Cookie & Storage Policy
Last updated: 6 October 2026. This page describes the current technical implementation rather than a generic list of tools.
1. What cookies and browser storage are
Cookies are small values a website or service can ask a browser to store and return with later requests. Browsers also provide storage mechanisms such as sessionStorage and localStorage. These technologies can be essential, functional, analytical or advertising-related depending on how they are used.
2. Current storage inventory
| Technology | Purpose | Status / duration |
|---|---|---|
| PHP session cookie | Supports session state used for contact-form CSRF protection and repeat-submission control. | Essential; duration depends on server/browser session settings. |
sessionStorage key csNotice | Remembers that the basic storage notice was acknowledged during the current browser session. | Functional; normally cleared when the browser session ends. |
| GA4 | Analytics | Not configured; no Measurement ID supplied. |
| GTM | Tag management | Not configured; no container ID supplied. |
| Cookiebot | Consent management | Not configured; no CBID supplied. |
| reCAPTCHA | Spam/security | Not configured; no site key supplied. |
| Google Maps | Map embed | Not configured and not used. |
| Affiliate cookies / pixels | Commercial attribution | No active affiliate links or partner tracking in this release. |
3. Essential storage
The contact form uses a PHP session to reduce cross-site request forgery and limit rapid repeated submissions. Disabling all cookies may prevent session-based form protection from working correctly.
4. sessionStorage
The site's simple notice uses sessionStorage rather than a persistent advertising or analytics cookie. The value records only that the notice was acknowledged in the current session; it is not designed to identify a person across websites or build a health profile.
5. Analytics
No GA4 ID has been provided. The supplied code does not load GA4 while the integration field is empty. If analytics is later activated, the site should first update this policy and implement the consent behaviour required for the actual deployment and audience.
6. Google Tag Manager
No GTM container is configured. GTM can load other technologies depending on how a container is configured; for that reason, it should not be added until the tags and consent logic are reviewed.
7. Advertising and affiliate tracking
The current release contains no advertising pixel, remarketing tag, affiliate redirect or partner cookie. Declaring an affiliate business model does not mean affiliate tracking is already active.
8. reCAPTCHA and spam protection
No reCAPTCHA key was supplied, so Google reCAPTCHA is not loaded. The contact form instead uses server-side validation, a CSRF token, a honeypot and a simple repeat-submission interval.
9. Maps and embeds
No Google Maps embed or other map integration is used. No verified operator street address was provided for this release.
10. Browser controls
Most browsers allow you to block or delete cookies and site data. Blocking the session cookie can affect the contact form. Clearing sessionStorage will simply cause the basic storage notice to appear again.
11. Consent and withdrawal
Because optional analytics and advertising technologies are not active in this release, the current notice is informational rather than a consent mechanism for those tools. If optional tracking is introduced, the site should implement an appropriate preference and withdrawal mechanism before loading non-essential technologies.
12. First-party and third-party technologies
The session cookie and sessionStorage notice are first-party to the website. No third-party analytics, advertising, CAPTCHA or map script is intentionally loaded in the supplied release.
13. Changes
This policy must be reviewed whenever analytics, affiliate tracking, advertising, maps, CAPTCHA, consent tooling or other browser-storage behaviour changes.
14. Contact
Questions about browser storage: [email protected].