Skip to main content
TRAKCORP Asset & Fleet Tracking
Operations manual 03 of 03

Cookies

  • In force from 7 August 2026
  • Issue 1
  • TRAKCORP LTD, company 17005499
  • Covers: trakcorp.uk alone

1. The short answer

Terms used throughout

Cookie
A short piece of text a site hands your browser and asks it to hand back on later requests.
First party
Storage written under the trakcorp.uk name itself.
Strictly necessary
Storage without which a service you deliberately asked for cannot function.

Browse trakcorp.uk and no first-party cookie is written to your device. There is no measurement script, no tag container, no advertising pixel, no social widget, no session tracking and no consent dialogue. Nothing here follows you off this domain, and nothing here assembles a picture of who you are.

Two third parties are nevertheless in the picture, and both get a section of their own below. Cloudflare delivers these pages, and the typefaces are fetched from Google's font hosts. Neither has anything to do with advertising, and neither can be switched off from this page, because each is part of how the page arrives at all.

This manual describes the six-page website at trakcorp.uk. It does not describe the TRAKCORP tracking platform or the applications issued under our name; those are separate systems, taken up at section 8 and in the privacy notice.

2. What counts as storage, and what PECR demands

A cookie is how a site remembers a login, a basket or a preference between one request and the next. It is also how an advertising network recognises the same browser turning up somewhere else entirely, which is why the law treats writing one as an event worth regulating.

Across the United Kingdom, putting information on your device or reading information already sitting there falls under regulation 6 of PECR, the Privacy and Electronic Communications Regulations 2003. Two duties follow: tell people clearly what the storage is, and obtain their consent to it. One exception cuts across both, for storage that is strictly necessary to a service the person deliberately asked for.

Where the storage also involves personal data, the UK GDPR stacks on top, and consent then has to clear the higher bar: freely given, specific, informed, and given by a clear affirmative act.

3. What this website writes

Nothing. No first-party cookie exists on trakcorp.uk.

That comes out of the construction rather than out of virtue. These pages are flat HTML files with one stylesheet and one small script beside them. Nothing runs on a server, there is no login, no basket, no personalisation and no form posting anywhere, so nothing exists for a cookie to carry. Every contact route on the site opens your own mail client instead.

The script does two jobs: it opens and closes the navigation on a narrow screen, and it lays a rule under the header once the hero photograph has scrolled past. It reads nothing about you, keeps nothing, and transmits nothing anywhere.

4. Cloudflare, standing in front

These pages sit on Cloudflare Pages and reach you across Cloudflare's network, which stands between your browser and the files, serves them from somewhere near you, and turns away malicious traffic.

Two consequences come with that, and we would rather write them down than leave you to find them in a developer console.

Connection records. Cloudflare sees your IP address, the page asked for, your user agent string and a timestamp, because no request can be served without them. Retention is Cloudflare's own, a matter of days on the plan in use here. We put them to nothing beyond chasing an error and blocking abuse. They are the edge log line in inventory A of the privacy notice.

Security cookies. Cloudflare's protective features can write one in particular circumstances: __cf_bm, a bot management cookie lasting around half an hour, and cf_clearance, written where a challenge has been shown and passed. No managed challenge is switched on for ordinary visitors, so in normal browsing neither should appear. Traffic flagged as automated may see one. Both are strictly necessary security storage under regulation 6(4) of PECR, written to protect the very service you asked for, and neither feeds measurement or advertising.

5. Typefaces fetched from Google

Headings on this site are set in Archivo and body text in Inter. Both are fetched from Google: fonts.googleapis.com serves the stylesheet, fonts.gstatic.com serves the font files themselves. That is a genuine third-party request, so your browser connects to Google, and Google therefore sees your IP address, your user agent, and the fact that a page here asked for those files.

Google states that requests to the Fonts API write no cookie, and that the files come off a cookieless host. Loading this site produces no Google cookie when we check it. What nobody here can promise is what Google does with the connection record at its own end, so the honest course is to tell you the request happens and leave the decision with you.

Rather it did not happen? A content blocker set against fonts.gstatic.com stops it, and the site stays entirely readable in whatever sans serif your system falls back to. The stylesheet is requested with display=swap for exactly that reason, so text is never held invisible waiting on a download.

6. Other kinds of local storage

Cookies are only one way of putting data on a device, and PECR reaches the others too. For completeness, this site uses none of the following: localStorage, sessionStorage, IndexedDB, Web SQL, service workers, cache storage written by script, canvas or font fingerprinting, device fingerprinting in any other form, ultrasonic beacons, or pixels buried in an image or an email.

Your browser will hold the HTML, the stylesheet, the script, the favicon and the photographs in its own cache, exactly as it does for any site. That is ordinary HTTP caching, run by your browser under rules we merely suggest, and clearing the cache clears it.

7. Why no banner stands here

Banners of that kind exist to gather permission for storage falling outside the strictly necessary exception. Nothing on this site falls outside it, so the banner would be gathering permission for an empty set.

Putting one up regardless would be worse than pointless. It would teach you to dismiss a dialogue carrying no information, it would suggest the site was doing something it is not, and it would need to write a cookie recording that you had dismissed it, which would then be the only cookie on the domain. Should measurement or anything else needing consent ever be added, a real consent mechanism with a genuine refuse option arrives with it, and this page changes before the change goes live.

8. The platform and the applications

The tracking platform is a separate system from this website. It takes a login, and a login needs a session, so it writes a strictly necessary session cookie or token to keep you signed in and to guard against cross-site request forgery. That is storage the requested service cannot run without, which puts it inside the regulation 6(4) exception.

What a TRAKCORP application keeps on a handset, and which permissions it asks for, is documented at section 12 of the privacy notice. An account holder signed in to the platform is given its own storage detail there rather than here, because this manual covers the public website alone.

Advertising is not run here, and no measurement follows a person between our product and anybody else's. The position taken for both applications is written out at section 13 of the privacy notice.

9. Working the controls in your browser

Nothing needs changing for this site, but every major browser lets you inspect, block and clear cookies and site data:

  • Safari: Settings, Privacy, Manage Website Data.
  • Chrome: Settings, Privacy and security, Third-party cookies and Site data.
  • Firefox: Settings, Privacy and Security, Cookies and Site Data.
  • Edge: Settings, Cookies and site permissions.

Blocking every cookie leaves this site working, since it uses none. It breaks most sites that need a login, so an exception list per site usually beats a blanket block.

10. Browser signals

Some browsers emit a Do Not Track header, or the newer Global Privacy Control signal. Neither changes anything at this end, for the plain reason that there is nothing here to opt out of: no tracking is done, no advertising is run, and nothing goes to a data broker, signal or no signal. Both are honoured by default, in the sense that our conduct already matches what they ask for.

11. Issue control, and checking this page yourself

This is issue 1, in force from 7 August 2026. Add anything that writes to your device and this page and its issue number change before the change reaches the live site, not afterwards.

None of it has to be taken on trust. Open the developer tools in your browser, look at the Application or Storage panel while these pages are in front of you, and the cookie list stands empty. Switch to the Network panel and you will find requests to this domain, to Cloudflare, and to the two Google font hosts, and nothing else at all. That check runs in about ten seconds and is worth more than a paragraph of assurance from us.

Questions about this page, or a report that something on it is wrong, go to [email protected], and most answers leave inside three working days. Your rights over any personal data caught up in the above, the route to the ICO included, are set out at section 10 and section 20 of the privacy notice.