Skip to content
venuebooker
Legal

Cookie Policy

Effective date: 15 August 2026 · Last updated: 15 August 2026 · Version 3.0 · VENUEBOOKER SOLUTIONS LTD

1. The short answer

No measurement cookie and no advertising cookie is placed on venuebooker.co. The only cookies that may appear are strictly-necessary security cookies belonging to Cloudflare, who host and defend the site. Strictly-necessary cookies are carved out of the consent requirement in the Privacy and Electronic Communications Regulations 2003, which is the reason no banner meets you at the door. A banner would be offering you a choice we are not actually holding back from you.

What follows explains those cookies, sets out what the rules require, says what we would commit to before introducing anything else, and shows you how to take the whole matter into your own hands. Read it beside our Privacy Policy.

2. What a cookie is, and what counts as one

A cookie is a short piece of text that a site puts into your browser’s keeping, to be handed back on the next request, so that something can carry over from one page to the next — a security check already passed, say, or a preference you set a minute ago.

Three properties decide how a cookie is treated:

  • Whose it is — placed by the site in the address bar, or by another domain whose content the page pulls in.
  • How long it lasts — discarded when the browser closes, or held for a stated period.
  • Whether it is essential — genuinely required to deliver something you asked for, or there for another reason such as measurement or advertising. Only the first of those escapes the consent rule.

The law treats a family of other techniques the same way, because they equally write to or read from your device:

  • Local storage and session storage — areas a browser sets aside for a site, holding data without shipping it along with every request.
  • IndexedDB and cache storage — larger stores that let a web application keep working when the connection drops.
  • Pixels and beacons — a tiny image or a fragment of script whose only job is to register that a page or an email was opened.
  • Identifiers inside apps — the equivalents used on a phone rather than in a browser, dealt with at section 7.

Where this page says “cookie”, read it as covering all of the above unless we draw a distinction.

3. The rules that govern this

Two bodies of rules apply in the United Kingdom, and they work in tandem.

The Privacy and Electronic Communications (EC Directive) Regulations 2003. Regulation 6 provides that writing information to a user’s device, or reading what is already there, calls for clear information about what is going on plus that user’s consent. Two situations fall outside it: where the storage or access exists purely to carry a communication over a network, and where it is strictly necessary for a service the user has expressly asked for. Security cookies that keep a site up and defended land in the second of those. Measurement cookies do not, however privacy-minded their design, and nothing serving advertising ever does.

The UK GDPR supplies the standard consent must reach whenever consent is what you are relying on: freely given, tied to a specific purpose, informed, unmistakable, expressed through a clear positive act, as easy to take back as it was to give, and not bundled up with anything else. In practice that rules out boxes ticked in advance, notices announcing that carrying on browsing counts as agreement, walls that make refusal impractical, and anything non-essential firing before a choice has actually been made.

Since nothing here requires consent, nothing here asks for it.

4. The full inventory

This is the complete list for venuebooker.co as at the effective date above. Should it change, this page changes ahead of the site.

NameWhoseWhat it doesCategoryHow long
__cf_bm Cloudflare, Inc. — a third party, placing it on our domain Bot management. Separates people from automated traffic so the site can hold off scraping, credential stuffing and denial-of-service attempts. It reads nothing personal about you and feeds no measurement. Strictly necessary · HTTP cookie Up to thirty minutes from your last request
cf_clearance Cloudflare, Inc. Notes that a challenge has already been answered correctly, sparing you the same one on every page. It appears only where a challenge was actually put to your connection, which for most visitors never happens. Strictly necessary · HTTP cookie Up to a year, or until a fresh challenge is issued

That is the whole inventory. The pages here place no first-party cookie of their own, and they call on no local storage, no session storage, no IndexedDB and no pixel. There is no tag manager anywhere, no advertising pixel, no social widget and no embedded video player on any page of this site.

5. Requests that leave this site without a cookie

Being complete means naming things that are not cookies but still put another company in the picture.

The typefaces on these pages are served by Google Fonts, from fonts.googleapis.com and fonts.gstatic.com. Serving a font file sets no cookie and leaves no identifier behind on your device. What such a request unavoidably discloses is your connecting address and your browser string, because that is true of any request to any server anywhere. It gets a mention because a page claiming to involve nobody else while pulling type off somebody else’s servers would be telling you a half-truth. Bringing those files onto our own infrastructure would close that request off altogether; were we to do it, this section would change with it.

Scripts, frames and network connections from any other origin are refused outright by our content security policy. That is a deliberate piece of engineering rather than a happy accident: it means a tracker cannot find its way onto a page here by somebody’s oversight.

6. Measurement and advertising: where we stand

There is no web analytics on this site — not Google Analytics, and not a cookieless or self-hosted substitute either. Visitor numbers, which pages do well, what referred somebody, how many people convert: none of it is measured here. What exists is the aggregate request counting our hosting provider produces in order to keep the site running and defended, which is tied to nobody and is not treated by us as a marketing figure.

