Legal
Cookies
The short version: this site sets four analytics cookies — two Google, two Microsoft — and stores one display preference in your browser. Microsoft Clarity also records your visit as a replay. There is no advertising tag and nothing is sold on. If you are in the UK, the EEA or Switzerland you will have been offered a way to turn the analytics off; taking it deletes those four cookies and stops the recording. Everything is listed in full below.
What this site stores today.
Five entries. Two are Google Analytics, which counts visits and pages. Two are Microsoft Clarity, which records the visit so we can watch where a page confuses people. One is the light/dark preference, written only if you use the toggle and never sent anywhere.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
| pf-theme | Local storage | Remembers whether you chose light or dark mode. Written only if you press the toggle; with nothing stored, your operating system setting decides. | Until you clear site data |
| _ga | Cookie | Set by Google Analytics 4 to tell one browser from another across visits, so a returning visitor is not counted twice. It carries a randomly generated ID, not a name or an address. | 2 years |
| _ga_V9FEGXVZ9V | Cookie | Set by Google Analytics 4 to hold the state of the current session for this property. | 2 years |
| _clck | Cookie | Set by Microsoft Clarity to keep one randomly generated ID for your browser, so repeat visits join up in the session recordings. | 1 year |
| _clsk | Cookie | Set by Microsoft Clarity to join the pages you view in one visit into a single recorded session. | 1 day |
Typefaces are served from this domain rather than a font CDN, so no third party sees a request for them. Clarity is the exception: it loads from clarity.ms, and Microsoft sets its own cookies on that domain — CLID, MUID, ANONCHK and SM — which this site does not set and cannot list a lifetime for. Clearing site data in your browser removes the entries above; the site then follows your operating system’s light or dark setting instead.
Status of the full policy.
Awaiting counsel-reviewed copy
The table above is accurate and checkable against the code. It is not a cookie policy — that document has to be written and reviewed by someone qualified, alongside the privacy policy, and it has to cover the tools listed below once they are actually installed.
What is still to be decided.
Each of these adds something to this page the day it goes live. None of them is built yet, so none of them is described here as though it were.
- The scheduler embed The audit page will carry an inline Cal.com calendar. An embedded third party sets its own storage under its own policy, and that has to be listed here once it is live.
- The email platform The calculator PDF capture and the contact form will post to an email platform. Whatever it sets, and what it does with an address, belongs on this page and in the privacy policy.
- Hosting and CDN The host may set its own operational cookies independently of the pages. That needs checking against the deployed site rather than assumed.
- Google Tag Manager The container is installed. On its own it sets no cookie — it is a loader. What it loads is edited in Google's interface, not in this repository, so a tag added there can start setting cookies with no code change and no edit to this table. Whoever adds a tag has to update this page in the same sitting, and until that habit is proven, treat the table above as accurate as of the last deployment rather than as of right now.
- Session recording Clarity replays a visit: cursor movement, scrolling, clicks and what was typed into a form. Clarity masks form input by default and this site has not turned that masking off, so what you type into the audit or contact form should not reach the recording — that needs verifying against a real recording rather than trusted, and the result belongs here. Microsoft is a separate controller for what it holds.
- Consent, and the limit of it Visitors in the UK, the EEA and Switzerland get a notice offering to turn analytics off. Outside those places nothing is shown, because nothing there requires it. Turning it off is real rather than cosmetic: it sets Google Consent Mode to denied, stops Clarity from loading on any later page, and deletes the four cookies listed above. The choice is remembered and applied before any tag loads next time. What this is not is prior consent — analytics runs until it is refused, and the stricter reading of UK and EU law is that a non-essential cookie should not be set until the visitor has agreed. That is a deliberate choice by us, not an oversight, and it is the one part of this page counsel is most likely to want changed. The switch between the two models is a single line in the codebase.
- How we decide where to show it From the timezone your browser reports, which costs no network request and sends nothing anywhere. It is a good signal, not a perfect one: a VPN or a travelling laptop can read wrong either way. If the timezone cannot be read at all the notice is shown rather than skipped. The Google tags are gated separately by Consent Mode using the region Google resolves from your IP, so those do not depend on the timezone guess.
Questions about any of this go to hello@pointerflow.com and get a written answer within one business day.