Skip to content
Pathfinder Labs Corporation
Legal

Cookie Notice

Effective date: 7 August 2026. Version 1.0. This is the first published version of this notice.

1. The short version

pathfinderlabs.co.uk is a static website. It has no accounts, no forms, no shopping basket and no analytics. We set no cookies of our own, and we run no tracking of any kind. The only cookies that may appear are security cookies set by Cloudflare, which serves the site, and they only appear when Cloudflare’s protection is actually doing something. There is no consent banner because there is nothing here that requires consent.

One thing does leave this site: the two font files come from Google’s font servers, which means your browser makes a request to Google. Section 6 explains exactly what that involves, because it would be dishonest to publish a page claiming zero third parties while quietly loading fonts from one.

2. What counts as a cookie here

A cookie is a small text file that a website asks your browser to store and send back on later requests. The law that applies in the United Kingdom is the Privacy and Electronic Communications (EC Directive) Regulations 2003, usually called PECR, and it covers more than cookies: it covers any storage of information on, or access to information already stored on, your device. That includes local storage, session storage, pixels and device fingerprinting.

Regulation 6 of PECR says that storage or access of that kind needs your consent, unless it is strictly necessary for a service you have expressly requested, or is done solely to transmit a communication. This notice uses that test throughout rather than a marketing definition of “essential”.

3. Cookies we set: none

THE PATHFINDER LABS CORPORATION LIMITED sets no cookies on this website. There is no server of ours involved in serving a page to you, because the site is a set of static files. There is no session, nothing to remember about you between pages, and no preference to store. If you inspect the site and find a cookie whose name we have not listed in section 4, we would genuinely like to know: write to hello@pathfinderlabs.co.uk and we will investigate and correct this page.

4. Cookies our host may set

The site is served by Cloudflare Pages. Cloudflare sits between your browser and the files, and it protects the site from automated abuse. When that protection engages, Cloudflare may set one of the cookies below. We do not read these cookies, we cannot associate them with a person, and we do not receive their values.

The table below scrolls sideways.

Cookies that may be set by the hosting provider
NameSet byPurposeWhen it appearsTypical lifetimeConsent needed
__cf_bm Cloudflare, Inc. Bot management. It helps Cloudflare tell an ordinary browser apart from an automated client during a period of suspicious traffic. Only when Cloudflare’s bot management is engaged for a request. Many visits will not receive it. 30 minutes from the last request No. Strictly necessary for security under regulation 6(4) of PECR.
cf_clearance Cloudflare, Inc. Records that a security challenge has been passed, so that you are not challenged again on every page. Only if you were shown a challenge page and completed it. Set by the challenge configuration, commonly 30 minutes and at most one year No. Strictly necessary for security under regulation 6(4) of PECR.
_cfuvid Cloudflare, Inc. Distinguishes requests from different clients that share an IP address, so that rate limiting applies to the right one. Only where rate limiting rules are applied. Session, deleted when you close the browser No. Strictly necessary for security under regulation 6(4) of PECR.

None of these is an analytics or advertising cookie, none builds a profile of you, and none is used to serve you content. Cloudflare acts as our processor for this activity, and the connection data it handles is described in section 4 of the Privacy Policy.

5. Why there is no consent banner

A consent banner is required when a site stores or reads something on your device that is not strictly necessary. This site does not. Everything in section 4 falls inside the strictly necessary security exemption in regulation 6(4) of PECR, and there is nothing else.

We could have installed analytics, put a banner up, and let most people click Accept. We would rather not know how many people read the site than ask you to agree to being counted. If we ever do add anything that needs consent, a compliant banner will appear, it will have a Reject button as prominent as the Accept button, nothing non-essential will run before you choose, and this page will be rewritten before the change goes live rather than after.

6. The one third party request this site makes

The typefaces used here, Bricolage Grotesque and Figtree, are loaded from Google Fonts. That means your browser requests a stylesheet from fonts.googleapis.com and font files from fonts.gstatic.com. In making those requests your browser sends the information any web request carries: your IP address, your user agent string, and the fact that a font used by this site was requested.

Google states that it does not set cookies on requests to fonts.gstatic.com, and we have found none in testing. Even so, the request itself involves a transfer of your IP address to Google, so we tell you about it rather than describing this site as third party free.

If you would rather not make that request, blocking fonts.googleapis.com and fonts.gstatic.com in your browser or with an extension will not break this site. The pages are readable in your system typefaces, the layout holds, and nothing is hidden behind the web fonts. We are considering self hosting the two font files to remove the request entirely: [TO CONFIRM: decision on self hosting the fonts, and the date it is made]

7. Local storage and other client side storage

This site writes nothing to local storage or session storage. It uses no IndexedDB, no service worker, no cache manifest of its own beyond ordinary HTTP caching of the files, and no fingerprinting. The one small script on the site, waypoint.js, opens and closes the navigation menu on small screens and makes wide tables reachable with a keyboard. It stores nothing and sends nothing anywhere.

8. What this site definitely does not use

  • No analytics of any kind, including Google Analytics, Plausible, Fathom, Matomo, or Cloudflare Web Analytics.
  • No advertising or retargeting pixels, including the Meta pixel, LinkedIn Insight Tag, X pixel and Google Ads tags.
  • No social media embeds, share buttons, comment systems or like buttons.
  • No chat widget, session recording, heat mapping or A/B testing tool.
  • No customer relationship management tracking, no lead identification or IP to company lookup service, and no email open tracking.
  • No content delivery network beyond the one serving the site itself, and no third party image, video or map embeds.

This list is deliberately specific. A general statement that we “respect your privacy” would be worth nothing, whereas a named list can be checked with the network tab of your own browser in about a minute, and we would encourage you to do exactly that.

9. How to control cookies yourself

You can block or delete cookies in your browser settings, and you can do that regardless of what any website tells you. Blocking the security cookies in section 4 may mean you are challenged more often by Cloudflare, but it will not stop you reading this site.

  • Safari: Settings or Preferences, then Privacy.
  • Chrome: Settings, Privacy and security, then Third party cookies and Site settings.
  • Firefox: Settings, Privacy and Security, then Cookies and Site Data.
  • Edge: Settings, Cookies and site permissions.

Browser controls change with each release, so if the path above no longer matches what you see, search your browser’s own help for “cookies”. Your browser’s Do Not Track or Global Privacy Control signal makes no difference here, because there is nothing to switch off.

10. Applications we may publish

We have published no mobile or desktop application at the effective date of this notice. If we publish one, it will not contain an advertising software development kit, a third party analytics kit, or any tracker that follows you across other companies’ apps and websites. The position on the iOS App Tracking Transparency prompt, and the permissions an application would request, are set out in section 20 of the Privacy Policy, and this notice will be updated at the same time as that section.

11. Changes, and how to contact us

If what this site sets ever changes, this notice changes first and the effective date at the top moves with it. We will not add something and document it later.

Questions about this notice, or a report that something on the site is setting a cookie we have not listed, go to hello@pathfinderlabs.co.uk. We reply within two working days. If you are not satisfied with our answer, you can complain to the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, telephone 0303 123 1113.