Cookie Policy
Last updated October 7, 2026
DRAFT — requires human review.
What cookies are
[Pending counsel review — no legal text drafted]
Cookies we set
This is the full list of cookies and browser storage the site uses today. The durations are the ones set by the site; counsel still has to confirm them.
Strictly necessary
consent_v1— stores your cookie choice (analytics and marketing on or off) and when you made it. First-party, set when you choose in the cookie banner. Kept for 180 days.consent_region— your approximate region (EU, EEA and Switzerland; UK; Brazil; US; or other), taken from the country our hosting provider derives from your IP address. It decides which cookie choice applies by default. First-party, set by our server before any choice. Kept for 24 hours.ln-admin-session— the sign-in session of site administrators, sent only to the private admin area (/admin). Visitors never get it. First-party, not readable by scripts. Kept for up to 12 hours. A long session may be split into numbered parts (ln-admin-session.0,ln-admin-session.1).
Analytics (PostHog)
ph_<project key>_posthogandph_<project key>_posthog_cpmcookies — an identifier for your browser and your current session, so visits and form steps can be counted. If you send us a form, the identifier is linked to your contact record. First-party. Kept for 365 days and renewed on later visits.- Browser storage with the same purpose:
ph_<project key>_posthogand__ph_opt_in_out_<project key>(which records that analytics is allowed) in local storage, andph_<project key>_window_idandph_<project key>_primary_window_existsin session storage, which is cleared when the tab closes. - Analytics requests go through our own domain and reach PostHog without your cookies.
- When they are set: only after you accept analytics. In the US they are on by default, unless your browser sends a Global Privacy Control signal or you choose Reject all (Do Not Sell or Share My Personal Information). Choosing Reject all deletes them.
Marketing attribution
_attr_ft(first visit) and_attr_lt(latest visit that came from a campaign or another site) — the campaign parameters in the link you followed (utm parameters, gclid, li_fat_id), the referring site and the landing page, so a contact or booking request can be linked to the campaign that brought you. First-party, not readable by scripts. Kept for 90 days.- When they are set: only after you accept analytics or marketing. In the US they are on by default, unless your browser sends a Global Privacy Control signal or you choose Reject all. Withdrawing your consent deletes them on your next page view.
Third-party services
- Cloudflare Turnstile — protects the booking form (
/contactand/book), the GTM assessment (/assessment) and the footer contact form against bots. Its script loads from challenges.cloudflare.com only when needed: at the last step of the booking form, and once you start filling in the assessment or the footer contact form. It loads whatever your cookie choice. - Calendly — after you send the booking form, the scheduling widget loads from assets.calendly.com and shows Calendly's booking page in an embedded frame. It loads whatever your cookie choice.
[Cookies and storage used by Cloudflare and Calendly to be confirmed with counsel]
Analytics and marketing cookies
[Pending counsel review — no legal text drafted]
Managing your choice
[Pending counsel review — no legal text drafted]
Changes to this policy
[Pending counsel review — no legal text drafted]
Contact
[Pending counsel review — no legal text drafted]