Legal & compliance
Cookies & Similar Technologies
Last updated: 28 July 2026
Meet Me Gently is a static site, and we keep first-party tracking technology to a minimum on purpose. This page lists, honestly, every cookie and every browser-storage key the site and its payment processor use, what each one is for, and how you can control or withdraw them.
1. What this covers
This page explains, in plain English, the cookies, security tokens and browser-storage keys that Meet Me Gently — operated by Ardit Tashi — and the services we rely on (Cloudflare for hosting and security, Stripe for payment) place on your device when you visit this site, preview the deck, or check out.
We do not run advertising networks, social-media pixels, or third-party
tracking scripts. The site is built as static HTML, CSS and JavaScript with
no server-side session of its own — most of what looks like "memory" on this
site (your saved cards, favourites, and progress through the sampler) lives
in your browser's localStorage, not in a cookie, and is covered
separately below.
2. Cookies, tokens, and localStorage keys we use
The table below is split into two parts: actual HTTP cookies set by
Cloudflare and Stripe, and browser localStorage keys set by our
own site code. Both are listed for completeness, even though only the first
group are cookies in the strict sense.
| Name or key | Type | Purpose | Provider | Storage & duration | Consent needed |
|---|---|---|---|---|---|
__cf_bm |
HTTP cookie | Bot-management: distinguishes automated traffic from genuine visitors so the site stays available and safe. | Cloudflare | Session-length, typically expires within about 30 minutes. | No — strictly necessary. |
cf_clearance and related challenge tokens |
HTTP cookie | Records that a visitor has passed a Cloudflare security check (e.g. after a challenge page), so it isn't repeated on every page load. | Cloudflare | Typically up to 24 hours, renewed on repeat challenges. | No — strictly necessary. |
| Stripe Checkout session & fraud-prevention cookies | HTTP cookie, set on Stripe's own domain | Created only once you reach checkout: maintains your payment session and screens the transaction for fraud so your card details are handled safely. | Stripe | Set and read on checkout.stripe.com / Stripe's
domains during and shortly after payment; we do not receive or
store these cookies ourselves. |
No — strictly necessary to complete a purchase. |
| Age-attestation record | HTTP cookie or equivalent short-lived token | Remembers that you already confirmed you are 18+ (or the age of majority where you live), so you are not asked again on every page. See Age Verification for the full policy. | First-party (this site) | Typically session-length or a limited number of days. | No — strictly necessary for legal compliance and to avoid repeat prompts. |
Separately, the site itself writes the following keys directly into your
browser's localStorage — never a cookie, and never sent to our
servers:
| Name or key | Type | Purpose | Provider | Storage & duration | Consent needed |
|---|---|---|---|---|---|
| Saved cards | localStorage | Keeps the individual cards you've marked to keep from the deck or sampler, so they're there next time you open the site on the same browser. | First-party (this site) | Persists until you clear it or clear your browser's site data; no expiry set by us. | No — functional, not tracking; see below. |
| Favourites | localStorage | Stores which cards you've starred or liked. | First-party (this site) | Persists until you clear it or clear your browser's site data. | No — functional, not tracking. |
| Deck / sampler progress | localStorage | Remembers where you left off in the free sampler or a purchased deck, so you can pick up where you stopped. | First-party (this site) | Persists until you clear it or clear your browser's site data. | No — functional, not tracking. |
| UI preferences (theme, motion) | localStorage | Remembers display choices such as light/dark theme or reduced-motion preference. | First-party (this site) | Persists until you clear it or clear your browser's site data. | No — functional, not tracking. |
3. localStorage isn't a cookie, but it's similar
Technically, localStorage is not a cookie — it isn't sent to
our servers with every request, and we have no way to read it remotely.
It's a small amount of data your browser keeps for itself, on your device,
tied to this site's domain.
Even so, under the ePrivacy Directive it counts as "similar technology," because it is storage on your device that the site reads and writes. The practical differences that matter to you are: it lives only in your own browser; it is never transmitted to us or to any third party; it persists until you clear it or clear your browser's site data for this domain; and if you do clear it, you will lose your saved cards, favourites and sampler progress, and will need to rebuild them from scratch.
↑ Back to top4. Analytics
Two analytics tools run on this site, and they behave very differently. The difference is the point: one cannot identify you and so runs for everyone, and the other can set cookies and so does not run at all unless you say yes.
