Cookies and measurement
Every cookie and similar technology this site sets, what it is for, and how to refuse everything that is not essential.
Choosing Essential only stops this browser sending any more data straight away. To have data that was already sent deleted, contact us at the address in the privacy notice and we will delete it.
A cookie is a small file a site stores in your browser. This page lists every one we set, what it is for, and how to refuse the ones you do not have to accept. Local storage works the same way for our purposes, so it is listed here too.
The rule we follow is the one in the Privacy and Electronic Communications Regulations: we may set what is strictly necessary to give you the service you asked for, and everything else needs your consent first. Refusing is the default. If you have not answered the banner, nothing optional is running.
Essential cookies (always set)
These make the site work. There is no way to turn them off and still have a working account, so we do not ask for consent for them.
- Session and authentication: set by us once you sign in. Keeps you signed in as you move between pages and stops somebody else using your session.
rt-accessholds a short-lived signed token and lasts an hour;rt-sessionlets us renew it and lasts a year, unless you sign out first or do not visit for 30 days. Neither is readable by the page's scripts. Beside them,rt-presentholds only the value 1, so the page can tell that somebody is signed in without learning who. - Last online:
rt-seen, a cookie, set only while you are signed in. It holds your account's internal id, and the time zone last sent with it, and lasts five minutes. While it is there we do not update the time you were last online, so that time is written at most once every five minutes rather than on every page. It is not readable by the page's scripts, is never sent to anybody but us, and records nothing about where you went. Why we keep the time you were last online is in the privacy notice. - Your time zone:
rt-tz, a cookie, set only while you are signed in. It holds the name of the time zone your device says it is in, such asAsia/Dubai, and nothing else, so that the times on your pages and in your emails are shown in your own local time. It is sent only to us, with the "last online" write above and only when it changes. Kept for a year. - Your region:
rt-region, a cookie. Decides which currency prices are shown and charged in, and whether a course page may describe training as a UK legal requirement. On your first visit it is set from the country your connection appears to come from, as reported by our host. If you have chosen a region on your profile, it is set from that choice instead when you sign in, so a new browser shows the same prices. After that it only changes when you pick a region in the footer or on your profile. Containsukoraeand nothing else. Kept for a year. - Your cookie choice:
rt.consent, stored in local storage. Remembers whether you accepted measurement, so we do not ask again on every page. Contains your answer, the version of this page you answered against, and the date. Nothing else. Kept until you clear it or change your mind. If you close the banner with the Escape key without answering,rt.consent.later, in session storage, stops it reappearing until you close the tab; nothing optional runs. - Resending a sign-in link:
rt-sign-in-sent, a cookie, set when you ask for a sign-in link. It holds the email address you typed, so that "Resend email" and the code field work without putting your address in the page address. Readable only by our server, sent only to the sign-in page, and kept for 15 minutes. - Checking a sign-in code:
rt-sign-in-sent-at, a cookie, set at the same time. It holds the time the sign-in email was sent and nothing else, so that the sign-in page can tell you a code has expired rather than that it is wrong. Readable only by our server, sent only to the sign-in page, and kept for an hour, as long as the code lasts. Both are removed when you sign in. - Checkout answers:
rt_checkout_choices, a cookie, set while you buy. It holds the answers you gave before the payment form (the tick to start your access, the email choices and which terms you agreed to), sealed so that it cannot be altered, and no name or email address. Readable only by our server, and kept for 30 minutes. - Payment: when you open the payment form, Stripe's script sets cookies needed to take the payment and to detect fraud. These are Stripe's, described in Stripe's own cookie notice, and they are set only on the payment step.
Preferences you set
These remember a choice you made on screen. They hold the choice and nothing else, and none of them is sent to anybody but us. They, and the region cookie above, are strictly necessary to give you the service you asked for in the way you asked for it, so we do not ask for consent for them.
- Sidebar width:
rt_app_rail, a cookie. Whether you collapsed the sidebar in your account. Kept for a year. - Interactive parts of a lesson:
rt-interactive, a cookie. Whether you switched the interactive parts of lessons off in favour of plain text. Our staff previewing a draft course have a separate one,rt-preview-interactive. Readable only by our server. Kept for a year. - Back-office navigation:
rt_admin_nav_collapsedandrt_admin_nav_closed, cookies, set only for our own staff. Kept for a year. - Catalogue layout:
rt.catalogue.shape, local storage. How many rows and cards the catalogue showed last time, so the page does not jump while it loads. Kept until you clear it. - Hints you closed:
rt:interactive-learning-explainedandrt:phone-hint-closed, local storage. That you have seen, or closed, a hint in a lesson, so it is not shown again. Kept until you clear them. - Lesson mode:
rt:learn-mode, local storage. Whether you last chose to follow a lesson as video or as audio. Kept until you clear it. - Captions:
rt:captions, local storage. Whether you turned captions off. Kept until you clear it. - Sharing your location:
rt:location-sharing, local storage. Your answer to whether you will share your location during assessments,yesorno, so you are not asked again on this browser. The answer itself is kept on your account; this copy only stops the question coming back. Kept until you clear it. - Checklist ticks: keys beginning
rt-ticks:, local storage. Which items you ticked on a checklist inside a lesson, so they are still ticked when you come back on the same browser. They are not part of your training record and are never sent to us. Kept until you clear them. - Time on a section: keys beginning
rt:on-screen:, local storage. How many seconds a section or a course's welcome has been on screen for you, so the wait before Next keeps what you have already done when you leave and come back on the same browser. One number a section and nothing else; never sent to us from here. Kept until you clear them. - Our staff's drafts: keys beginning
rt.workbench.draft., local storage, andrt:narration-popup, session storage, set only for our own staff while editing a course, so an unsaved edit survives a reload and the narration window reopens where they left it.
