Cookies notice
Last updated: 10 May 2026.
This notice explains how borderkit.app uses cookies and similar
device-storage technologies. It complements the
privacy notice.
Summary
The public website sets only strictly-necessary cookies. It does not set advertising cookies, analytics cookies, or any cross-site tracking technology. Because no non-essential storage access takes place, no consent banner is required under the Privacy and Electronic Communications Regulations (PECR) Regulation 6(4) strictly-necessary carve-out.
Cookie categories used
Strictly-necessary cookies. These are required for the site to function and are exempt from consent under PECR Regulation 6(4). At the time of writing, the only strictly-necessary cookies that may be set are those used by the hosting platform's runtime for routing, load balancing, and security headers. None of these cookies identify you as an individual, profile your behaviour, or persist across sessions for tracking purposes.
If the site ever sets a strictly-necessary cookie that you can see in your browser, you can inspect it via your browser's developer tools. The list of strictly-necessary cookies is audited before every site deploy.
What we do not use
We do not set, and do not allow third parties to set, any of the
following on the borderkit.app origin:
- advertising cookies of any kind;
- analytics cookies (no Google Analytics, no Plausible cookie, no Umami cookie, no equivalent);
- cross-site tracking cookies or pixels (no Facebook Pixel, no LinkedIn Insight, no Google Ads remarketing tag);
- A/B testing or session-replay cookies;
- chat-widget cookies;
- fingerprinting libraries;
- third-party iframe cookies (we do not embed YouTube without
youtube-nocookie.com, Vimeo withoutdnt=1, or any equivalent cookie-setting embed).
We also do not write to localStorage, sessionStorage, IndexedDB, or
any Service Worker storage for analytics or tracking purposes. PECR
Regulation 6 applies to all device-storage access, not only cookies, and
our compliance posture covers all of it.
Server-side analytics
If, in the future, the site uses server-aggregated cookieless analytics to understand traffic patterns, the chosen processor will be one that:
- does not access device storage;
- does not set cookies on this origin;
- does not identify individual visitors;
- offers a UK GDPR Article 28 data processor agreement.
If those constraints are not met, the analytics integration is not adopted, and a Consent Management Platform (CMP) is added first. At the time of writing, no analytics processor is engaged.
What triggers a consent banner
A consent banner becomes mandatory on this site if any of the following ever ship:
- a tool that sets a non-strictly-necessary cookie;
- a tool that writes to
localStorage,sessionStorage,IndexedDB, or Service Worker storage for analytics or tracking purposes; - a fingerprinting library or vendor;
- a cross-site tracker;
- a chat widget, A/B testing tool, or session-replay tool that sets storage;
- any third-party iframe that sets cookies on this origin.
If any of those ship in the future, a Consent Management Platform will be added that presents Accept and Reject with equal prominence (per ICO 2019 guidance), defaults to no non-essential storage until an affirmative action is taken, and provides one-click withdrawal at any time. This notice will be updated and the change-history section below will record the date of change.
Change history
| Date | Change | | :--------- | :---------------------------------------------------- | | 2026-05-10 | Initial publication. Strictly-necessary cookies only. |
Further information
For broader information about how we handle personal data — including the legal bases, your rights under the UK GDPR, and how to contact us — see the privacy notice.