Skip to main content
The Revenue House
Legal

Cookie Policy

Version 3.0 · Tabled 15 August 2026 · Supersedes the edition of 5 August 2026 · Governs https://therevenuehouse.uk and storage placed on your device by applications published by THE REVENUE HOUSE LIMITED.

To
Anyone who opens a page on this site, and anyone running an application we publish.
From
THE REVENUE HOUSE LIMITED, Company No. NI740029, registered in Northern Ireland.
Subject
Precisely what gets placed on your device, or read back off it, in the course of dealing with us — and the legal footing for each.
Standing
The disclosure owed under the Privacy and Electronic Communications Regulations 2003 (PECR), regulation 6, read together with the standard the UK GDPR sets for consent.
Ranking
Where storage also involves personal data, our Privacy Policy governs that handling. Our Terms of Use sit alongside both.

Item 01 The short answer, for readers in a hurry

The position

No cookie on this site originates with us. Nothing here measures you, profiles you or advertises to you. There is no tag manager, no social widget, no embedded video, no tracking pixel, and no browser storage written by our own code.

What this means in practice

Two cookies may appear, both placed by Cloudflare, the security and delivery layer in front of this site, and both there to tell a person apart from an automated request. Because they are strictly necessary to deliver the page you asked for, the law does not require your consent for them, which is why you are not asked for it. Item 04 names them individually.

One outbound request deserves flagging, since anyone inspecting the network tab will find it: our lettering is served from Google's font infrastructure, so returning those files puts your browser's request in front of Google. Item 04 sets out what that involves and what we intend to do about it.

Action owed to the reader

You can stop reading here and lose nothing. The remaining items exist for readers who want the mechanism rather than the summary.

Item 02 Cookies, and everything the law treats alongside them

The position

A cookie is a short string handed to your browser for safekeeping and returned automatically on subsequent visits. The distinctions that follow are not pedantry — each one decides which rule bites.

What this means in practice

  • Whose domain sets it. A first-party cookie comes from the site in your address bar. A third-party cookie arrives from a different domain whose material the page has loaded, which is the everyday machinery behind advertising that trails people from site to site.
  • How long it lasts. A session cookie disappears when the browser closes. A persistent one survives until it expires or you clear it.
  • Whether it is necessary. A strictly necessary cookie delivers something you actually asked for — security, load balancing, staying signed in. Everything else, measurement and personalisation and advertising included, is non-essential, and the difference decides whether consent is needed.

The law does not stop at cookies. It reaches anything that writes to, or reads from, your device, and treats all of it the same way:

  • Local and session storage — browser-side stores a site can write to, holding rather more than a cookie and not attached to every request.
  • Pixels and beacons — a minute graphic, or a snippet of script, planted in a page or a message and reporting home the instant it renders.
  • Fingerprinting — assembling a stable identifier out of your browser and device characteristics instead of storing one, which is no less tracking for leaving nothing behind.
  • Application storage and embedded kits — the mobile equivalents, covered at item 08.

Action owed to the reader

Judge any site, ours included, on the whole of that list rather than on its cookie banner. A site with no cookies and a fingerprinting script is tracking you more thoroughly than one with three cookies and none.

Item 04 Everything present on this site

The position

The table below is the complete inventory. Where something is not in it, it is not here.

What this means in practice

Complete inventory of storage on therevenuehouse.uk
NamePlaced byPurposeKindLifetime
__cf_bm Cloudflare, Inc., acting as our hosting and security provider Telling a human reader apart from machine traffic, so that harvesting, credential abuse and flooding attempts can be held off HTTP cookie · strictly necessary Roughly half an hour from your most recent request
cf_clearance Cloudflare, Inc. Noting that your browser cleared a security challenge, sparing you the same challenge on every page. It appears solely where such a challenge was raised, which most readers never encounter HTTP cookie · strictly necessary The challenge validity period configured for this site, and in practice well short of its maximum
— THE REVENUE HOUSE LIMITED No cookie is placed by us. This site has no accounts, no forms, no basket and no preference switches, so there is nothing about you for it to carry between pages — —
— THE REVENUE HOUSE LIMITED Neither local nor session storage is used. The single script on the site opens the navigation on a small screen, draws the hairline under the masthead once the page has scrolled, and keeps the footer year current. None of that writes anything to your device — —
— Any third party Measurement, advertising, tag management, social widgets, embedded video and split testing are absent from this site in every form — —

The two Cloudflare cookies serve no measurement or advertising purpose, do not identify you to us by name, and are not joined to anything else we hold. The handling of your network address and request record that goes alongside them is described at item 05 of the Privacy Policy.