Time on a section (no cookie)
A section of a course counts how long its page is open in a visible tab, and tells our own server when you leave the section or press Next. Nothing is stored in your browser for it, and nothing is read from your device but whether the page is in view. It is kept with your progress through the course, as part of your training record, so that an appeal or a question about how an assessment was sat can be looked at against how the course was used. It is never sent to PostHog or anybody else, and it runs whatever you chose in the banner, because it is part of the record of the training rather than measurement of how the site is used. The privacy notice explains what is kept and for how long.
Optional cookies (only with your consent)
- Product analytics: PostHog, hosted in the European Union. Tells us which course pages people read, where in a lesson they stop, and whether the controls in the lesson player are being found. PostHog keeps an identifier in a cookie and in local storage, both named beginning
ph_. The cookie lasts a year. If your employer enrolled you and your behaviour is masked, nothing is written to your browser at all and the identifier lasts only as long as the page.
Nothing loads until you accept. If you decline, the analytics script is never fetched, so no request is made to a third party at all.
These limits are enforced in the code rather than left as a promise:
- We never send your assessment data. No answers, no scores, no pass or fail, no question references. Automatic event capture is switched off entirely on any assessment screen. Item statistics are accreditation evidence and are produced from our own database, where they can be reproduced years later.
- We never send your name or your email address. If you are signed in you are identified by an opaque user id and nothing else.
- We only record visits to the public site, and never what you type. With your consent, PostHog may record how a visit goes on our public pages and on the sign-in, checkout and sign-up pages, so we can see where people get stuck. Every box you type into is masked in the recording, and the console and network are not recorded. Lessons, assessments, your account and every screen showing someone's name are never recorded. If your employer enrolled you, nothing is recorded at all.
- We record errors so we can fix them. When a page breaks in your browser, and only if you accepted measurement, the error and where in our code it happened are sent to PostHog, with any email address or id removed from the message. Nothing is sent from an assessment screen. An error on our server is recorded whatever you chose here, because it is an error log rather than measurement. It carries your account's internal id if you were signed in, and never your name, email address or cookies. On an assessment screen, in a lesson or in Ask it is sent without the error's message.
If your employer enrolled you, there is a further limit: your behavioural data is masked unless your employer's data processing agreement expressly covers it. Masked means no identity is attached, nothing persists between visits, and events about your progress through a lesson are not sent at all.
What we do not use
- No advertising or retargeting cookies. We do not advertise to you and we do not let anyone else do it here.
- No social media tracking pixels, and no tracking image in our emails unless you ask for one: "Let rTraining know when I open emails", under Emails in your account, is off until you turn it on. With it on, each email carries a tiny image from our own site that tells us when it was opened. Nothing is stored in your browser and nothing goes to anyone else, and you can turn it off there at any time. That switch covers opens only. The links in our emails pass through a short address on our own site so that we can count which are followed; that sets no cookie and stores nothing in your browser, and the privacy notice explains it under "Links in our emails".
- No third-party embedded content. We do not embed videos, maps or posts from other sites.
- No fingerprinting to get round a refusal.
Changing your mind
Use the controls at the top of this page. The change takes effect straight away and applies to this browser.
Turning measurement off stops any further data being sent. It does not delete what was already sent, but you can ask us to delete that and we will. Write to training@rtriibe.com with "privacy" in the subject line.
You can also block or delete cookies in your browser settings. If you block the essential ones you will not be able to sign in.
Do Not Track and Global Privacy Control
We honour a Global Privacy Control signal from your browser as a refusal of optional cookies. While your browser sends it, measurement stays off, the banner does not ask, and a choice stored earlier in this browser is set aside. We do not act on the older Do Not Track header, because it was never given an agreed meaning. Refusing through the banner works in full.
More detail
- What data we hold and for how long: privacy notice.
- The events we record, one by one, and how the masking switch works: a separate document written for a data protection officer. Ask for it at training@rtriibe.com, with "privacy" in the subject line, and we will send it.
Last reviewed: 1 October 2026.