There is no advertising technology of any description: no advertising cookie, no retargeting pixel, no conversion tag, no data-broker integration, no cross-site tracking. Personal data is neither sold nor shared for advertising, and we take no part in real-time bidding.

Were that position ever to shift, section 8 is the undertaking we would be held to first.

7. Once you are signed in, and inside the apps

The signed-in web application necessarily keeps a few things on your device, and every one of them is strictly necessary to deliver what you have asked for:

  • a session cookie holding you signed in, flagged Secure, HttpOnly and SameSite, and expiring with the session or after a stretch of inactivity;
  • a CSRF token guarding form submissions against cross-site request forgery;
  • optionally, a local storage entry carrying your interface preferences and a cached copy of recent bookings, so that the diary appears quickly on a poor connection.

None of that measures anything or serves advertising, and all of it clears when you sign out. The inventory above covers these public pages; the signed-in application carries its own list, held to the same standard and available on request.

Inside the apps the mechanics differ, because an app has no browser cookies to work with. A sign-in token lives in the platform keychain or keystore and a cache lives in the app’s private container, alongside a push token and a resettable installation identifier. Advertising identifiers stay untouched — Apple’s IDFA and Android’s Advertising ID alike — and nothing resembling an advertising or third-party tracking SDK is compiled in. Section 18 of our Privacy Policy covers all of it properly.

8. If we ever needed something non-essential

Should we one day conclude that we need analytics, or any other non-essential cookie or storage technique, these are the commitments that would come with it:

  • The choice comes first. Nothing non-essential fires until you have chosen. No pre-ticked boxes, no consent inferred from the fact that you kept reading, nothing set on the way to asking.
  • Refusing is exactly as easy as agreeing — a “Reject all” sitting as prominently as “Accept all”, both on the first layer.
  • Choice by purpose, rather than one switch covering everything at once.
  • Changing your mind whenever you like, through a link present on every page, taking no more effort than agreeing took.
  • No cookie wall. Refuse and the site still works, all of it.
  • This page updated first, carrying the name, owner, purpose, category and duration of every new item, before any of it is deployed.

Advertising and cross-site tracking cookies are a different matter: we do not set them, and no change of circumstances would alter that.

9. Taking control in your own browser

Cookies can be blocked or cleared whenever you like, and you certainly do not need our permission. Blocking the strictly-necessary Cloudflare cookies is entirely your prerogative; the practical consequence is that a security check may be put to you more often, or that a page occasionally refuses to load.

  • Chrome on the desktop: from the ⋮ menu open Settings, where privacy and security holds both the third-party cookie switch and, under site settings, the per-site cookie controls. Clearing what is already stored happens from the same privacy and security screen.
  • Chrome on Android: from the ⋮ menu open Settings, then site settings, where cookies has its own entry.
  • Safari on macOS: from the Safari menu open Settings and choose Privacy, which offers both a per-site data manager and the switch marked “Prevent cross-site tracking”.
  • Safari on iPhone and iPad: open Settings and find Safari under Apps, where cookies can be blocked outright; clearing a single site is done from the website data screen under Advanced.
  • Firefox on the desktop: from the ☰ menu open Settings and choose Privacy & Security, which carries the cookie and site data controls alongside Enhanced Tracking Protection.
  • Firefox on Android and iOS: from the ☰ menu open Settings, where the same protection sits alongside a data management screen.
  • Microsoft Edge: from the ⋯ menu open Settings and choose cookies and site permissions, which is where stored cookies are managed and removed.
  • Samsung Internet: from the ☰ menu open Settings, then sites and downloads, where cookies has its own entry.

Every major browser also offers a private or incognito window, which throws away cookies and storage the moment it closes. Independent guidance on all of this is published by the Information Commissioner at ico.org.uk.

10. Do Not Track and Global Privacy Control

Do Not Track is a header some browsers offer, announcing that the person behind them would rather not be tracked. It never hardened into an enforceable standard, and a number of browsers have since removed the setting entirely. We take no action on it — not out of indifference, but because there is nothing here for it to switch off. No tracking happens whether the header arrives or not.

Global Privacy Control is the newer signal, sent by some browsers and extensions, declaring an opt-out from personal data being sold or shared, and from targeted advertising. It carries legal force in some jurisdictions and is not presently mandatory under United Kingdom law. Our answer is the same one: nothing is sold, nothing is shared, no targeted advertising is served, so the signal changes nothing about what happens here. Were we ever to introduce something the signal is designed to stop, it would be honoured as a valid objection to that processing — and this page would say so before any of it went live.

11. Contact

Questions about any of this, or a cookie you have spotted on our site that the inventory above does not name — which is something we would genuinely want to hear about:

Version 3.0 · Effective 15 August 2026 · Last updated 15 August 2026 · Supersedes version 2.0 of 5 August 2026.