This policy describes the cookies and similar browser storage used by the replacement timlord.co.uk application. It should be read with the Privacy policy.
Your choice comes first
Non-essential services are disabled by default. The first-visit controls give equal access to accepting or rejecting optional cookies, with a separate preferences view. Scrolling or continuing to browse does not count as consent, and rejecting optional services does not block ordinary public content.
Essential storage
Essential storage supports security, authentication, a service you request, and the record of your privacy choice. It cannot be disabled through the site because the relevant feature would otherwise not work.
timlord_consent_v3Records policy version, analytics choice, marketing choice, external-media choice and decision time.180 daystimlord.reaction-token and timlord.reaction-liked (local storage)A random value created by your browser only if you press Like, so the same reaction is not counted twice and the control can show what you have already liked. Only a one-way hash of the random value reaches the server.Until you clear site dataLikes
Liking a piece of content is a first-party feature of this site. No identifier is created until you press Like. At that point your browser generates a random value, keeps it in its own local storage, and sends it once so the like can be recorded; the server stores only a one-way hash of it.
No IP address, browser details, email address, account or social-network identifier is stored with a like, and nothing about it is shared as part of storing the like. With separate analytics or marketing consent, a successful like can also send a ContentLike measurement event; the reaction token and its hash are never shared. This is a first-party functional reaction identifier, not an advertising or Meta identifier. Clearing site data in your browser removes it.
Sharing
The share controls are ordinary links. Displaying them sends nothing to Facebook, X, LinkedIn, WhatsApp or anyone else, and no social network script, plugin or tracking pixel is loaded by those controls. The optional Meta and TikTok integrations described below are separate. A share request reaches one of those services only if you choose that destination yourself. Where your device offers its own share sheet, the site hands over to it and the choice of app stays with you.
Analytics
Google Analytics 4 is classified as optional analytics. The Google tag is not requested and no Google measurement ping is sent before analytics consent. If enabled, the site uses the existing destination G-7B413ZVXXH and may create first-party cookies such as _ga and a property-specific _ga_* cookie.
After consent, page views may be measured across the public site and signed-in/member journey, including article, music, Workshop, service, member/account, sign-in/signup/recovery-page and private-reader/discussion pages. Admin, preview, internal API/render, authentication callback and destructive data-deletion/account-deletion routes are excluded. Public or member-page query parameters may be included when they provide ordinary navigation or campaign context, but parameters or values that look like email addresses, names, account/member identifiers, form data, passwords, verification values, authentication or other security data are removed before a page view is sent. URL fragments and form contents are not deliberately sent.
With analytics consent, the same selected action events described under Marketing are also sent to Google Analytics, independently of the marketing choice. The implementation uses privacy-conservative Basic Consent Mode v2. analytics_storage becomes granted only after consent. ad_storage, ad_user_data and ad_personalization remain denied. Google Ads and LinkedIn tracking are not installed.
Marketing: Meta and TikTok
With marketing consent, Meta Pixel (257860501617804) measures public page visits and selected actions for Facebook and Instagram advertising measurement and audiences. Meta may receive your IP address, browser/device information, permitted page URLs and cookie identifiers, and may match activity to your Facebook or Instagram account. See Meta’s privacy policy. No Meta script or measurement request is made before marketing consent.
Measured actions include verified account signup, enquiry submission, newsletter/resource email requests, explicit email-updates opt-ins, resource unlocks, authorised download starts, successful website likes, checkout starts and Stripe-verified initial Workshop purchases. Newsletter requests do not prove double opt-in confirmation; a download start does not prove the file was saved. Purchase events contain the paid GBP amount, billing cadence and an opaque transaction reference. Names, email addresses, passwords, verification codes, messages, reaction tokens and signed download URLs are not included in event data. Automatic event detection and advanced matching are not enabled by this site.
Meta may set _fbp and _fbc cookies, typically lasting up to three months. Optional session storage remembers measurement choices at checkout and prevents repeat purchase events in the current browser tab. Checkout markers are ignored after 24 hours; purchase markers last for the tab session. Analytics permission alone never enables Meta. Version 1 and 2 cookie choices are not reused for the new TikTok purpose; version 3 asks you to choose again.
Meta page views cover public pages. Selected signup/account pages support conversion events only. Admin, preview, password/recovery, private reader, internal and deletion routes are excluded. URLs with unapproved query parameters or fragments are excluded to avoid sending personal data.
With the same Marketing choice, TikTok Pixel (DB2GNCBC77U9003F8LRG) measures the selected visits and actions above for TikTok advertising and audiences. TikTok may receive your IP address, browser/device information, permitted page URLs and cookie identifiers and match activity to its users. See TikTok’s privacy policy. No TikTok script or event is sent before consent.
TikTok may use _ttp, _tt_enable_cookie, ttclid and ttcsid/ttcsid_* cookies, which may last up to 13 months from their last use. With marketing consent before Checkout and on return, our server can also send a Stripe-verified initial purchase to TikTok’s Events API, including IP address, browser information and an available TikTok cookie identifier. The browser and server use the same event reference to avoid counting a purchase twice. This does not report subscription renewals or payments where you do not return to the site.
TikTok uses the same protected-page exclusions as Meta. Automatic page-change events, form matching, enhanced data collection and assisted event detection are disabled for this integration. Withdrawing Marketing consent stops new application events and clears removable first-party marketing cookies.
External media and players
Approved third-party embeds are treated as optional functional media. That currently means privacy-enhanced YouTube, Spotify, SoundCloud and Apple Music: the providers a music release can be played from, and the video provider used inside articles.
Before consent the page shows a local placeholder naming the provider it would contact, and makes no request to that provider at all — no iframe, no script, no cookie. You may allow external media as a saved preference, or load one item deliberately for the current page only. A one-time load is not remembered.
Choosing to load a player means your browser connects to that provider, which may then process your visit under its own terms and privacy policy. That part is outside this site’s control, which is why nothing is loaded until you ask for it. The site never sends your identity, your email or any account information to a provider; it only asks for the specific release you chose to hear.
Only a finite list of providers is supported, and the embed address is always derived by this application from a stored provider link. Arbitrary embed code cannot be published. The existing server-side provider and iframe allowlists remain in force, and each provider is granted only the minimum iframe permissions its player needs.
Booking a call
The call-booking dialog uses Calendly. It makes no request to Calendly while closed. After you open it, the calendar loads only if you have allowed external embeds or choose to load Calendly for that booking. That one-time choice is forgotten when you close the dialog and does not change your analytics preference. Booking details you enter go directly to Calendly under its privacy policy. You can also email Tim instead.
Change or withdraw consent
Open Cookie settings in the footer to see and update the current choices. Disabling analytics takes effect immediately for application events, removes the Google tag, and attempts to clear removable first-party _ga cookies. A later reload leaves Analytics blocked. Disabling marketing immediately revokes Meta and TikTok consent, stops new application events and attempts to clear removable first-party Meta and TikTok cookies listed above. A reload with marketing disabled does not load either Pixel. Rejecting both measurement categories also clears optional measurement session storage. Browser controls can delete stored cookies, including third-party cookies that this site cannot clear.
Policy changes
The consent cookie includes a schema version. A material change to the categories or purposes can increment that version and ask visitors to choose again. Questions can be sent to Tim Lord at hello@timlord.co.uk.