privacy Choices link in the Academyship website footer to review or change your privacy selection at any time. It reopens the same panel with your current selections shown, on whichever page you are already on; you do not need to navigate elsewhere to change your settings.

You can also control cookies through your browser settings — for example, to block or delete cookies, or to be warned before cookies are set. Browser help pages explain how to manage cookies for your specific browser. You can also clear local storage and session storage through your browser; clearing site data removes the academyship_cookie_consent record, and Privacy Choices will then ask for your selection again. Clearing site data also removes the website measurement identifiers and any measurement opt-out record described in section 05. To exclude your browser from website measurement, use the opt-out in section 05. Application storage on a tenant or Institution-branded domain is cleared by clearing site data for that domain (section 06). Google provides its own controls for Google Fonts, Google Maps and YouTube, Stripe provides its own controls for its hosted services, and calendar providers provide their own controls on their services.

#10Blocking essential cookies

If you block strictly necessary cookies, core features may not work — for example, you may be unable to sign in, stay signed in or submit secure forms. If you clear functional storage, the homepage scroll position, selected sign-up source or an optional remembered username may not be retained. In the application, clearing storage can reset your display preferences and selected campus or branch, and can lose an unfinished multi-step form or payment-screen draft.

#11Data disclosures

Information processed through cookies and browser storage is handled as described in this policy and the Privacy Policy. Academyship does not sell this information. The Stripe Checkout disclosure above identifies the third-party payment service relevant to Academyship subscriptions.

Requests are not the same as cookies. Whenever your browser loads a page, font, script, image or video from a server, that server receives standard technical information, such as your IP address, browser type and the page that made the request, whether or not any cookie is set. That is true of Academyship's own servers, including its website measurement service, and of Google Fonts, Google Maps, YouTube, Stripe and calendar providers when your browser contacts them. A statement in this policy that no cookie or storage item was identified for a service does not mean that no information is disclosed to it. Academyship's handling of the technical information its own servers receive is described in the Privacy Policy.

#12Changes and review

We review this policy at least annually and whenever cookies, browser storage, analytics, advertising, chat, pixels, session replay or embedded third-party technology changes. We update the “Last updated” date when we change it. Prior versions can be requested from legal@academyship.com.au.

#13Change history

Version history of this Cookie Policy
VersionDateSummary of changes
2.19 October 2026Records the introduction of the Academyship Privacy Choices preference mechanism and the academyship_cookie_consent first-party preference record, and updates the Consent and preferences and Managing cookies sections accordingly. Discloses Academyship's first-party website measurement, the cookie and storage items it creates and how to exclude a browser from it, and states that Privacy Choices does not currently switch that measurement on or off; the earlier statements that no analytics was in use, and that any later optional analytics would stay disabled until permitted, are replaced by this disclosure, and the commitment is kept for third-party analytics and marketing technology. Restates the review of public pages published in September 2026 as a dated record and notes other public pages that load Google Fonts or YouTube content. Replaces the student and guardian portals section with an Application and portals section describing the kinds of browser storage the application uses or may use, session and local storage on shared devices, tenant and Institution-branded domains, and user-initiated calendar and payment pages. Explains that requests to other services disclose technical information such as IP address even where no cookie is set. No advertising, session-replay or support-chat technology was added.
2.012 September 2026Records the inspected production cookie and browser-storage inventory and the Stripe hosted-checkout position for subscription payments.

#14Related documents