Skip to main content

Legal document 03 of 03

Cookie notice

  • Effective 7 August 2026
  • Version 1.0
  • PECR 2003 and the UK GDPR
  • Company number 17061506

This site sets no cookies of its own and runs no analytics, so there is no consent banner. Two things still touch your device or leave a trace, and both are set out below rather than buried. Everything here can be checked in your browser's developer tools, which is the only verification worth having.

1. Position in one paragraph

The site sets no cookies of its own. There is no analytics, no advertising, no tracking pixel, no session recording and no profile of you. There is no consent banner because nothing here needs consent. A strictly necessary security cookie may be set by our hosting provider, and the page requests three typefaces from Google's font servers. Those two facts are the whole story, and both are described below.

2. The rule this notice answers to

A cookie is a small file a site asks your browser to store and return on later visits. Local storage, session storage and pixel tags achieve the same thing by other means, and the law treats them alike.

In the United Kingdom the rule is regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, read with the UK GDPR. Storing information on a user's device, or accessing information already stored there, requires clear information and consent.

There is one narrow exemption: consent is not needed where the storage or access is strictly necessary for a service the user has explicitly requested. The Information Commissioner's Office reads that narrowly. It covers a security or load-balancing mechanism. It does not cover analytics, and it does not cover anything a site operator merely finds useful.

3. Why there is no banner

A consent banner exists to collect permission for storage that is not strictly necessary. This site has none, so a banner would ask you to consent to nothing.

We think that is worse than omitting it. It trains people to dismiss a control that matters elsewhere, and it implies activity that is not happening.

If analytics or anything else outside the exemption is ever added, we will ask for consent before it loads, make refusing as easy as accepting, and update this page and its effective date first.

4. What is actually stored

The site is a set of static files. There is no login, no basket, no server-side form, no session and no account, so there is nothing for a first-party cookie to remember.

Storage that may reach your device
What Set by Purpose Consent needed
__cf_bm or a similarly named Cloudflare cookie Cloudflare, our hosting and content delivery provider Bot management. Distinguishes automated clients from human ones so the site stays available. Set only when Cloudflare's protection engages. No. Strictly necessary for the security and availability of a service you requested.
Nothing else Not applicable The site defines no cookie and writes nothing to local or session storage. Not applicable

Check it yourself. Open developer tools, go to the storage or application panel, and load any page. The cookie list should be empty or hold only a Cloudflare entry, and local storage should be empty.

The Cloudflare cookie's exact name and lifetime are set by Cloudflare, not by us, which is why this notice describes it by function rather than quoting a duration we do not control.

5. What this site does not do

  • No analytics of any kind, first party or third party, hosted or self-hosted. We do not count visitors.
  • No advertising, ad network, retargeting or conversion pixel.
  • No social buttons, embeds or share widgets.
  • No embedded video, map or comment system.
  • No fingerprinting, session recording, heatmap or A/B testing tool.
  • No cross-site tracking, and no sale or sharing of anything about you.
  • No chat widget.

The practical consequence is that we do not know how many people read this page. That is the trade, and we accept it.

6. The one outbound request

The site loads three typefaces from Google Fonts, so your browser contacts fonts.googleapis.com and fonts.gstatic.com when a page loads.

That request sets no cookie, but it does disclose your IP address and standard request headers to Google LLC, and it is a transfer of personal data outside the United Kingdom. Google states it does not use these requests for advertising profiles. We cannot verify that, so we tell you the request happens and let you weigh it.

The content security policy served with every page permits those two hosts and nothing else. You can read it in the response headers.

Self-hosting the fonts would remove the request entirely. It is on the list and is not done. Until it is, this notice states the position as it stands.

7. Server logs

Serving a page produces a log entry at the hosting provider. That is a record held at the server, not storage placed on your device, so PECR does not apply to it. It is still personal data and is covered by the privacy notice.

A log line holds the IP address, timestamp, path, response status, user agent and referring page. It is used to keep the site running and to investigate abuse. It is not joined to anything else and not used to profile anyone.

8. Controlling storage yourself

You do not need our permission. Every current browser lets you inspect, block and delete cookies and site storage.

  • Chrome: Settings, Privacy and security, Third-party cookies; Site settings for per-site control.
  • Safari: Settings, Privacy, Manage Website Data, plus Prevent cross-site tracking.
  • Firefox: Settings, Privacy and Security, Cookies and Site Data, plus Enhanced Tracking Protection.
  • Edge: Settings, Cookies and site permissions.

Blocking the Cloudflare security cookie may mean Cloudflare challenges your requests more often, since it can no longer tell your browser has already passed a check. Nothing else here depends on storage, so blocking everything will not break the site.

An extension that blocks third-party requests will stop the font request. The site then renders in your system typefaces. The layout is built to survive that and stays readable.

9. Do Not Track and Global Privacy Control

Some browsers send a Do Not Track header, some send a Global Privacy Control signal, and there is no settled standard for how a site must respond to either.

The question does not arise here. No tracking happens whether or not a signal is sent, so honouring it and ignoring it produce the same result. We mention it so you are not left guessing.

10. If this changes

This notice describes the site as at the effective date above. If anything is added that stores information on your device beyond the strictly necessary, we will update this notice, change the effective date, and put a consent mechanism in place before the new technology loads for the first time.

We will not quietly add analytics and rely on this page having been amended at some earlier point.

11. Questions and complaints

Email privacy@thetwentyfintech.co.uk with "Cookies" in the subject line. If you think this notice is inaccurate, tell us what you observed and how, and we will check it and correct the page if you are right.

You may also complain to the Information Commissioner's Office, the United Kingdom supervisory authority for PECR and data protection: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, telephone 0303 123 1113, or the complaint form at ico.org.uk. You can go to the ICO without contacting us first, although we would rather have the chance to fix it.