AccessLedger

Cookies

Cookies and tracking

Policy version 2026-07-31. Operated by Access Ledger. The table below is generated from the same record the site checks before it loads anything, reconciled against what this server is actually configured to run, so the page cannot say one thing while the site does another.

The short version

This site sets two session cookies, which are strictly necessary and need no permission, and it uses Google Analytics 4 to count page views. Analytics is the only thing here that needs an answer from you, and there is nothing else: no advertising pixel, no remarketing tag, and nothing that follows you to other websites.

What you are getting right now

Analytics on, and you can switch it off You appear to be outside the EU, EEA, UK and Switzerland, where the law works on an opt-out basis, so analytics is running. Press the button below and it stops, on this site and on every visit from this browser.

Change your analytics choice

Where the rules differ

Article 5(3) of the EU ePrivacy Directive, the UK PECR that implements it, and the revised Swiss FADP all require permission before anything is stored on or read from your device unless that storage is strictly necessary. Our session cookies are strictly necessary. Google Analytics is not, so in the EU, the EEA, the UK and Switzerland it does not load until you say yes. If we cannot tell where you are, we apply the stricter rule.

Everywhere else, including the United States and Canada, the ordinary position is opt-out, so analytics runs and you can turn it off. Once you turn it off we honour that everywhere, because an answer freely given is an answer.

Every category, and whether it is live

Cookie and tracking categories used by AccessLedger
Category In use today Purpose Legal basis Retention
Strictly necessary Yes, active
since
Keeps you signed in and protects forms against cross-site request forgery. Without it the site cannot tell one request from another and nobody can sign in. Not consent. Legitimate interest under GDPR Art. 6(1)(f), and exempt from the consent requirement under Art. 5(3) of the ePrivacy Directive because the storage is strictly necessary to provide the service you asked for. Customer session 30 days, administrator session 7 days. Expired rows are pruned by the maintenance job.
Marketing email Yes, with your consent
since
Sends occasional guidance on keeping a site accessible to people who asked for it. Consent under GDPR Art. 6(1)(a). Withdrawable at any time, one click, no sign-in needed. Until consent is withdrawn or erasure is requested.
Analytics and measurement Yes, with your consent
since
Google Analytics 4, used to count visits and see which pages are read so we know what to write next. Consent, and only consent. Art. 5(3) of the ePrivacy Directive and the UK PECR require the answer before anything is stored on or read from the device, so nothing loads until a visitor opts in. Declining, or not answering, means no analytics request is made at all. Cookies set by Google Analytics expire after up to two years. Event data is held inside Google Analytics for the period set on the property, and that setting lives in Google rather than in this database.
Advertising and remarketing No, not in use Would allow advertising platforms to recognise a visitor across sites in order to target advertising. Would require prior opt-in consent in the EU and UK. Under the CPRA it would also constitute "sharing" for cross-context behavioural advertising, which requires a Do Not Sell or Share My Personal Information link. Would be stated here before any such tool is switched on.

Strictly necessary. al_session for customers and al_admin for administrators, both holding a random token and neither readable by script. A CSRF token derived from the session. And al_consent, which records the analytics answer itself: it is readable by script on purpose, because the client-side loader re-checks it before running anything.

Marketing email. Not a cookie. Recorded here because it is consent and belongs in the same audit trail.

Analytics and measurement. IN USE, opt-in only. Loaded by src/web/analytics.ts from googletagmanager.com, and the Content-Security-Policy is widened for Google hosts only for a visitor who has consented. Data is processed by Google in the United States.

Advertising and remarketing. NOT IN USE. No advertising or remarketing pixel exists in this codebase.

The cookies themselves

Every cookie this site can set, and when
Name Set when What it does How long Readable by script
al_session You sign in to a customer account Holds a random token identifying your session. The token means nothing on its own; the session itself lives in our database, so signing out ends it server side immediately. The token also derives the CSRF protection on our forms, so there is no separate CSRF cookie. 30 days, or until you sign out No. httpOnly and SameSite=Lax.
al_admin An administrator signs in The same thing for our own staff. Never set for a customer. 7 days, or until sign out No. httpOnly and SameSite=Lax.
al_consent You answer the analytics question Records your answer as analytics=1 or analytics=0 and nothing else. No identifier, no profile. It is strictly necessary in the sense that matters: without it we cannot honour the choice you made. 6 months, then we ask again Yes, on purpose. The loader re-checks it in the browser before running anything, and a choice the page cannot read is a choice the page cannot honour.
_ga, _ga_<id> Only once analytics is running for you Set by Google Analytics to give your browser a random identifier so repeat visits are counted as one visitor rather than several. Up to 2 years, set by Google Yes. They are Google's cookies, not ours. Google may set others; the current list is in Google's own documentation.

Check it yourself

You do not have to take our word for any of this. Decline analytics, then open your browser developer tools and look at the network and storage panels on any page here. You will see no third-party request and no third-party cookie, because with analytics declined the site keeps its original Content-Security-Policy of script-src 'self' and the browser would refuse to load anything from another domain even if we tried.

Accept, and you should see requests to googletagmanager.com and google-analytics.com and nothing else. If you ever see a third domain we have not named on this page, tell us, because that would be a bug and we would want to know.

Google Analytics, honestly

Google Analytics processes data on Google infrastructure, which includes servers in the United States. Between 2022 and 2023 data protection authorities in Austria, France, Italy and Denmark all found particular uses of it unlawful, largely on the grounds of those transfers. The EU-US Data Privacy Framework has changed the picture since and Google now offers EU-based collection and IP handling controls, but the question is still contested and the Framework itself is under legal challenge.

That is why it is opt-in wherever the law says it must be, and why nothing loads before you answer. If you would rather not be counted, decline. It costs you nothing and the site works identically.

We do not enable Google Analytics advertising features or Google Signals, and analytics data is not linked to any advertising account. Those are settings inside the Google Analytics property rather than anything in our code, which is a limit on how far we can demonstrate it to you from this side. If that ever changed it would amount to sharing under the California CPRA, and we would publish a Do Not Sell or Share My Personal Information link before switching it on rather than after.

Marketing email

Marketing email is consent too, and it is recorded in the same audit trail as your analytics answer, but it is not a cookie. Every marketing message carries a one click unsubscribe link that needs no sign-in. If you have an account you can also switch it on or off from your data page.

Advertising

Not in use, as the table above shows. If an advertising or remarketing tag is ever introduced it will appear there with an activation date, it will be described in the privacy policy, it will be opt-in in the EU and UK, and the California Do Not Sell or Share link would go up first. This paragraph is a description of how we would do it, not permission to do it.

Not legal advice

We are not lawyers and this page is not legal advice. It is a plain description of what our own code does, written by the people who wrote the code. If you are relying on it for your own compliance, have your own adviser look at it.

Contact

[email protected]