Skip to main content

Cookie Policy

Last updated October 7, 2026

DRAFT — requires human review.

What cookies are

[Pending counsel review — no legal text drafted]

Cookies we set

This is the full list of cookies and browser storage the site uses today. The durations are the ones set by the site; counsel still has to confirm them.

Strictly necessary

  • consent_v1 — stores your cookie choice (analytics and marketing on or off) and when you made it. First-party, set when you choose in the cookie banner. Kept for 180 days.
  • consent_region — your approximate region (EU, EEA and Switzerland; UK; Brazil; US; or other), taken from the country our hosting provider derives from your IP address. It decides which cookie choice applies by default. First-party, set by our server before any choice. Kept for 24 hours.
  • ln-admin-session — the sign-in session of site administrators, sent only to the private admin area (/admin). Visitors never get it. First-party, not readable by scripts. Kept for up to 12 hours. A long session may be split into numbered parts (ln-admin-session.0, ln-admin-session.1).

Analytics (PostHog)

  • ph_<project key>_posthog and ph_<project key>_posthog_cpm cookies — an identifier for your browser and your current session, so visits and form steps can be counted. If you send us a form, the identifier is linked to your contact record. First-party. Kept for 365 days and renewed on later visits.
  • Browser storage with the same purpose: ph_<project key>_posthog and __ph_opt_in_out_<project key> (which records that analytics is allowed) in local storage, and ph_<project key>_window_id and ph_<project key>_primary_window_exists in session storage, which is cleared when the tab closes.
  • Analytics requests go through our own domain and reach PostHog without your cookies.
  • When they are set: only after you accept analytics. In the US they are on by default, unless your browser sends a Global Privacy Control signal or you choose Reject all (Do Not Sell or Share My Personal Information). Choosing Reject all deletes them.

Marketing attribution

  • _attr_ft (first visit) and _attr_lt (latest visit that came from a campaign or another site) — the campaign parameters in the link you followed (utm parameters, gclid, li_fat_id), the referring site and the landing page, so a contact or booking request can be linked to the campaign that brought you. First-party, not readable by scripts. Kept for 90 days.
  • When they are set: only after you accept analytics or marketing. In the US they are on by default, unless your browser sends a Global Privacy Control signal or you choose Reject all. Withdrawing your consent deletes them on your next page view.

Third-party services

  • Cloudflare Turnstile — protects the booking form (/contact and /book), the GTM assessment (/assessment) and the footer contact form against bots. Its script loads from challenges.cloudflare.com only when needed: at the last step of the booking form, and once you start filling in the assessment or the footer contact form. It loads whatever your cookie choice.
  • Calendly — after you send the booking form, the scheduling widget loads from assets.calendly.com and shows Calendly's booking page in an embedded frame. It loads whatever your cookie choice.

[Cookies and storage used by Cloudflare and Calendly to be confirmed with counsel]

Analytics and marketing cookies

[Pending counsel review — no legal text drafted]

Managing your choice

[Pending counsel review — no legal text drafted]

Changes to this policy

[Pending counsel review — no legal text drafted]

Contact

[Pending counsel review — no legal text drafted]

Your privacy choices

We use strictly necessary cookies to run this site. With your consent, we would also use analytics and marketing cookies. You can change your choice at any time from Cookie settings in the footer. Read the cookie policy