Skip to main content

Cookie Policy

This Cookie Policy explains what cookies and similar technologies we use on nextbasket.com, what they do, and the choices you have. It should be read together with our Privacy Policy.

Effective date: 23 July 2026

Document version: Version 1.0 — effective 23 July 2026

1. What cookies are

Cookies are small text files stored on your device when you visit a website. Similar technologies (such as local storage and scripts loaded from another domain) can serve comparable purposes. We use them to keep the site secure and to make it work — not to advertise to you or track you across other sites.

2. Our approach — no non-essential cookies

  • Strictly necessary and security technologies (provided by Cloudflare) are used without consent, because the site cannot function safely without them.
  • Our analytics (Google Analytics 4) runs in a cookieless mode: it is configured to store nothing on your device, sets no analytics cookies, anonymizes your IP, and has all advertising features disabled. It is environment-gated and off by default, and only runs when analytics is enabled for the production build.
  • We do not use advertising, ad-personalization, or cross-site tracking cookies.
  • Because we set no non-essential cookies, this site does not display a cookie-consent banner. If that ever changes (for example, if a third-party technology begins storing or reading information on your device), we will introduce an appropriate consent mechanism.

No consent management platform (CMP) or cookie banner is required while this site uses only strictly necessary security storage and truly cookieless analytics with no advertising features. We would introduce a CMP if we ever added any of the following: a non-essential cookie or local-storage item, advertising or personalisation, cross-site tracking, a persistent analytics identifier, or a third-party embed that reads or writes information on your device.

3. Cookies and similar technologies we use

Technologies on this site

CategorySet byPurposeCookie / storageName(s) and duration
Strictly necessary / securityCloudflare (our CDN and edge)Protect the site, mitigate bots and abuse, and route trafficCookieMay appear: __cf_bm — bot-management cookie that expires after 30 minutes of inactivity
Strictly necessary / security (conditional)CloudflareVerify a visitor after a security challenge or Turnstile pre-clearanceCookieMay appear only when you pass a challenge, or when Turnstile pre-clearance is enabled: cf_clearance — its lifetime equals the configured Challenge Passage
Strictly necessary / security (conditional)CloudflareApply rate-limiting protectionsCookieMay appear only when the relevant rate-limiting rule is enabled: _cfuvid
Strictly necessary / security (conditional)CloudflareDiagnose and complete a security challengeCookieShort-lived challenge diagnostic cookies may appear only during a challenge
Anti-bot challenge (forms)Cloudflare TurnstileVerify that a human is submitting a form, on the contact and demo-request pagesTokenNormally a one-time token rather than a cookie
Analytics (cookieless, when enabled)Google Analytics 4Measure page views and usage to improve the site — no cookies, no device storage, IP anonymized, ad features offNo cookie (cookieless pings)None set — client_storage disabled; active only when analytics is enabled in the production build
FunctionalThis siteFonts are self-hosted, so no third-party font cookie is setNoneNo third-party font cookie

Several of the Cloudflare cookies above are conditional: they are set only in specific situations — when you pass a security challenge, when Turnstile pre-clearance is enabled, or when a rate-limiting rule applies — so most visits set none of them. Before each release we attach a current live cookie scan and remove from this list any cookie that is not actually observed or configured in production.

4. US privacy choices (CCPA "Do Not Sell or Share")

US law does not require an opt-in cookie banner. The main US control is the right to opt out of the "sale" or "sharing" of personal information under the California CCPA and similar state laws. Because this site sets no advertising or cross-site tracking cookies and runs no cross-context behavioral advertising, no such "sale" or "sharing" occurs through cookies here.

You can exercise your privacy choices at any time — see the "Your Privacy Choices" section of our Privacy Policy for how to do this. Because this site does not sell or share your personal information and does not use targeted advertising, there is nothing to opt out of through a browser signal, and we do not claim to detect or honor Global Privacy Control (GPC) signals. If our practices ever change, we will implement and test GPC or universal opt-out detection before deployment.

5. How to manage cookies

You can control and delete cookies through your browser settings, and set your browser to warn you before storing them. Blocking strictly necessary cookies may stop parts of the site — such as form submission — from working. Because this site sets no advertising or cross-site tracking cookies, there is nothing here for a browser-level Global Privacy Control (GPC) signal to opt out of; see our Privacy Policy for your privacy choices.

6. Third-party providers

Some technologies are provided by third parties who process the related data under their own policies. The main ones are Cloudflare (security, edge, and Turnstile) and, when analytics is enabled, Google (Analytics 4, in cookieless mode). See our Privacy Policy for the full list of providers and international-transfer safeguards.

7. Changes to this policy

We may update this Cookie Policy as our site changes. The effective date above will be updated when we do. Questions? Email office@nextbasket.com.