Cookie Policy
A complete account of what these pages ask your device to keep, which duties apply to that, and how to overrule us. Two security values written by our provider are the whole of it.
1. Scope of this note
Everything below describes one website, https://themecanvas.uk, published by THEME CANVAS UK LIMITED, Company No. NI736836. Two companion documents sit alongside: the Privacy Policy for personal data at large, and the Terms of Use, which is the contract itself.
Four things sit outside it: any site you reach by following a link from here, the websites we have built for clients, the two app stores, and your own WordPress installation after you fit one of our products to it. That last case has its own entry at section 10.
2. The storage techniques, defined
A cookie is a short labelled string. The site asks the browser to keep it, and the browser returns it on later visits. Two distinctions matter for what follows. One is lifespan: a session value disappears once the browser is shut, while a persistent value waits for its stated expiry date or for you to clear it. The other is authorship. A first-party value is owned by whatever address your URL bar displays. A third-party value is owned by some other host whose content this page has drawn in.
Several other mechanisms are treated identically here, because each of them writes to or reads from equipment you own:
- Web storage — the local and session key stores a page can write into. They resemble cookies but travel only when a script fetches them, not automatically on every request.
- IndexedDB and the Cache API — much larger stores, designed to let an application hold structured records or work offline.
- Beacons and pixels — an image or script that exists only to be fetched, since the fetch is the measurement. Registering that somebody opened a page or a message is the usual job.
- In-app storage — the same idea inside a mobile application, written by the app or by an embedded kit.
- Fingerprinting — assembling a recognisable signature out of device and browser characteristics, so that nothing has to be stored at all. The regulator treats it as equivalent to storage. It plays no part in this site.
3. Which rules govern this
The governing provision is regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, PECR for short, which speaks to anything written onto or read back from your equipment. Two duties fall out of it: tell the person plainly what the storage achieves, and obtain agreement beforehand. One category escapes the second duty — storage that is strictly necessary to deliver something the person deliberately asked for. Keeping a requested page reachable and defended qualifies. Counting visitors or selling advertising space does not.
When agreement is needed, the UK GDPR supplies the test it has to meet, and the bar is a real choice made by a deliberate act. Ruled out, then: pre-selected boxes, agreement bundled invisibly into acceptance of a contract, a wall whose only alternative is leaving, and scrolling construed as assent. Refusal has to be as easy to express as agreement, and a decision already given has to be as easy to take back.
4. Where this site stands today
Measurement scripts and advertising scripts are absent from these pages. No third-party tag manager runs here, no advertising pixel fires, and no signature is assembled from your device. What may appear is a pair of security values written by Cloudflare, which serves and shields the site. Since nothing optional is ever written, there is nothing for a permission banner to ask about, and putting one up would be theatre.
5. The two values Cloudflare may write
Whether either appears depends on how Cloudflare reads the request. Neither carries a profile, neither carries advertising data, and neither follows you onto anyone else's website.
| Name | Written by | What it achieves | Class | Lifespan |
|---|---|---|---|---|
__cf_bm | Cloudflare, first-party | Separates a person at a keyboard from automated traffic, so that abusive machinery can be held off the site | Strictly necessary, security | Roughly half an hour after the last request |
cf_clearance | Cloudflare, first-party | Remembers that a security challenge was already answered, so the challenge is not put to you again on the next page | Strictly necessary, security | Written only where a challenge occurred; from about half an hour up to a year, according to configuration |
For the security work these two values perform, Cloudflare acts on our instructions as processor. The technical record kept alongside them is itemised at section 6.7 of the Privacy Policy.
One outbound request deserves naming, although no cookie is involved. Two type families arrive from Google's font hosts, fonts.googleapis.com and fonts.gstatic.com. Fetching them hands your address and browser details to Google, which says it uses them to return the file and to keep aggregate counts. A note that counted only cookies would leave you with half the picture, which is why it appears here. Block those two hosts if you would rather not make the request; the pages then set themselves in a face already on your machine and lose nothing you came for.
6. Web storage and similar
The single script this site loads opens and closes the navigation on a narrow screen. It writes nothing to local storage, session storage, IndexedDB or the Cache API, and it keeps no record of your visit. Our messages carry no opening or click beacons.
7. Measurement
Nothing on this site counts you. There is no Google Analytics tag, no product-analytics kit, and no self-hosted counter either. Our whole picture of traffic comes from the summary charts Cloudflare produces while defending and delivering the site, which are aggregate figures and are never assembled into a portrait of an individual.
