Cookie Policy
Last updated: 9 September 2026
This site is deliberately light on tracking. It sets no advertising cookies, no cross-site tracking cookies, and it does not run Google Analytics or Google Tag Manager. This page lists every piece of storage the site uses and what each one is for.
Cookies and similar storage — the full list
UK law (the Privacy and Electronic Communications Regulations, read with UK GDPR) covers cookies and anything else stored on your device, including localStorage and sessionStorage. So this table lists all of it, not just cookies.
| Name | Type | Category | Purpose | Duration |
|---|---|---|---|---|
brg_beacon_sid |
localStorage (first-party) | Analytics | A random string that lets us count one visitor moving through several pages as one visit rather than several. It holds no name, email or account reference and is never matched against one. | Until you clear your browser storage, or until you reject or withdraw analytics consent, when it is removed |
_bsid |
localStorage (first-party) | Analytics | The same job as above for pages built on our shared site framework — a random session identifier so page views can be grouped into a visit. | Until you clear your browser storage, or until you reject or withdraw analytics consent, when it is removed |
brg_intro_hide |
localStorage (first-party) | Preference | Remembers that you closed the welcome panel in the partner portal, so it does not reappear every time. | Until you clear your browser storage |
sb-<project>-auth-token |
localStorage (first-party) | Strictly necessary | Keeps you signed in to the partner portal on this device. Without it the portal cannot tell who you are and shows you nothing. Only set once you sign in. | Until you sign out or the session expires |
__cf_bm, _cfuvid and similar |
Cookie (Cloudflare, our host) | Strictly necessary | Set by Cloudflare where bot-management or rate-limiting is engaged on a request, to tell automated traffic from human traffic. They carry no advertising identifier. | Up to 30 minutes (__cf_bm); session-lifetime (_cfuvid) |
attoh_consent_v1 | localStorage (first-party) | Strictly necessary | Remembers the choice you made in the cookie banner (accept, reject or your own settings), with the policy version and the date you chose, so we can honour that choice on every page without asking again. Written only when you make a choice, and it contains nothing else. | Kept until you clear your browser storage; after 12 months it lapses and you are asked again |
Storage in the “strictly necessary” category is exempt from the consent requirement, because the service you asked for cannot be delivered without it. The analytics and preference entries are first-party, are not shared with anyone, and are not used to build a profile of you or to follow you onto other websites.
How our analytics actually work
We built our own measurement rather than installing a third-party analytics product, precisely so that visiting this site does not hand your browsing to an advertising company.
On each page view a small first-party script sends us: the page path, the event type (page view, button click, form submission), the referring address if your browser provides one, any campaign parameters in the link you followed, your screen width, and the random session identifier described above. That is the complete list. We do not store your IP address alongside these events, we do not fingerprint your device, and none of it goes to an advertising network.
Third parties that see a request
| Third party | What it does | Storage it sets |
|---|---|---|
| Cloudflare | Hosts and delivers the site, and filters malicious traffic. Sees your IP address as part of serving the page. | The bot-management cookies listed above, when engaged. Cloudflare's own web analytics, where enabled, is cookieless. |
| Google Fonts | Serves the typefaces used across the site. Google's font servers receive your IP address when a font file is requested. | None. Google Fonts sets no cookies. |
| Supabase | Receives the analytics events and anything you submit through a form. | The portal sign-in token listed above, and only once you sign in. |
Advertising and cross-site tracking
There is none. No Google Analytics, no Google Tag Manager, no Meta pixel, no LinkedIn Insight tag, no advertising or remarketing cookies of any kind. If that ever changes we will update this page first and ask for your consent before setting anything that requires it.
Managing what is stored
You can clear or block cookies and site storage in your browser settings, usually under Privacy or Site settings, and you can delete what this site has stored without affecting other sites. Everything on this page except the sign-in token is optional: clearing it will not stop the site working, though the partner portal will ask you to sign in again.
Most browsers also offer a “do not track” or global privacy signal. Since we do not track you across sites in the first place, there is nothing here for it to switch off.
Questions about anything on this page? Email [email protected]. How we use the data these tools produce is set out in our privacy policy.