Storage, entry by entry
A short handbook about what tolvara.co puts on your device, what it asks other machines for, and what our host writes down while serving you a page. It is arranged alphabetically, like the rest of our documentation.
Eleven entries. The short version: this is a static brochure site, so there is very little to describe — but the little there is deserves saying accurately rather than in a banner nobody reads.
- P
- PECR
Browser storageThe other places a page can leave something behind.
Cookies get the attention, but a browser offers a site several drawers to put things in: local storage, session storage and an in-browser database. This site opens none of them. Close the tab and your machine keeps nothing that came from us, which is why returning here later looks exactly like arriving for the first time.
ConsentWhy no banner interrupts you.
A consent prompt exists to get permission for storage that is not strictly necessary and for the tracking that usually accompanies it. Neither of those happens here, so asking would be theatre: a click to accept something nobody is doing. Should that ever change — if we added a booking widget, a chat tool or a measurement script — the prompt would appear before the thing it asks about ran, with refusing as easy as agreeing, and this handbook would be updated first.
CookiesSmall named values a site can leave in your browser and read back later.
A cookie is a short labelled value stored under a domain, handed back to that domain on every subsequent request. It is what lets a shop remember a basket, a bank keep you signed in, and an advertising network recognise the same browser on an unrelated site a week later.
The pages under tolvara.co set none. There is no session to keep, no basket, no login, no preference worth remembering between visits, and no advertising relationship for anybody to track. If you inspect this site with developer tools open, the cookie jar for our domain stays empty.
Embedded contentThe usual source of third-party cookies, absent here.
Most sites pick up their tracking from things they embed: a video player, a map, a social feed, a chat bubble, a booking calendar. Each of those loads code from somebody else's server, and that somebody else usually stores an identifier. This site embeds none of them. Photographs and the wordmark are served from our own host, the drawer icon is inline in the markup, and the page you are reading pulls nothing from a platform.
FontsThe one request that leaves our host.
Three typeface families carry the text on this site. Google serves the stylesheet that describes them from fonts.googleapis.com; the font files themselves arrive from fonts.gstatic.com. Fetching a file from any server means that server sees the request: your address, your browser and operating system version, and the page that referred you. Google publishes that the font service is cookie-free, and that it retains the request logs it needs to operate the service.
That fetch is the only outbound connection a page here makes, and it is a fair thing to object to. Blocking those two hosts in your browser or network leaves the site fully readable — you get your system's own fonts and slightly different letterforms, and nothing else changes.
Host logsWhat the machine serving these pages writes down.
Every web server keeps an access log, and ours is no exception: the requesting address, the moment of the request, the path asked for, the status code returned and the browser string. That record exists so that outages can be diagnosed and abuse can be spotted — a flood of requests from one address, say — and it is held for a short period before rolling over.
Log lines are not built into profiles, not sold, not joined to any other source, and not used to work out who a visitor is. Our privacy handbook covers the legal footing under its entry on visitors.
Links outWhere our responsibility ends.
A handful of links here point away from our domain — the regulator, occasionally a vendor's documentation. Follow one and you are on somebody else's site under somebody else's rules, including whatever they store on your device. We have no control over that and no visibility of it. Email links are different: they open your own mail client and involve no third party at all.
Managing storage yourselfTaking the decision out of any site's hands.
Every mainstream browser lets you block storage entirely, block it only for other domains, clear what has accumulated, or wipe everything automatically when you close the window. The menus move between versions often enough that printing a click-path here would mislead you within months, so the reliable route is your browser vendor's own help pages, or the guidance the ICO publishes for the public at ico.org.uk.
Blocking storage across the board occasionally breaks sites that genuinely need it, banking and shopping in particular. It will not break this one, since there is nothing here to block beyond the font request described above.
PECRThe rules that govern all of this.
In the United Kingdom, putting something on a visitor's device or reading something back from it is regulated by the 2003 regulations on privacy in electronic communications, known as PECR, which sit alongside the UK GDPR. The rule is straightforward: unless the storage is strictly necessary to deliver something the visitor asked for, you need informed consent first.
Since these pages store nothing at all, the consent question does not arise, and the ICO's guidance is the reference we work to if it ever does. Complaints about how any UK site handles storage go to the ICO — Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113.
ScriptsThe one piece of JavaScript on the site.
A single small file runs here, and its whole job is the navigation drawer on narrow screens: open it on a tap, close it on a tap or the escape key, keep the background from scrolling underneath while it is open. It talks to nothing over the network, reads no storage and writes none. There is no tag manager, no analytics library, no session recorder and no advertising pixel anywhere in the markup, which you can confirm by viewing the source of any page.
UpdatesHow this handbook changes.
The revision line under the title moves whenever the text does. Anything that would put storage on your device gets described here before it is switched on, not afterwards, and would arrive with a consent prompt attached. Questions about this handbook, or about anything in the sibling privacy A–Z or our terms of business, go to info@tolvara.co and reach a director.
↑ Back to the A–Z index