Were that to change, the sequence is fixed: choose a tool that respects the visitor, publish it in the table above while it is still switched off, and then ask permission through a banner whose refusal control is as prominent as its acceptance control. Counting visitors sits outside the strictly-necessary exemption in all but unusual configurations, and we would treat it as outside.
8. Advertising
Our income comes from software licences and commissioned work, never from attention. These pages carry no advertising, place no advertising value on your device, and take no part in bidding exchanges or advertising networks. The Transparency and Consent Framework is not implemented here. Personal data is never passed or sold to brokers or advertisers. Inside our applications there are no advertising kits and no advertising identifiers are read.
9. What we would do before adding anything optional
Should any non-essential storage ever be proposed, these commitments bind us. It stays switched off until you have agreed. The banner offers acceptance and refusal at equal weight, with nothing pre-selected. A footer control lets you revisit or revoke the decision afterwards. This page and its table are amended, with a fresh version number and date, ahead of the technology going live rather than after it. And the agreements themselves are recorded, so that we can show what was given and when.
10. Our products running on your website
Install one of our themes, kits or plugins and the resulting site is yours to answer for, including its cookie compliance, because you operate it. What our code does there is worth stating precisely:
- nothing we ship writes analytics, advertising or tracking values onto the devices of the people who visit you;
- a paid product keeps your licence key in your own WordPress options table, which is a database row and not a cookie;
- the periodic licence and update call travels from your server to ours and touches no visitor's device at all; its exact contents are itemised at section 7 of the Privacy Policy; and
- WordPress itself, together with whatever else you have installed — caching, comments, statistics, WooCommerce — writes according to its own rules. Those values are not ours to control and belong in the cookie notice you publish.
11. Inside our applications
An application is not a web page and reaches for no browser cookies. What it keeps is held on the handset: your own content, your settings, and an identifier unique to that installation, all described at section 19 of the Privacy Policy. No advertising kit is compiled in and no advertising identifier is read. Where an application opens somebody else's web page inside a panel, whatever that page stores is governed by whoever publishes it.
12. Taking control in your own browser
Every browser lets you inspect, remove and refuse stored values, for this site as much as any other. Turning away the two Cloudflare values may mean a security challenge is put to you more often than it otherwise would be; nothing else about the site changes.
| Browser | Route |
|---|---|
| Chrome, desktop | Open the ⋮ menu, then Settings, then Privacy and security. Third-party cookies holds the refusal switches; Delete browsing data clears what is already held. For this site alone, use the icon at the left of the address bar and choose Cookies and site data. |
| Safari, macOS | Safari, then Settings, then Privacy. Manage Website Data lists and removes; Block all cookies refuses everything. Intelligent Tracking Prevention is already running. |
| Firefox | Open the ☰ menu, then Settings, then Privacy & Security. Cookies and Site Data offers Manage Data and Clear Data; Enhanced Tracking Protection offers Standard, Strict or Custom. |
| Edge | From the … menu choose Settings, and inside it the entry for cookies and site permissions; the controls for managing and deleting sit there. Tracking prevention is separately set to Basic, Balanced or Strict. |
| iOS, Safari | Settings, then Apps, then Safari. Clear History and Website Data wipes everything; Advanced, then Website Data removes one site; Block All Cookies also lives under Advanced. |
| Android, Chrome | Open the ⋮ menu, then Settings, then Site settings, then Cookies and site data. Wiping is under Privacy and security, then Delete browsing data. |
A private or incognito window throws away everything it stored the moment you close it, which is the quickest way to visit without leaving anything behind. General guidance is maintained at aboutcookies.org. These routes shift between releases; if your menus disagree, the phrase to search for in your browser's own help is "manage cookies".
13. Two browser signals
Do Not Track was an attempt to let a browser state a preference against being followed. It never became a standard and most publishers disregard it. Here the question is academic, since there is no following to switch off, and your experience is identical whether the header is sent or not.
Global Privacy Control is the later attempt, and it registers an objection to personal data being sold or shared. Nothing here is sold or shared for advertising, so the signal finds nothing to alter. The principle behind it is one we accept: if optional storage is ever introduced, a browser that sends this signal will be treated as having objected, and none of it will be written for that browser whatever a banner may have collected.
14. Revisions, and how to reach us
Alter what this site writes and this page is altered with it, the version number and date at the top moving in step. Version 1.0 was published on 31 July 2026. Version 2.0, dated 5 August 2026, added the statutory framework, the position on web storage and outbound requests, the per-browser routes, and the treatment of the two browser signals above.
Questions, or a value you believe we have overlooked, go to team@themecanvas.uk. The Information Commissioner's Office also takes complaints, at ico.org.uk or 0303 123 1113.