The font request. Our lettering arrives from Google's font infrastructure rather than from our own server. That means your browser makes a request to a Google-operated domain, and in the course of returning the files Google receives your network address and browser string. No cookie is placed on this site by that request, and nothing about it reaches us or is used by us for any purpose. Serving those files from our own infrastructure, so that the request disappears entirely, is under review, and this memorandum will record the change if we make it.

Action owed to the reader

Open your browser's storage inspector on this page and check the table against what you find. Where the two disagree, tell us — the inventory is meant to be verifiable, not taken on trust.

Item 05 Measurement and advertising: the decision we took

The position

Running measurement here was considered and rejected. We would have learned a little about which pages get read; you would have paid for that with a consent decision on arrival and a record of your visit sitting with a third party. For a small site whose whole job is to explain what we do and invite an email, that exchange is not worth making.

What this means in practice

Advertising technology is absent in every form: no networks, no conversion pixels, no remarketing tags, no audience lists, no data-broker connections and no identifiers shared across sites. Data about readers is neither sold nor shared, and it is never enriched or appended to.

Some traffic information reaches us regardless, because a page cannot be served without the request arriving. Cloudflare produces aggregate counts of requests, bandwidth and blocked threats, carrying no identification of any individual. That is a by-product of hosting rather than a measurement product, it places nothing on your device, and it is not used to assemble a picture of anybody.

Action owed to the reader

Where this decision is ever reversed, item 07 governs how it happens, and you will meet the consent request before you meet the technology.

Item 06 Why no consent banner appears

The position

Everything present here qualifies as strictly necessary under the regulation 6(4) exemption, which means the law asks for no consent to it. A banner asking for permission we do not need would be posing a question with no meaning behind it.

What this means in practice

There is a second reason, and it is the one we care about more. A consent banner on a site that does not track anybody teaches readers to dismiss banners without reading them, which degrades the value of consent on every site they visit afterwards. Adding one here would buy us the appearance of compliance at everybody else's expense.

What the law does require for strictly necessary storage is clear information, and this memorandum is that information. Should the position ever change, the request arrives before the technology does, as item 07 sets out.

Action owed to the reader

Take the absence of a banner here as a claim you are entitled to test, using item 04 and your own browser, rather than as something you have to believe.

Item 07 What would happen before anything non-essential arrived

The position

Should we ever decide to introduce measurement, or any other non-essential storage, five commitments bind us and every one of them is discharged before the technology goes anywhere near this site.

What this means in practice

  • A consent mechanism that holds the technology back until you opt in, with refusal presented as prominently as acceptance, and with no pre-ticked boxes and no consent inferred from your behaviour.
  • A route to withdraw that is no harder than the route to give, honoured by removing the technology and, so far as we are able, whatever storage it created.
  • The inventory at item 04 updated with the name, provider, purpose, kind and lifetime of every new entry, and the Privacy Policy updated wherever personal data is involved.
  • The version number and date at the head of this memorandum revised.
  • The site kept entirely functional for anyone who declines. No feature will ever be withheld as the price of consent.

Action owed to the reader

Hold this item up against whatever we do next. It is written to be quoted back at us.

Item 08 Storage inside our applications

The position

A mobile application uses no browser cookies, but it certainly writes to your device, and regulation 6 reaches that storage exactly as it reaches a cookie.

What this means in practice

Three things are written to the device: your content and settings, so that the product works with no connection; an authentication token, so that you are not signed out between sessions; and a random per-installation reference used for grouping failure reports and for support. All three are strictly necessary to provide the product you asked for, and none of them is an advertising identifier.

