Privacy policy
Demonstration policy — last updated October 2026
Who we are
MediBasket.co.uk is a demonstration application. It is not a trading business and has no customers, so this policy exists to illustrate the shape of a real privacy notice rather than to describe live processing.
No payment data
This application never collects, transmits or stores payment card expiry dates or CVV codes. The checkout deliberately omits a CVV field entirely. Only the last four digits of the demo card value are recorded against an order so that the admin screens look realistic.
Cookies
Two first-party cookies are used: a session cookie (MBSESSID) that keeps you signed in and protects forms against cross-site request forgery, and a basket cookie (mb_cart) that holds a random basket identifier so an anonymous basket survives between visits. No analytics, advertising or third-party tracking cookies are used.
Your rights
In a production deployment you would have the usual UK GDPR rights — access, rectification, erasure, restriction, portability and objection. In this demo all data can be removed by emptying the database tables.
What this demo stores
| Data | Where it lives | Why |
|---|---|---|
| Demo account details | Site database | So sign-in and order history can be demonstrated |
| Passwords (hashed) | Site database | bcrypt hashes only — never plain text |
| Orders and addresses | Site database | So the order and admin journeys can be demonstrated |
| Basket identifier | Browser cookie | So an anonymous basket survives a page refresh |
| Card number / CVV | Nowhere — never stored | Not required, not transmitted, not stored |