Privacy and Electronic Communications Regulations 2003
Cookie statement
What zaapto.uk stores on your device, which is very little, and why there is no consent banner in your way.
Effective 7 August 2026 Version 1.0 ZAAPTO LTD, company number 16938315
1. The rule this page answers to
Regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 says that storing information on, or gaining access to information stored on, a user's device requires clear information about what is stored and why, and the user's consent. There is one exception: consent is not required where the storage or access is strictly necessary to provide a service the user has explicitly requested.
That is the whole test, and this page applies it honestly rather than assuming an answer. Where personal data is involved, the UK GDPR applies as well, and the privacy notice covers that side.
2. What ZAAPTO sets: nothing
This website is a set of static HTML, CSS, SVG and JavaScript files. ZAAPTO sets no cookie of its own on any page of it. There is no account, no login, no basket, no form, no preference to remember, and therefore nothing this site needs to store on your device in order to work.
There is also no analytics product, no tag manager, no advertising pixel, no session recording, no heat mapping, no chat widget, no embedded video, no social sharing script and no consent management platform. The site loads two things from outside its own domain: two typefaces, covered in section 4. Nothing else.
The small JavaScript file the site loads reveals sections as you scroll, settles the header, and opens and closes the questions on the about page. It stores nothing, reads nothing from your device, and sends nothing anywhere. With JavaScript disabled the site is complete and readable.
3. What the hosting platform may set
The site is served through Cloudflare, which is the hosting and content delivery provider. Cloudflare operates protections at the network edge that can set a cookie in specific circumstances, and those are the only cookies that can appear when you visit this site.
| Name | Set by | When it appears | Purpose | Duration | Consent needed |
|---|---|---|---|---|---|
| __cf_bm | Cloudflare, as processor for ZAAPTO | On a request the platform assesses for automated traffic | Distinguishing a human visitor from a bot, so that the site can be protected from automated abuse. It is not used to identify you or to track you between sites | About 30 minutes from the last request | No. Strictly necessary for the security of a service you requested |
| cf_clearance | Cloudflare, as processor for ZAAPTO | Only if you are shown a security challenge and pass it | Recording that the challenge was passed, so that you are not challenged again on every page | Up to 30 minutes, or as the challenge configuration sets | No. Strictly necessary for the security of a service you requested |
The table scrolls sideways on a narrow screen.
Neither cookie carries a profile, a preference or anything about you as a person. Neither is read by ZAAPTO. On a typical visit to a static site of this kind you may see one, both or neither, which is why this section says "may" and does not pretend to a certainty it cannot have.
If you would like to see for yourself, open your browser's developer tools, go to the storage or application panel, and look at the cookie list for this domain. Nothing there should be a surprise after reading this page, and if it is, please tell us.
4. Typefaces and Google
The site is set in two typefaces served by Google Fonts from fonts.googleapis.com and fonts.gstatic.com. Requesting those files does not set a cookie on your device. It does disclose your IP address, your browser and operating system details, and the page that requested the font to Google, in the same way that requesting any file from any server discloses those things.
That disclosure is not a cookie question, so it is not answered by consent under regulation 6. It is covered in the privacy notice, which names Google as a recipient, states the lawful basis, and explains the international transfer position.
If you would rather your browser did not contact Google at all, a content blocker or a browser setting will stop it. The site then renders in a serif and a sans serif already installed on your device, and no content is lost.
5. Local storage and similar techniques
This site writes nothing to local storage, session storage or IndexedDB. It registers no service worker, uses no web beacon or tracking pixel, and attempts no device fingerprinting. Regulation 6 covers all of those techniques, not only cookies, which is why they are listed here rather than left unmentioned.
Your browser will cache the stylesheet, the script, the favicon and the font files so that the site loads faster next time. Ordinary HTTP caching is a function of your browser rather than something this site stores on your device, and it holds nothing about you.
6. Why there is no consent banner
A consent banner exists to obtain consent for storage that is not strictly necessary. This site performs no such storage: it sets no cookies of its own, and the only cookies that can appear are the security cookies in section 3, which fall inside the strictly necessary exception because they exist to protect the delivery of the page you asked for.
Showing a banner anyway would ask you to consent to something that is not happening, and would train you to click through a dialogue that means nothing. The honest alternative is this page, which lists everything and can be checked in your own browser in about a minute.
If ZAAPTO ever adds analytics or any other non essential storage, a genuine consent mechanism will appear first, refusing will be as easy as accepting, nothing will be set before a choice is made, and this page will be rewritten before that change goes live.
7. Controlling cookies in your browser
You can block or delete cookies in your browser settings, and you can do that for this site specifically without affecting others.
- Safari: Settings, Privacy, where you can block all cookies, and Privacy Report to see what a page requested.
- Chrome: Settings, Privacy and security, Third party cookies and Site settings.
- Firefox: Settings, Privacy and Security, Enhanced Tracking Protection and Cookies and Site Data.
- Edge: Settings, Cookies and site permissions.
Blocking the two security cookies in section 3 will not stop you reading this site, although in an unusual case it could mean a security challenge is shown more than once. Nothing on this site depends on a cookie to display correctly.
8. Applications
As at the effective date, ZAAPTO LTD has published no application on any app store. Where it does, an application does not use cookies in the way a website does, and what any ZAAPTO application would store on a device, together with the permissions it may request, is set out in the privacy notice rather than repeated here.
9. Changes, and how to challenge this page
This statement carries a version number and an effective date at the top. Both change when the page does, and a change is made before the storage it describes begins, never afterwards.
If you inspect this site and find storage that this page does not list, that is a defect in the page and we want to know. Write to contact@zaapto.uk with what you found and how you found it, and we will either correct the page or remove the thing that should not be there, and say which we did.
You can complain to the Information Commissioner's Office about cookie practices at any time: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, telephone 0303 123 1113.