Where an application includes optional feature counters, and recording them means storing or reading anything on your device beyond what is strictly necessary, we ask inside the product before switching them on, and the choice can be changed at any point from the privacy settings. Declining costs no feature. Our applications carry no advertising kits, never read the iOS Identifier for Advertisers or the Android Advertising ID, and present no App Tracking Transparency prompt, because there is nothing there to track. Item 24 of the Privacy Policy carries the full detail, including our Data Safety and privacy label position.

Action owed to the reader

Every optional item above can be switched off from inside the product, and nothing you rely on stops working when you do.

Item 09 Managing all of this from your browser

The position

Cookies are yours to inspect, block and clear whenever you like. Blocking the Cloudflare cookies is entirely permitted and this site continues to work, though you may meet a security challenge rather more often than you otherwise would.

What this means in practice

Where the controls live, by browser
BrowserRoute
Chrome on desktop⋮ › Settings › Privacy and security › Third-party cookies. To clear what is already stored, ⋮ › Settings › Delete browsing data. Controls for one site alone sit behind the icon at the left of the address bar.
Safari on macOSSafari › Settings › Privacy, where cookies may be blocked outright and stored website data cleared. The cross-site tracking defence ships switched on.
Firefox☰ › Settings › Privacy & Security. Enhanced Tracking Protection offers Standard, Strict and Custom modes; the Cookies and Site Data panel clears storage or records exceptions.
Edge⋯ › Settings › Cookies and site permissions › Manage and delete cookies. Tracking prevention lives one panel away, under Privacy, search and services.
Safari on iPhone or iPadSettings › Apps › Safari, which carries both Block All Cookies and Clear History and Website Data.
Chrome on Android⋮ › Settings › Site settings › Third-party cookies. Stored data clears from ⋮ › Settings › Delete browsing data.

Menu wording shifts between versions, so your browser's own help pages will be more current than any table. Most browsers also offer a private window, whose cookies and storage are thrown away as soon as it shuts. Blocking cookies across the board will affect other sites that depend on them for signing in and for baskets.

Action owed to the reader

Nothing on this site penalises you for blocking anything. Where you find that it does, that is a defect on our side and we would like to know.

Item 10 Two browser signals, and why neither alters anything

The position

Two browser signals exist for telling a site to leave you alone. Neither changes anything here, and the honest reason is that there is nothing running for either of them to switch off.

What this means in practice

Do Not Track was a header a browser could send asking sites not to follow the reader. It never became a standard, no UK law obliges a site to honour it, and most browsers have withdrawn the setting. We take no action on it, though indifference is not the reason: nothing here follows anybody, so the signal finds no target.

Global Privacy Control is a newer signal, registering an objection to personal data being traded on and, in certain jurisdictions, to advertising aimed by profile. Since nothing is traded on here and no advertising is aimed at anybody, the signal alters none of this site's behaviour; the activity it asks us to halt was never running. Were non-essential storage ever introduced under item 07, we would treat an incoming signal as a valid objection and place nothing non-essential for that reader.

Action owed to the reader

Keep sending both signals. They cost you nothing here and they matter a great deal on sites that do have something to switch off.

Item 11 Revisions to this memorandum

The position

This memorandum is reviewed at least annually, and additionally whenever the technology on the site or inside an application changes. The edition in force always sits at this address carrying its number and date.

What this means in practice

Where a revision introduces a new cookie or a new storage item, the inventory at item 04 is updated before the item is deployed, and item 07 governs how permission is obtained for anything non-essential.

Version record. Version 1.0, 31 July 2026, first publication. Version 2.0, 5 August 2026, adding the wider technologies covered, the legal framework, a complete inventory, the font disclosure, our position on measurement and advertising, application storage, per-browser routes and the position on both browser signals. Version 3.0, 15 August 2026, recasting the whole document as a numbered memorandum and stating for each item the action owed to the reader.

Action owed to the reader

We keep earlier editions and will send one over, so that what this page said on the day you visited is establishable rather than lost.

Item 12 Where to put a question

The position

Put questions about this memorandum — or about anything your browser turns up after a visit here — to enquiries@therevenuehouse.uk.

What this means in practice

A person reads that address and replies within one business day. A question about what a particular cookie does will be answered specifically rather than with a link back to this page.

Action owed to the reader

The Privacy Policy covers the personal data sitting alongside this storage, and the Terms of Use govern everything else about dealing with us.

Return to the head of the memorandum ↑