Skip to content

Legal Cookies

Cookies

LAST UPDATED 2026-08-13 · NO BANNER · ALMOST NONE

The short version: the public marketing pages of this site do not run advertising cookies, do not run analytics cookies, and do not place anything that profiles you across sites. You will not see a cookie banner on these pages, because there is nothing to ask consent for. The only separate case is a personalised proposal preview page, which uses product analytics, and records a session replay of the visit, so we can see whether the proposal we sent was opened and read; that is covered in Analytics on proposal pages below.

What this site actually sets

Name Purpose Lifetime
(none on the marketing site) Our own code sets no cookies on the public marketing pages of this site, and at our last review of the live site (August 2026) no first-party cookies were observed being set on them. None
__cf_bm (Cloudflare) Bot-mitigation cookie our host Cloudflare can set when its bot protection is active, to distinguish humans from bots. It does not identify you. At our last review (August 2026) this cookie was not being set on this site; we list it because Cloudflare may start setting it without a change on our side, and if it does, this is what it is. 30 minutes (when set)
Cloudflare Turnstile (enquiry form) Spam and bot protection for our enquiry form, provided by Cloudflare, Inc. The form is not only on the contact page: it also sits on the home page, the pricing page, our service pages, our location pages, and other pages that carry it. On every page with the form, the Turnstile script loads from Cloudflare when the page loads, not only when you submit, and it may use cookies or similar local storage to confirm you are a real person. Strictly necessary for spam protection of the form, third-party; it does not track you across sites. More about Turnstile. Session / short-lived (managed by Cloudflare)
PostHog (proposal preview pages only) Product analytics on our unlisted, personalised proposal preview pages (under /proposals/), never on the public marketing pages. On most proposals PostHog runs entirely in memory and sets no cookie and no local storage; on some it sets a first-party cookie and uses local storage to keep the session together. Details in Analytics on proposal pages below. None (in-memory) or persistent (managed by PostHog), depending on the proposal

What we do not set

Analytics on the marketing pages

We run no analytics on the public marketing pages of this site - no Google Analytics, no cookieless alternative, nothing. The only traffic information we have is the standard, short-lived server logs our host (Cloudflare) keeps to protect and serve the site, which do not place cookies and are not used by us to profile you.

Analytics on proposal pages

Separately from the public marketing site, when we send a business a personalised website proposal, that proposal lives on its own unlisted preview page. To understand whether the proposal was opened and read, that preview page uses PostHog product analytics. We want to be straight about what that means:

If you have received a proposal from us and would rather we did not measure engagement, reply and tell us, or email [email protected], and we will switch it off for you and take the preview page down. The privacy notice explains the lawful basis and your rights in full.

Embedded media

Where a page embeds external media (a YouTube video, a Vimeo embed, a Tweet), that provider may set their own cookies when the embed loads. We avoid this by default on this site: embeds are used sparingly and, where present, use privacy-mode endpoints (e.g. youtube-nocookie.com). If you see an embed that does not, email [email protected] and we will swap it.

How to control cookies in your browser

You can block all cookies in your browser, including the strictly-necessary ones above, and this site keeps working. That includes the enquiry form: the spam check is best-effort, so if the Turnstile check cannot load or run, the form still submits, and our form handler leans on its other protections instead (a hidden honeypot field and a rate limit). On the spam-check side, a submission is only refused when a spam-check token is present but fails verification; the handler's other checks (required fields, the honeypot, the rate limit) still apply to every submission.

Changes to this page

If we ever add an analytics provider, an embedded chat widget, or anything else that places a cookie, this page updates first and (for clients) we email you. Cosmetic edits are not announced; the date at the top reflects the most recent revision.

Plain-English notice, written by a person.