Skip to content
Legal

Cookie Policy

What the ServusOne marketing site stores in your browser, why, and how to change or clear your choice.

Last reviewed: 2026-08-21

Cookies and similar technologies

Cookies are small values a site asks a browser to store. Similar technologies include local storage, session storage, scripts, pixels, and embedded content.

This site stores your own privacy preference choice in your browser, and records the decisions that change it in a consent audit database we operate. Both are described in full below. Your preference itself is stored in the browser's local storage rather than as a cookie.

If you allow the analytics category, Google Analytics 4 additionally sets its own first-party `_ga` and `_ga_<container>` cookies in your browser. Those are cookies, unlike this site's own preference record, and they are set only after you have allowed analytics.

Categories this site asks about

Necessary: always on. This covers the storage of your own preference choice and the security behaviour of the site itself. It cannot be switched off, because switching it off would mean not being able to record that you switched anything off.

Analytics: offered, and off until you allow it. When it is allowed, Google Analytics 4 measures seven named conversion actions on this site. It never measures page views, scrolling, hovering, session replay, or heat maps.

This site does not ask you about marketing or preference categories, because it does not use them. Asking for consent to something a site does not do is a request for permission it has no use for.

What is stored in your browser

Mechanism: a JSON record in your browser's local storage. This site does not set a consent cookie.

Storage key: a site-scoped key naming this site specifically, so a preference recorded here is never read as a preference for another Tradeforce site.

Contents: the site identifier, the privacy-policy version the choice was made against, your true/false choice for each category, a random consent receipt identifier, and — only where you have allowed an optional category — the date and time our own database recorded that decision. Nothing else.

The consent receipt identifier is a random value generated in your browser. It is not an account, a user, a device, or a session identifier, it is not derived from your address, your IP address, or any device characteristic, and it is not shared with any other Tradeforce site.

The record contains no name, no email address, no fingerprint, no page history, and no referrer history. It is not used to recognise you.

Duration: browser local storage has no expiry date of its own, so this site sets one for permissions. An allowed optional category is relied upon for at most 24 months from the time our database recorded the decision. After that the site stops relying on it, the privacy panel reopens, and nothing optional runs again until you make a fresh choice that is recorded.

A refusal is not expired in the same way. Refusing an optional category stays in force until you change it, you clear your browser's site data, or the policy version changes. We do not ask you to re-refuse something you have already declined.

Invalidation: if the stored record names a different site or is unreadable, it is discarded and treated as no choice at all. The same applies to a stored permission whose recorded date and time are missing, unreadable, or more than 24 months old. Optional categories are denied until you make a fresh choice — a stale, expired, or unrecognised record is never treated as permission.

What is recorded on our servers

When you make a choice that changes your privacy settings, that decision is also recorded in a consent audit database we operate on Cloudflare D1. This is what lets us show which choice was made, and against which version of this policy.

Each recorded decision contains: a random event identifier, your random consent receipt identifier, a record-format version, the site identifier, the policy version, a fingerprint of the exact consent policy, category configuration, and retention periods you were shown, which control you used, your true/false value for each category, and the date and time our database recorded it.

That is the whole record. It contains no name, no email address, no message you may have sent us, no IP address, no browser or device information, no referrer, no page history, and no analytics identifier. Nothing in it identifies you.

The date and time are taken from our database, not from your browser, so the recorded time is ours to stand behind rather than something a browser could be made to misreport.

The consent audit is append-only in ordinary operation, as a matter of how this application and this database are built: this website can only add records to it. The database refuses every attempt to change an existing record, and refuses to delete one unless that individual record has been separately authorised for deletion by the retention process described in the next section. This is an application and database rule. It is not a claim that the records are legally or cryptographically immutable — an administrator with separate account-level access to the underlying database could still act on it.

There is no public way to read this audit back, and no public way to delete from it. The receipt identifier is not a password; this site provides no page or interface that returns your consent history, and the website itself has no ability to remove a consent record.

How long consent records are kept

Active consent: while we are actually relying on it. A decision that allows an optional category is kept for as long as that permission is in force.

Refresh: an allowed optional category is relied upon for at most 24 months from the moment our database recorded the decision. At that point we stop relying on it and ask you again, so a permission is never carried forward indefinitely on the strength of a choice you made years ago.

History: once you withdraw or refuse consent, or the version of this policy the decision was made against is superseded, the historical record of that decision is kept for a further 36 months. It is kept so we can show what was decided and against which wording, which is the whole reason for recording it.

A permission that is never refreshed is therefore kept for at most 24 months of reliance plus 36 months of history — 60 months from the decision — and becomes eligible for deletion after that.

Deletion: a scheduled maintenance process, which is separate from this website and cannot be reached from it, deletes records that have passed their retention period. It works in small batches, it deletes one consent history as a whole rather than removing individual records from the middle of one, and the database will not let it delete a record it has not separately and specifically authorised. It records how many records it deleted, never which ones.

This site does not keep consent audit records indefinitely, and this policy does not claim that it does. No archive copy of the consent audit is kept anywhere else, and no copy would be allowed to outlive the periods above.

How the controls work

Accept all allows every optional category this site offers.

Reject non-essential keeps necessary functionality active and refuses every optional category.

Save preferences records exactly the category choices shown in the panel.

Allowing an optional category takes effect only once the decision has been recorded in our consent audit database. If that recording fails, is refused, or cannot be confirmed, the category stays off and the panel tells you so. We do not switch anything on and record it later.

Refusing or withdrawing a category takes effect in your browser immediately, before and regardless of any recording. If the recording is temporarily unavailable, your refusal still applies and the record of it is retried later.

Closing the panel, pressing Escape, scrolling, or continuing to browse does not grant optional consent. Nothing optional is treated as allowed until you actively allow it.

Change or withdraw a choice

Use the privacy preferences control on this site to review or change your choices at any time. Refusing a category withdraws it and stops any future optional loading for it straight away.

Clearing your browser's site data for this site removes the stored record entirely and returns the site to its first-visit state. It does not remove decisions already recorded in the consent audit, which is the point of keeping one. Those recorded decisions are deleted at the end of the retention period set out above.

Other optional services

Google Analytics 4 is the only optional service on this site, and it runs only under the analytics category described above.

Advertising pixels, retargeting tags, session replay, heat maps, and optional embedded third-party content are not used, and no marketing category is offered.

Before any further optional service could be enabled it must be assigned to the correct category, blocked before consent, documented in this policy — which changes the policy fingerprint recorded with every consent decision — and tested.

Policy changes and contact

A policy-version change returns the site to necessary-only behavior and asks for a fresh choice, because a choice made against different wording is not a choice about this wording. So does the 24-month refresh described above, for the same reason: a permission nobody has confirmed for two years is not a current answer.

For questions about this policy, use the ServusOne contact page.