Cookie Policy
This Cookie Policy explains what cookies and similar technologies we use on nextbasket.com, what they do, and the choices you have. It should be read together with our Privacy Policy.
Effective date: 23 July 2026
Document version: Version 1.0 — effective 23 July 2026
1. What cookies are
Cookies are small text files stored on your device when you visit a website. Similar technologies (such as local storage and scripts loaded from another domain) can serve comparable purposes. We use them to keep the site secure and to make it work — not to advertise to you or track you across other sites.
2. Our approach — no non-essential cookies
- Strictly necessary and security technologies (provided by Cloudflare) are used without consent, because the site cannot function safely without them.
- Our analytics (Google Analytics 4) runs in a cookieless mode: it is configured to store nothing on your device, sets no analytics cookies, anonymizes your IP, and has all advertising features disabled. It is environment-gated and off by default, and only runs when analytics is enabled for the production build.
- We do not use advertising, ad-personalization, or cross-site tracking cookies.
- Because we set no non-essential cookies, this site does not display a cookie-consent banner. If that ever changes (for example, if a third-party technology begins storing or reading information on your device), we will introduce an appropriate consent mechanism.
No consent management platform (CMP) or cookie banner is required while this site uses only strictly necessary security storage and truly cookieless analytics with no advertising features. We would introduce a CMP if we ever added any of the following: a non-essential cookie or local-storage item, advertising or personalisation, cross-site tracking, a persistent analytics identifier, or a third-party embed that reads or writes information on your device.
3. Cookies and similar technologies we use
Technologies on this site
| Category | Set by | Purpose | Cookie / storage | Name(s) and duration |
|---|---|---|---|---|
| Strictly necessary / security | Cloudflare (our CDN and edge) | Protect the site, mitigate bots and abuse, and route traffic | Cookie | May appear: __cf_bm — bot-management cookie that expires after 30 minutes of inactivity |
| Strictly necessary / security (conditional) | Cloudflare | Verify a visitor after a security challenge or Turnstile pre-clearance | Cookie | May appear only when you pass a challenge, or when Turnstile pre-clearance is enabled: cf_clearance — its lifetime equals the configured Challenge Passage |
| Strictly necessary / security (conditional) | Cloudflare | Apply rate-limiting protections | Cookie | May appear only when the relevant rate-limiting rule is enabled: _cfuvid |
| Strictly necessary / security (conditional) | Cloudflare | Diagnose and complete a security challenge | Cookie | Short-lived challenge diagnostic cookies may appear only during a challenge |
| Anti-bot challenge (forms) | Cloudflare Turnstile | Verify that a human is submitting a form, on the contact and demo-request pages | Token | Normally a one-time token rather than a cookie |
| Analytics (cookieless, when enabled) | Google Analytics 4 | Measure page views and usage to improve the site — no cookies, no device storage, IP anonymized, ad features off | No cookie (cookieless pings) | None set — client_storage disabled; active only when analytics is enabled in the production build |
| Functional | This site | Fonts are self-hosted, so no third-party font cookie is set | None | No third-party font cookie |
Several of the Cloudflare cookies above are conditional: they are set only in specific situations — when you pass a security challenge, when Turnstile pre-clearance is enabled, or when a rate-limiting rule applies — so most visits set none of them. Before each release we attach a current live cookie scan and remove from this list any cookie that is not actually observed or configured in production.
4. US privacy choices (CCPA "Do Not Sell or Share")
US law does not require an opt-in cookie banner. The main US control is the right to opt out of the "sale" or "sharing" of personal information under the California CCPA and similar state laws. Because this site sets no advertising or cross-site tracking cookies and runs no cross-context behavioral advertising, no such "sale" or "sharing" occurs through cookies here.
You can exercise your privacy choices at any time — see the "Your Privacy Choices" section of our Privacy Policy for how to do this. Because this site does not sell or share your personal information and does not use targeted advertising, there is nothing to opt out of through a browser signal, and we do not claim to detect or honor Global Privacy Control (GPC) signals. If our practices ever change, we will implement and test GPC or universal opt-out detection before deployment.
5. How to manage cookies
You can control and delete cookies through your browser settings, and set your browser to warn you before storing them. Blocking strictly necessary cookies may stop parts of the site — such as form submission — from working. Because this site sets no advertising or cross-site tracking cookies, there is nothing here for a browser-level Global Privacy Control (GPC) signal to opt out of; see our Privacy Policy for your privacy choices.
6. Third-party providers
Some technologies are provided by third parties who process the related data under their own policies. The main ones are Cloudflare (security, edge, and Turnstile) and, when analytics is enabled, Google (Analytics 4, in cookieless mode). See our Privacy Policy for the full list of providers and international-transfer safeguards.
7. Changes to this policy
We may update this Cookie Policy as our site changes. The effective date above will be updated when we do. Questions? Email office@nextbasket.com.