Legal
The short version
This summary is a courtesy, not the contract. The numbered terms below are what governs.
1.1This is the complete list. There is nothing else stored in your browser by this site.
| Name | Type | Purpose | Duration | Party |
|---|---|---|---|---|
| authjs.session-token | Cookie | Keeps you signed in | 30 days | First-party |
1.2Nothing else appears in this table because nothing else exists — no analytics identifier, no advertising cookie, no third-party script. §3 explains how we still manage to count page visits without one.
2.1When you sign in, we set a session cookie (named authjs.session-token, or __Secure-authjs.session-token when served over HTTPS) so you don't have to log in again on every page. It lasts 30 days, or until you sign out.
2.2This is strictly necessary — the site can't keep you signed in without it — so it doesn't need your consent and there's no toggle for it. It doesn't track you across other websites.
3.1The cookie rules (UK PECR, regulation 6) are about storing or reading information on your device — a cookie, a localStorage entry, anything left behind in your browser. We don't do that for analytics at all. When you view a page, nothing is written to your device and nothing is read back from it on your next visit.
3.2Instead, our own server counts the visit using only what's already in the request: it takes your IP address and browser type, combines them with the day's date, and runs the result through a one-way salted hash. That hash is stable for the rest of that day — enough to tell "one visitor viewed three pages today" from "three different visitors viewed one page each" — and it cannot be linked to the same visitor tomorrow, because tomorrow's date changes the hash completely. The raw IP address itself is never written to our database; only the hash is, and only for that day.
3.3If your browser sends a Global Privacy Control or Do Not Track signal, we honour it automatically: the page view is still counted in that day's total, but no hash is attached to it at all, so it can't even be grouped with your other visits that day. There's nothing for you to switch on — if your browser or an extension sends the signal, it's already working.
3.4Because nothing is stored or accessed on your device, this doesn't engage regulation 6 and doesn't need a consent banner — not because we decided an exception applied, but because there's nothing here for the rule to apply to.
4.1No advertising cookies, no third-party tracking pixels (Meta, Google Ads, TikTok or otherwise), no social-media embeds that track you, and no cross-site tracking of any kind. If that ever changes, a proper consent banner — asking before anything is set, with "reject" as easy to choose as "accept" — becomes mandatory, and we'll build one before we add anything that needs it.
5.1There's no opt-out toggle on this page, and there doesn't need to be one — a toggle would itself have to store your choice somewhere on your device, which is exactly the kind of thing we're not doing. Your browser's Global Privacy Control or Do Not Track setting is honoured automatically, with no action needed from you (see §3.3).
5.2If you'd like to object in any other way, or have a question about how visit-counting works, email info@policystack.co.uk and we'll deal with it directly.
6.1If what we store or why changes, we'll update this page with a new date and version number.
6.2Version history: 1.1 — 29/08/2026 — rewritten to describe server-side, device-free visit counting; the earlier browser-stored visitor id and opt-out toggle were removed from the product, not just this page. 1.0 — 29/08/2026 — first published version.
PolicyStack is a trading name of ELITE4U LTD, registered in England and Wales, company number 14657268.
Registered office: Office 7775, 321-323 High Road, Romford, England, RM6 6AX
Contact: info@policystack.co.uk