/ Legal

Cookie Policy

Last updated: 9 September 2026

This site is deliberately light on tracking. It sets no advertising cookies, no cross-site tracking cookies, and it does not run Google Analytics or Google Tag Manager. This page lists every piece of storage the site uses and what each one is for.

Cookies and similar storage — the full list

UK law (the Privacy and Electronic Communications Regulations, read with UK GDPR) covers cookies and anything else stored on your device, including localStorage and sessionStorage. So this table lists all of it, not just cookies.

NameTypeCategoryPurposeDuration
brg_beacon_sid localStorage (first-party) Analytics A random string that lets us count one visitor moving through several pages as one visit rather than several. It holds no name, email or account reference and is never matched against one. Until you clear your browser storage, or until you reject or withdraw analytics consent, when it is removed
_bsid localStorage (first-party) Analytics The same job as above for pages built on our shared site framework — a random session identifier so page views can be grouped into a visit. Until you clear your browser storage, or until you reject or withdraw analytics consent, when it is removed
brg_intro_hide localStorage (first-party) Preference Remembers that you closed the welcome panel in the partner portal, so it does not reappear every time. Until you clear your browser storage
sb-<project>-auth-token localStorage (first-party) Strictly necessary Keeps you signed in to the partner portal on this device. Without it the portal cannot tell who you are and shows you nothing. Only set once you sign in. Until you sign out or the session expires
__cf_bm, _cfuvid and similar Cookie (Cloudflare, our host) Strictly necessary Set by Cloudflare where bot-management or rate-limiting is engaged on a request, to tell automated traffic from human traffic. They carry no advertising identifier. Up to 30 minutes (__cf_bm); session-lifetime (_cfuvid)
attoh_consent_v1 localStorage (first-party) Strictly necessary Remembers the choice you made in the cookie banner (accept, reject or your own settings), with the policy version and the date you chose, so we can honour that choice on every page without asking again. Written only when you make a choice, and it contains nothing else. Kept until you clear your browser storage; after 12 months it lapses and you are asked again

Storage in the “strictly necessary” category is exempt from the consent requirement, because the service you asked for cannot be delivered without it. The analytics and preference entries are first-party, are not shared with anyone, and are not used to build a profile of you or to follow you onto other websites.

How our analytics actually work

We built our own measurement rather than installing a third-party analytics product, precisely so that visiting this site does not hand your browsing to an advertising company.

On each page view a small first-party script sends us: the page path, the event type (page view, button click, form submission), the referring address if your browser provides one, any campaign parameters in the link you followed, your screen width, and the random session identifier described above. That is the complete list. We do not store your IP address alongside these events, we do not fingerprint your device, and none of it goes to an advertising network.

Third parties that see a request

Third partyWhat it doesStorage it sets
CloudflareHosts and delivers the site, and filters malicious traffic. Sees your IP address as part of serving the page.The bot-management cookies listed above, when engaged. Cloudflare's own web analytics, where enabled, is cookieless.
Google FontsServes the typefaces used across the site. Google's font servers receive your IP address when a font file is requested.None. Google Fonts sets no cookies.
SupabaseReceives the analytics events and anything you submit through a form.The portal sign-in token listed above, and only once you sign in.

Advertising and cross-site tracking

There is none. No Google Analytics, no Google Tag Manager, no Meta pixel, no LinkedIn Insight tag, no advertising or remarketing cookies of any kind. If that ever changes we will update this page first and ask for your consent before setting anything that requires it.

Managing what is stored

You can clear or block cookies and site storage in your browser settings, usually under Privacy or Site settings, and you can delete what this site has stored without affecting other sites. Everything on this page except the sign-in token is optional: clearing it will not stop the site working, though the partner portal will ask you to sign in again.

Most browsers also offer a “do not track” or global privacy signal. Since we do not track you across sites in the first place, there is nothing here for it to switch off.

Questions about anything on this page? Email [email protected]. How we use the data these tools produce is set out in our privacy policy.