Legal

Cookie Policy

Last updated: October 2026

What cookies and local storage are

Cookies are small text files stored on your device by your browser. Local storage is a similar browser mechanism that lets a site remember information (such as your consent choice). Under UK PECR, we need your prior consent before storing or accessing anything that is not strictly necessary — so optional categories below stay off until you opt in. Browser settings alone are not our consent mechanism; use the on-site consent banner or the “Cookie Settings” footer link.

Consent categories we use

  • Necessary — always on. Required for the site to work and to remember your consent choice (`bf-consent-v1`, containing only a version, your category choices and a timestamp).
  • Analytics — opt-in. Aggregate measurement of site usage.
  • B2B visitor identification — opt-in. Loads the Dealfront / Leadfeeder tracker to attribute visits at company level. Nothing in this category runs until you accept it.

Optional categories are never pre-ticked. You can accept all, reject all non-essential, or pick individually via “Manage preferences”.

Necessary technologies

  • `bf-consent-v1` (localStorage) — your consent record: version, analytics choice, visitor-identification choice, timestamp. No personal information beyond those flags.
  • Interface preferences set by site components (for example UI state). These do not identify you for marketing.

Vercel Analytics

We use Vercel Analytics for aggregate measurement (e.g. page views and performance). According to Vercel's public documentation it is designed to be cookieless — it does not set tracking cookies and reports aggregated statistics rather than cross-site profiles.

TODO (legal review): confirm the lawful basis, retention and international-transfer position for Vercel Analytics (vendor documentation indicates processing in the United States) before treating this as a complete legal statement.

Dealfront / Leadfeeder (consent-gated)

The tracker at `sc.lfeeder.com` loads only after you accept the “B2B visitor identification” category. Before consent, your browser makes no request to that host from our site and no Leadfeeder storage is created by us.

Based solely on the vendor's public help documentation (not independently probed), the tracker may use first-party cookies/local storage reported under names including `_lfa`, `_lfa_consent`, `_lfa_test_cookie_stored` and a `_lfa_expiry` local-storage entry, and may process IP address, visitor identifier, pages visited, visit date/time, duration and referring source / UTM data for company-level attribution. We do not state exact expiry periods here because they may vary with vendor configuration — refer to the vendor's current cookie documentation for authoritative durations.

TODO (legal/vendor review): confirm lawful basis, retention period, data processing agreement, IP-anonymisation setting and vendor-dashboard Consent Mode status.

Changing or withdrawing consent

Use the “Cookie Settings” link in the footer at any time to reopen preferences and accept, adjust or withdraw optional categories. Withdrawing B2B visitor-identification consent prevents the tracker loading on future visits from that browser, and we make a best-effort attempt to clear readable Leadfeeder cookies/storage on that device.

Withdrawal stops future tracking but cannot necessarily erase processing the third-party provider already performed. For access, erasure, restriction, portability or objection requests, contact hello@brandflume.com.