Skip to main content
WILDDECK

Cookie statement

Controller
WILDDECK LTD, company number SC880737, registered in Scotland
Contact
hello@wilddeck.co.uk
Effective
10 August 2026
Version
1.0, the first published version
Framework
PECR 2003, regulation 6, read with the UK GDPR
Applies to
wilddeck.co.uk

This site sets no cookies of its own and runs no analytics, so there is no consent banner and nothing to accept or reject. Two things still reach beyond the page and both are set out below, along with the reason a banner would be theatre rather than compliance.

1. The short answer

This website sets no cookies of its own. No analytics, no advertising, no tracking pixel, no session recording.

There is no consent banner, because there is nothing here that requires consent.

Two things do reach beyond the page: a strictly necessary security cookie our hosting provider may set, and a request to Google's font servers. Both are set out below.

2. The rule this answers to

The operative rule is regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, read with the UK GDPR. Storing information on your device, or gaining access to information already stored there, requires clear information and consent.

The rule is technology neutral. Local storage, session storage, IndexedDB, pixel tags and device fingerprinting are caught exactly as cookies are, so avoiding the word does not avoid the obligation.

The exemption

Consent is not required where the storage or access is strictly necessary for a service you explicitly requested. The Information Commissioner's Office reads that narrowly: a security or load balancing mechanism qualifies, and analytics does not, however anonymous it claims to be.

3. Why there is no banner

A banner exists to collect permission for storage that is not strictly necessary. There is none here, so a banner would be asking you to consent to nothing.

That is worse than leaving it out. It trains people to dismiss a control that matters on other sites, and it implies this one is doing something it is not.

If anything outside the exemption is ever added, we will ask before it loads, make refusing exactly as easy as accepting, record what was agreed and when, and update this page and its effective date first.

4. Everything this site may store

Two cookies, neither set by us.

  • __cf_bm, set by Cloudflare, our hosting provider. Distinguishes automated traffic from human traffic so abusive requests can be blocked. 30 minutes, refreshed on activity. Strictly necessary.
  • cf_clearance, set by Cloudflare only if you are shown and pass a challenge, recording that you passed so you are not asked again. Up to 30 days. Strictly necessary.

That is the complete list, and neither is readable by us as an identifier of you.

5. What this site does not do

  • No Google Analytics, Plausible, Fathom, Matomo or any other analytics.
  • No advertising and no advertising cookies.
  • No Meta pixel, LinkedIn Insight tag, TikTok pixel or conversion tracking.
  • No session recording, heatmapping or scroll tracking.
  • No embedded video, map, social widget or comment system.
  • No local storage, session storage or IndexedDB written by our code.
  • No fingerprinting and no attempt to recognise a returning visitor.

Open the Application and Network panels in your browser's developer tools and compare them with this list. That is a better assurance than any promise on this page.

6. The one outbound request

This site loads two typefaces from Google Fonts, at fonts.googleapis.com and fonts.gstatic.com. That request discloses your IP address, your user agent and the referring page to Google's servers. Google states the Fonts service sets no cookies and does not use the requests for advertising or profiling.

Self hosting the files would remove the request and it is on our list. Until then this is the honest description rather than an omission, and blocking those two hosts leaves the site fully readable in a system font.

7. Server logs are not cookies

Every web server records the requests it receives. Our hosting provider logs IP address, timestamp, path, user agent and response code. Nothing is stored on your device, so regulation 6 is not engaged, but an IP address is personal data under the UK GDPR and it belongs in an honest account of what this site collects.

The lawful basis is legitimate interests under Article 6(1)(f): delivering the site and defending it from abuse. The logs sit with the provider on its own cycle, currently under 30 days, and are not combined with anything else.

8. Controlling storage yourself

Every major browser lets you block cookies, delete them, and inspect what a site has set. Blocking the two above may mean Cloudflare challenges you more often, but the site will still work.

  • Chrome: Settings, then Privacy and security, then Third-party cookies and Site data.
  • Safari: Settings, then Privacy, then Manage Website Data.
  • Firefox: Settings, then Privacy and Security, then Cookies and Site Data.
  • Edge: Settings, then Cookies and site permissions.

9. Do Not Track and Global Privacy Control

Both are honoured, which is straightforward because there is nothing here to switch off. If either signal is present, no additional storage or processing occurs, and the same is true if neither is.

We say so anyway, because a site that ignores these signals and stays quiet about it has made a choice it would rather you did not notice.

10. Applications do not use cookies

Cookies are a website mechanism. A mobile application does not use them, and nothing on this page describes one.

What an application would store on your device, and what it would send anywhere, is described in the privacy notice. No application has been released, so at present the answer is that nothing is stored and nothing is sent.

11. Changes, questions and complaints

If anything that stores information on your device is added beyond what is listed here, this page and its effective date change before it goes live, and consent is collected where regulation 6 requires it.

Questions go to hello@wilddeck.co.uk and are answered within five working days. A data protection request is answered within one month, as Article 12(3) of the UK GDPR requires.

If our answer does not satisfy you, you can complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113, ico.org.uk. There is no fee, you do not need a solicitor, and you do not need our agreement.