Skip to main content
Levyloom
Legal centreContactBack to Levyloom

Cookies · Current website

Cookie policy

Levyloom's application code sets no cookies or browser identifiers. Pre-launch checks observed one Cloudflare security-cookie type at each public hostname; no analytics, advertising, or preference cookies were observed.

Last updated
12 July 2026
Applies to
The public Levyloom website
Questions
admin@levyloom.com

On this page

  1. Current cookie position
  2. What cookies are
  3. Technology audit
  4. Consent and future changes
  5. Your controls

01

One security-cookie type was observed before launch

Current status

1 security-cookie type per host · 0 analytics or advertising technologiesApplication and public-domain edge inspected on 19 July 2026.

Levyloom's page code does not set a cookie. The current levyloom.com and www.levyloom.com network edge sets Cloudflare's __cf_bm cookie for bot detection and website security. It is not used by Levyloom for analytics, advertising, preferences, or cross-site profiling.

The site does not use local storage, session storage, analytics identifiers, advertising cookies, tracking pixels, session replay, third-party embeds, or a service worker to recognise or profile visitors. Because the only observed cookie is used for essential security, there is currently no cookie-consent banner. Before public launch, Levyloom must confirm and record whether the security cookie meets the applicable consent exception in the final configuration; otherwise it must be disabled or held back until valid consent is obtained. Any future non-exempt technology must also remain off until the required choice is obtained.

02

What cookies and similar technologies are

A cookie is a small piece of data that a website asks a browser to store on a device. Cookies may last only for a browsing session or remain until a set expiry date. They may be set by the website you visit or by another service used on that website.

Similar technologies can store or access information through other browser features. The same privacy and consent principles may apply where they perform a comparable function, even if they are not technically called cookies.

03

Current technology audit

Scroll horizontally to see all columns →

CategoryTechnologyPurpose and duration
Network-edge security cookie__cf_bm · Cloudflare · first-party domainBot detection and protection against malicious traffic. Expires after 30 minutes of continuous inactivity. Cloudflare classifies it as necessary for its bot product; the final Levyloom configuration and UK consent-exception assessment remain a pre-launch approval item.
User-requested interface stateURL fragment and browser History API · Levyloom first-party codeRecords the section and finite illustrative selection a visitor chooses so that the selected view, back button, and shareable page state work as requested. It remains in the URL or browser history until changed or cleared, contains no user identifier, and is not sent to Levyloom in an ordinary web request.
Adaptive presentationCSS media queries and limited matchMedia checks · Levyloom first-party codeReads screen and reduced-motion signals locally to adapt layout, navigation, and motion. The application does not retain or transmit those signals or use them to identify or profile a visitor. The final review must confirm the applicable UK storage-and-access exception and any required objection control.
Preference or functional cookiesNoneNot applicable
Analytics or performance cookiesNoneNot applicable
Advertising or social-media cookiesNoneNot applicable
Local or session storageNoneNot applicable
Pixels, fingerprinting, or session replayNoneNot applicable

Cloudflare generates __cf_bm independently. Cloudflare states that it contains encrypted bot-score information, does not correspond to a Levyloom application user ID, and is not used to track a person from one customer site to another. Cloudflare also provides a configuration for disabling the cookie. ReadCloudflare's cookie documentation for provider detail.

UK consent exceptions are assessed from the visitor's perspective and are purpose-specific. A provider's product description does not by itself decide whether a technology is exempt. Levyloom must document why the final security configuration is reasonable, proportionate, and within an applicable exception—or disable it or obtain valid consent—before launch. See theICO guidance on storage-and-access exceptions.

Deployment check required

Cloudflare may set additional challenge-related cookies when a particular protection is triggered. The final deployed origin must be audited before launch and after any DNS, CDN, firewall, challenge, hosting, or analytics change; this table must be updated if another cookie can be set.

What is not a cookie

Your browser may cache public files such as HTML, styles, scripts, and images to load the page efficiently. A hosting or security provider may also create routine server logs when responding to a request. Those processes do not place a cookie on your device, although server logs may contain personal information such as an IP address and are covered by our privacy notice.

The website keeps optional product-example selections in the page URL fragment so a view can be revisited. That fragment stays in your browser and is not sent to Levyloom as part of an ordinary web request. It is not stored in a cookie or web-storage API, but it is included in the technology audit above because the page reads and updates it to provide the selected view.

04

Consent and future changes

Levyloom will not introduce a non-essential cookie or similar technology unless its owner, purpose, information use, provider, and duration have been assessed and documented. Where consent is required, the technology must remain off until a visitor makes a clear choice, rejecting must be as easy as accepting, and a way to change the choice must remain available.

If the technology changes, this policy and the audit table must be updated at the same time. The “Last updated” date will show when that happened.

05

Your controls and questions

Most browsers let you inspect, block, or delete cookies through privacy settings. Blocking the Cloudflare security cookie may cause a security check to repeat or prevent access when protection is triggered.

If you observe a Levyloom-domain cookie or storage entry that is not described here, please take a screenshot or note its name, domain, and time, then email admin@levyloom.com. It may come from a hosting configuration, browser extension, security product, or a change that needs investigation.

Legal centre

Plain-language policies, kept together.

  • Company informationCorporate identity, statutory disclosures, independence and site status.
  • Privacy noticeHow Levyloom handles website, enquiry and correspondence information.
  • Cookie policyThe current security cookie, first-party technologies and consent boundary.
  • Website terms of useThe terms that apply when visiting this public website.
  • Accessibility statementThe accessibility target, current assessment and route for feedback.
Levyloom

A clearer view of regulated tax work.

  • Platform
  • How it works
  • Case comparison
  • Evidence & controls
  • Company
  • Privacy
  • Cookies
  • Terms
  • Accessibility
  • Contact

© 2026 Levyloom

LEVYLOOM LIMITED · Registered in England and Wales · Company 17302243 · Registered office: 85 Kings Road, Chelmsford, England, CM1 2BB

No analytics, advertising, or data-capture forms.