Legal
Cookie Policy
What this site actually stores in your browser. Compiled from a technical audit of the live site, not from a template.
Last updated 28 July 2026 · audited 28 July 2026 · DRAFT, NOT YET LEGALLY REVIEWED
Status. Working draft, not yet legally reviewed. The cookie list below was produced by loading this site in a clean browser and recording what was actually stored. It replaces an earlier template that listed cookies this site does not set.
1. What this covers
Cookies are small files a site stores in your browser. Browsers also offer local storage and session storage, which do the same job by different means. This policy covers all three, because the distinction matters to engineers and not to you.
2. What this site actually stores
Audited 28 July 2026 on the public homepage in a clean browser session.
Strictly necessary
__cf_bm · set on the elementor.com domain, not ours, when your browser loads design assets from cdn.elementor.com. Cloudflare bot management. Expires within the day.
wc_cart_hash, wc_fragments · browser storage, set by WooCommerce, which is installed on this site. They track a shopping cart. There is nothing on sale here at present, so in practice they hold an empty cart.
Functional
ea11y-global-state, ea11y-session-state · browser storage, set by the accessibility toolbar so your accessibility preferences persist while you read.
Marketing attribution, and an open issue
sbjs_first, sbjs_current, sbjs_first_add, sbjs_current_add, sbjs_session, sbjs_udata, sbjs_migrations · seven cookies set by SourceBuster, which ships as part of WooCommerce. They record how you arrived at the site, such as the search engine or referring link, so that a purchase can later be attributed to a traffic source. Most expire when you close the browser; sbjs_session persists.
Open issue, stated plainly. These attribution cookies are set as soon as you arrive, before any consent is asked for, and this site currently has no cookie consent banner. Attribution cookies are not strictly necessary, particularly on a site with nothing for sale. Under the ePrivacy rules and the GDPR that is a gap. The fix is one of: disable SourceBuster while WooCommerce is not selling, or add a consent mechanism that blocks non-essential storage until the visitor agrees. This should be resolved before this policy is published, not after.
What is not here
No Google Analytics. No Meta or Facebook pixel. No Microsoft, LinkedIn, TikTok or Pinterest advertising tag. No Stripe or payment-processor cookies. No cross-site advertising or remarketing tracker of any kind was found. If any of these are added later, this page is updated before the tag goes live.
3. Who sets them
Cookies set on umbrella-co.eu come from the site itself and its plugins. The only third-party host contacted on a normal page load is cdn.elementor.com, which serves design assets and sits behind Cloudflare.
4. Managing them
You can delete or block cookies in your browser settings, and clear local storage the same way. Blocking everything will not break this site, because nothing here depends on a cookie to display content. If a consent mechanism is added, this section will explain how to change your choice.
5. Changes
This page is re-audited whenever a plugin or tag that touches the browser is added or removed, and the date at the top changes with it. A cookie policy that is not re-audited is fiction.
6. Contact
Questions: hello@umbrella-co.eu. How we handle personal data more broadly is covered in the Privacy Policy.