Cloudflare Web Analytics — always on, no cookies. Every
page loads a small script from
static.cloudflareinsights.com that reports the page address,
a coarse country, the referring site, the browser and how quickly the page
rendered. It sets no cookies and writes nothing to your device,
it does not follow you between websites, and it builds no profile. Because
it stores nothing on your device it does not require consent under the
ePrivacy rules, so it is not covered by the banner and there is nothing to
switch off. Cloudflare processes it as our processor and we see only totals.
Google Analytics 4 — off until you opt in. If you accept
analytics in the banner, and only then, the site loads
googletagmanager.com and Google Analytics sets its own cookies
(typically _ga and _ga_<id>, up to two
years) to count returning visits. Until you accept, that script is
never requested and no Google cookie exists — consent is not
merely "denied" while the tag loads anyway, the tag is not fetched at all.
IP addresses are truncated and Google advertising signals are disabled.
Your choice is remembered on your own device, in the
localStorage key mmg-consent-analytics, whose value is simply
granted or denied. It is not a cookie, it is
never transmitted to us, and clearing your browser storage for this site
removes it — after which the banner asks again.
To withdraw consent, clear this site's browser storage
(which deletes mmg-consent-analytics and returns the banner),
or delete the _ga cookies in your browser settings. You can
also refuse at the banner in the first place; nothing on the site behaves
differently either way.
5. Consent basis
Our legal basis for cookies and similar technologies in the EU/EEA and UK is Article 5(3) of the ePrivacy Directive 2002/58/EC, as implemented in national law, read together with the GDPR's standard of consent: consent must be freely given, specific, informed and unambiguous, given through a clear affirmative act, and must be as easy to withdraw as it was to give.
Storage that is strictly necessary — to run the site, keep it secure, or complete a transaction you've asked for — is exempt from that consent requirement, and that is the only category of storage this site currently uses. Anything beyond strictly-necessary storage (such as analytics or advertising) would need your prior opt-in consent before it loads, for visitors in the EEA and UK.
In the United States, the position differs by state: several states (for example California, Colorado, Virginia and Connecticut) treat this kind of storage on an opt-out basis rather than requiring prior opt-in consent. We will follow the rule that applies in your location.
↑ Back to top6. How to withdraw or change consent
Every page on this site has a "Cookie settings" link in the footer. Selecting it — or the button below — reopens the same banner you saw on your first visit, so you can switch your analytics choice at any time, just as easily as you gave it.
You can also clear cookies and site data directly in your browser:
- Chrome — Settings → Privacy and security → Cookies and other site data → See all site data and permissions, then search for this site and remove it.
- Firefox — Settings → Privacy & Security → Cookies and Site Data → Manage Data, then search for this site and remove it.
- Safari — Settings → Privacy → Manage Website Data, then search for this site and remove it.
- Edge — Settings → Cookies and site permissions → Manage and delete cookies and site data → See all cookies and site data, then search for this site and remove it.
Blocking or clearing strictly-necessary storage may break checkout (Stripe cannot complete payment without its own session cookies) or interrupt access to a download you've already paid for. Clearing site data will also remove your saved cards, favourites, and sampler progress, since those live in the same browser storage.
↑ Back to top7. Do Not Track & Global Privacy Control
We do not run cross-site advertising trackers, so there is little for a Do Not Track signal to switch off — but we address both signals directly. The "Do Not Track" browser header never became an agreed standard across browsers and regulators, so we do not rely on it as a meaningful opt-out signal on its own.
Global Privacy Control (GPC), where sent by your browser or a browser extension, is treated as a valid opt-out request wherever an opt-out right applies to your location — for example under California's CCPA/CPRA. As noted above, we currently deploy no optional cookies or analytics for GPC to switch off, but the signal will be honoured automatically if and when any are added.
↑ Back to top8. Changes to this policy, and contact
We may update this cookies notice as the site's technology changes — for example if an analytics or support-chat tool is added. The "last updated" date at the top of this page will change whenever we do, and any newly added optional storage will be reflected in the table above before it goes live.
This page should be read alongside our Privacy Notice, which explains in full what personal data we collect and why. For questions about cookies, tokens or localStorage on this site, contact hello@meetmegently.com.
↑ Back to top