Skip to content
Pathfinder Labs Corporation
Legal

Cookie Notice

A short guide to what a visit here leaves behind on your device: what is left under our name, what the hosting edge may leave, and the single request that travels off the site.

Edition one, in force from 15 August 2026. Should what this site leaves behind ever change, this notice is rewritten before the change goes live, not after it.

1. The short version

pathfinderlabs.co.uk is a set of static files. Nothing here signs you in, takes a submission, fills a basket or counts you. Under our own name, nothing at all is stored on your device, and no measurement of any kind runs on these pages. The only tokens that can appear come from Cloudflare, which serves the site, and they appear only while Cloudflare’s protection is actually working. No consent bar stands here, because nothing on these pages needs consent.

One thing does travel off the site. The typefaces arrive from Google’s font servers, which means your browser reaches out to Google to fetch them. Waypoint 6 sets out precisely what that involves, since a page claiming to touch nobody while quietly fetching from somebody would be worth very little.

2. What counts as a trace here

A cookie is a small file a site asks your browser to keep and hand back on later visits. The rule that governs this in the United Kingdom is the Privacy and Electronic Communications (EC Directive) Regulations 2003, known as PECR, and it reaches well past cookies: it covers storing anything on your device, and reading anything already there. Local storage, session storage, tracking pixels and device fingerprinting all fall inside it.

Regulation 6 says that storing or reading in that way needs your consent, with two exceptions: where it is strictly necessary to deliver a service you asked for, or where it exists solely to carry a communication. This notice applies that test as written, rather than a looser marketing sense of the word “essential”.

3. Left under our own name

THE PATHFINDER LABS CORPORATION LIMITED stores nothing on your device through this website. No server of ours stands between you and a page, because the pages are flat files handed straight over. There is no session to hold open, no preference worth remembering and nothing about you to carry from one page to the next.

Inspect the site and find a cookie whose name is missing from waypoint 4 and we would genuinely like to hear about it: write to [email protected], and we will look into it and put this page right.

4. Left by the hosting edge

Cloudflare Pages serves the site. Cloudflare sits between your browser and the files and shields them from automated abuse. When that shielding engages, one of the tokens below may be issued. We never read them, never receive their values, and cannot tie one to a person.

The table below scrolls sideways.

Tokens the hosting provider may issue
NameIssued byWhat it doesWhen it turns upHow long it lastsConsent needed
__cf_bm Cloudflare, Inc. Bot management: it helps Cloudflare separate an ordinary browser from an automated client while traffic looks suspicious. Only where bot management engages for a request. Plenty of visits never see it. Thirty minutes after the most recent request No. Regulation 6(4) of PECR puts a security token of this kind outside the consent rule.
cf_clearance Cloudflare, Inc. Remembers that a security challenge was passed, sparing you the same challenge on every page after it. Only where you were shown a challenge and completed it. Set by the challenge configuration; commonly half an hour, at most a year No. Regulation 6(4) of PECR puts a security token of this kind outside the consent rule.
_cfuvid Cloudflare, Inc. Tells apart clients sharing one IP address, so a rate limit falls on the right one. Only where rate limiting rules come into play. Until you close the browser No. Regulation 6(4) of PECR puts a security token of this kind outside the consent rule.

Not one of those measures anything, advertises anything, builds a picture of you or shapes what you are shown. Cloudflare acts as our processor throughout, and the connection data passing through its hands is mapped at waypoint 4 of the Privacy Policy.

5. Why no consent bar stands here

A consent bar becomes necessary once a site stores or reads something on your device that is not strictly necessary. This one does neither. Everything in waypoint 4 sits inside the security exemption at regulation 6(4) of PECR, and beyond that there is nothing to declare.

Installing analytics, raising a bar and watching most people click Accept was always available to us. We would rather not know the readership than ask you to agree to being counted for our convenience. Should anything requiring consent ever be added, a compliant bar will appear, Reject will carry the same weight as Accept, nothing non-essential will run until you have chosen, and this page will be rewritten before the change reaches the site.

6. The one request that leaves

Bricolage Grotesque and Figtree, the typefaces you are reading, are fetched from Google Fonts. Your browser therefore asks fonts.googleapis.com for a stylesheet and fonts.gstatic.com for the font files themselves. Those requests carry what any web request carries: your IP address, your browser string, and the fact that something used by this site was wanted.

Google states that requests to fonts.gstatic.com are not answered with cookies, and testing here has turned up none. The request still hands your IP address to Google, though, which is why it is written down here rather than glossed over.

Exits. Blocking fonts.googleapis.com and fonts.gstatic.com, in your browser or with an extension, breaks nothing. The pages fall back to the typefaces already on your machine, the layout holds its shape, and no content is hiding behind a web font.

7. Storage other than cookies

Nothing is written to local storage or session storage. There is no IndexedDB, no service worker, no cache manifest of ours beyond the ordinary HTTP caching of the files themselves, and no fingerprinting. One small script runs, waypoint.js, which opens and closes the navigation on narrow screens and makes wide tables reachable from a keyboard. It keeps nothing and transmits nothing.

8. Not aboard at all

  • No measurement product of any description: not Google Analytics, Plausible, Fathom, Matomo, nor Cloudflare Web Analytics.
  • No advertising or retargeting pixel: not Meta’s, LinkedIn’s Insight Tag, X’s, nor a Google Ads tag.
  • No social embed, share button, comment thread or reaction widget.
  • No chat widget, session recorder, heat map or split testing tool.
  • No sales platform tracking, no service that turns an IP address into a company name, and no open tracking on mail we send.
  • No content delivery network besides the one serving the site, and no image, video or map pulled in from a third party.

The list names products deliberately. A vague promise to respect your privacy costs nothing to make, whereas a named list can be checked against your own browser’s network tab inside a minute, and we would encourage exactly that.

9. Taking control yourself

Your browser lets you block or clear cookies whatever any website prefers. Blocking the security tokens at waypoint 4 may earn you more challenges from Cloudflare, but it will not keep you from reading a word of this site.

  • Safari: Settings or Preferences, then Privacy.
  • Chrome: Settings, then Privacy and security, covering both Third party cookies and Site settings.
  • Firefox: Settings, then Privacy and Security, then Cookies and Site Data.
  • Edge: Settings, then Cookies and site permissions.

Those paths shift with each browser release, so where the wording no longer matches your screen, search your browser’s own help for cookies. A Do Not Track or Global Privacy Control signal changes nothing here, for the simple reason that there is nothing switched on for it to switch off.

10. Applications we release

Any application released under the company name will arrive without an advertising kit, without a third party measurement kit, and without any tracker that follows you across other companies’ apps and sites. Where an application stores something on your device to do its job, that is described in the listing before you install it. The position on the iOS App Tracking Transparency prompt, and the permissions an application would ask for, are set out at waypoint 20 of the Privacy Policy, and this notice moves in step with that waypoint.

11. Revisions, and who to tell

Should what this site leaves behind ever change, this notice changes first and the edition line at the top moves with it. Nothing gets added quietly and documented later.

Questions about this notice, or a report that something here is storing what is not listed, go to [email protected], and an answer follows inside two working days. Where our answer does not satisfy you, the Information Commissioner’s Office will hear from you directly: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, telephone 0303 123 1113.