Cookie policy

Last updated 26 August 2026

What a cookie policy is for

UK law says that storing anything on your device, or reading anything off it, needs your consent — unless it’s strictly necessary for something you asked for. It applies to more than cookies: local storage, session storage and tracking pixels all count. So this page covers everything we put in your browser, not just the things technically called cookies.

What we store today

What needs your consent

These load only if you accept. Reject and they are never requested.

  • Google Analytics 4Tells us which pages get read, how people arrive, and where they give up — in aggregate. We use it to see what's working on the site, not to identify anyone.
    • _gaTells one browser from another, so a repeat visit isn't counted as a new person. Expires: 2 years.
    • _ga_P1KBP43WRLKeeps session state for this particular property. Expires: 2 years.
  • HubSpotOur CRM. It recognises a returning visitor, so when someone fills the form we can see which pages they read on the way there rather than starting the conversation cold.
    • hubspotutkIdentifies a browser across visits, and is sent with a form submission so the enquiry joins up with that browsing history. Expires: 6 months.
    • __hstcThe main tracking cookie — first visit, previous visit and current visit. Expires: 6 months.
    • __hsscTracks the current session, to tell one visit from the next. Expires: 30 minutes.
    • __hssrcRecords whether this is a new browser session. Expires: When you close the tab.

One thing that isn’t a cookie

If you run the scorecard, your answers and your result are kept in your browser’s session storage while you’re on the page. That’s what lets the result survive a reload and travel with your request if you go on to ask for a diagnostic.

It’s strictly necessary for the thing you asked for, so it doesn’t need consent. It never leaves your device on its own, it isn’t used to recognise you, and it’s gone when you close the tab. Closing the tab without submitting the form means we never see it at all.

Booking a call

The booking page is our own, at /book— there’s no third-party calendar embedded in the site. Because booking writes to real calendars, the moment you pick a time and start booking, the page runs a Cloudflareanti-bot check, which may set a Cloudflare security cookie. Until then — while you’re just looking at times — your browser never contacts Cloudflare. That cookie is strictly necessary — it’s there only to tell people from bots on a page that would otherwise be a target, not to track you — so it doesn’t need consent. Prefer not to involve Cloudflare at all? Email us instead and it’s never loaded.

If we add anything else

The list above is everything we load, and none of it loads unless you accept. If we ever add anything else — an advertising pixel, say — it goes in that list, it stays off until you accept, and rejecting stays one click, in the same place and the same size as accepting. We won’t start tracking you and mention it afterwards.

Your choice

You haven't been asked yet, or your previous answer has expired. The bar will ask next time you load a page.

Blocking cookies yourself

Every browser lets you block or delete cookies and site data, and you don’t need our permission to use it. If you’ve accepted analytics, blocking cookies in your browser will stop Google Analytics and HubSpot recognising a repeat visit — nothing else on the site will break. Blocking session storage will stop the scorecard remembering your result across a reload.

More detail

What we do with the details you actually send us — your name, email and message, and your scorecard result if you attach one — is in the privacy policy.