Cookie policy
An inventory of what this website and our applications write to your device — every key named, with its lifetime and the legal footing it stands on.
Version 2.0 · in force from 15 August 2026 · supersedes version 1.0
1. What device storage is
A cookie is a small keyed value a site asks your browser to hold and hand back on the next request. Local storage and session storage do something similar without the automatic hand-back, and a pixel or script fetched from another domain can achieve the same tracking effect with no key written at all.
The law does not care which mechanism is used, and neither does this policy. What matters is whether something is placed on your device or read back from it, so everything below is documented as a store with named keys rather than as a category of technology.
2. The rule that applies
Two instruments govern this. Regulation 6 of the Privacy and Electronic Communications Regulations 2003 says storage may only be placed on or read from your equipment with your consent, unless it is strictly necessary to deliver a service you actively asked for. Where the stored value also identifies you, the UK GDPR applies on top and the privacy policy documents the handling.
The strictly necessary exemption is narrower than it is usually treated. It covers the thing that makes the page work — a session token, a security value, a load balancer's routing hint. It has never covered analytics, and measuring your visit is not made necessary by a company's wish to measure it.
3. Storage inventory: this website
The inventory for these pages is empty. No cookie is written by this site, no key is placed in local or session storage, and nothing is read back from your device between page views.
site_storage
- Keys
- None.
- Consent
- Not engaged, because Regulation 6 bites on storage and there is none.
- Analytics
- No measurement product is installed. There is no tag manager, no page-view beacon and no session recorder.
- Advertising
- No advertising or retargeting pixel is present, and no audience list is built from your visit.
- Embeds
- No video player, map, chat widget or social button is embedded, so no third party is handed an opportunity to write its own key.
This is a description of how the site is built rather than a promise about how it behaves. The pages are static files with one small script that toggles the mobile menu and draws a line under the header on scroll; that script keeps its state in memory and forgets it when you leave.
Our hosting platform writes ordinary server request logs, which is a record kept at their end rather than storage placed on your device. The access_log entity in section 11 of the privacy policy documents what those contain and how briefly they are held.
4. Outbound requests
One honest caveat belongs here, because a page that stores nothing can still cause your browser to talk to someone else.
The typefaces on this site are served by Google Fonts. Rendering a page therefore makes your browser request stylesheet and font files from fonts.googleapis.com and fonts.gstatic.com, and those requests disclose your network address, your browser's user-agent string and the page that referred them — the unavoidable content of any HTTP request. Google states that it does not set cookies on font requests and does not use them to build advertising profiles, and nothing in our markup asks it to do otherwise. We have no way to audit that from outside, so we tell you the request happens and let you weigh it.
font_request
- Hosts
fonts.googleapis.com,fonts.gstatic.com- Purpose
- Delivering the display, body and monospace typefaces the pages are set in.
- Written to device
- Nothing beyond the browser's ordinary HTTP cache for the font files themselves.
- Disclosed
- Network address, user-agent, referring page.
- Avoiding it
- A content blocker that stops third-party font hosts will prevent the request. The pages fall back to your system fonts and remain fully readable.
5. Storage inventory: our applications
Applications we publish under our own name do use device storage, because an application you sign in to cannot work without it.
app_storage
- Session key
- Holds the token proving you are signed in. Cleared when you sign out, and expiring on its own if you do not.
- Preference keys
- Remember choices such as theme or default view, so the application opens the way you left it. Persistent until you clear them or remove the application.
- Security keys
- Short-lived values that protect a form submission from being forged by another site.
- Consent
- All three are strictly necessary to a service you asked for by signing in, so Regulation 6 does not require a prompt.
- Absent
- No advertising identifier, no cross-app measurement, no third-party analytics library.
Where we have built an application published under a client's name, its storage is the client's to document and its own policy governs it.
6. Why nothing asks for consent
Consent is required for storage that is not strictly necessary. This site places no storage at all, so there is nothing for a banner to obtain permission for, and a dialogue asking you to accept an empty set would be theatre.
It is worth saying what a banner usually signals. Sites deploy them because they want to run measurement and advertising, and the banner exists to make that lawful. Choosing not to run either removes the need for the banner as a consequence rather than as a design flourish — the quieter site is the point, and the missing dialogue is the evidence.
7. What a change would look like
If we ever introduce anything beyond the strictly necessary, the order of events is fixed and stated here in advance so it can be held against us.
- Nothing would be placed on your device before you agreed to it. Loading a page would not count as agreement, nor would scrolling it.
- A prompt would offer refusal as plainly as acceptance, with no pre-ticked boxes and no design that makes declining the harder path.
- This inventory would be updated first, naming each new key, its purpose, its lifetime and the party setting it.
- Withdrawing consent would be as easy as granting it, and would take effect on the next request rather than at some later reconciliation.
- Refusal would leave the site fully usable, because none of the content here depends on being measured.
8. Clearing storage yourself
You do not need our co-operation to control any of this. Every current browser lets you inspect what a site has stored, delete it, and block future storage — usually under privacy or site settings, and for a single site through the padlock or information control in the address bar.
Blocking storage site by site is the setting worth knowing; blocking it everywhere will sign you out of most services you use, which is why we mention the narrower control first. Private browsing windows discard storage when closed, and a content blocker extension will additionally stop the font request described in section 4.
Nothing on this site will break if you block storage, since there is none to block. If you want to confirm any of this rather than take our word for it, open your browser's developer tools, look at the storage and network panels, and reload the page.
9. Do Not Track and Global Privacy Control
Do Not Track is a header a browser can send asking sites not to track. It was never given legal force in the UK and most sites ignore it. Ours has nothing to change in response, because the behaviour it asks for is the behaviour already in place.
Global Privacy Control is a newer signal with a clearer legal footing in some jurisdictions, and it expresses an objection to a site selling or sharing personal data. We sell nothing and share nothing for advertising, so the signal finds nothing to stop here either. Both are honoured by default rather than by configuration.
10. Revisions
This policy is versioned, and the version and effective date sit at the top of the page. Because the inventory above is the honest state of a static site, a revision here would mean something genuinely changed — a new key, a new outbound host, or a new application store to document.
Any change that introduces storage requiring consent will be published here before it is deployed, not afterwards.
11. Contact
Questions about anything above, or a report that the site is doing something this page does not describe, go to the same address as everything else. A discrepancy report is genuinely welcome: if you find a key we have not documented, we would rather hear it from you than not at all.
cookie_contact
- Company
- UR DATA LIMITED, registered in Northern Ireland, company number NI737745
- Related
- Privacy policy · Terms
You may also complain to the Information Commissioner's Office, at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF or on 0303 123 1113, which supervises the Privacy and Electronic Communications Regulations as well as data protection. We would appreciate the chance to put a problem right first, though nothing obliges you to give it to us.