Effective / last reviewed: 6 October 2026.
1. What cookies and browser storage are
A cookie is a small piece of data that a website can ask a browser to store and return with later requests. Session cookies commonly expire when the session ends, while persistent cookies can remain for a defined period.
Browsers also support storage technologies such as localStorage and sessionStorage. These can store information in the browser without sending the value automatically with every page request. The legal and privacy significance depends on what is stored and why.
2. Storage used by the current build
| Name / type | Where used | Purpose | Duration |
|---|---|---|---|
PHP session cookie, commonly PHPSESSID |
Contact page | Maintains the PHP session used for the contact form’s CSRF security token. | Session-based by default; exact expiry depends on the server’s PHP configuration. |
cd_privacy_notice in localStorage |
Site-wide | Remembers that the visitor dismissed the privacy/storage notice. | Until browser storage is cleared or the key is removed. |
No account-login cookie, shopping-cart cookie, payment cookie or behavioural advertising cookie is implemented in this build.
3. Essential and functional use
The contact-form session is used for security. Without it, the anti-forgery token cannot work in the intended way. The privacy-notice localStorage key is a small functional preference that avoids repeatedly showing the same notice.
Neither item is used in the website code to build advertising profiles, infer a medical diagnosis or sell visitor data.
4. Analytics, advertising and Google tags
Google Analytics 4 and Google Tag Manager configuration fields exist in config/integrations.php, but the fields are currently empty. The page templates only load those scripts if a real ID is inserted. Therefore this build does not currently load GA4 or GTM and does not set Google analytics or advertising cookies.
Cookiebot is also not active because no Cookiebot Domain Group ID was supplied. The site instead uses the simple first-party notice described above.
If analytics or advertising technology is enabled later, this policy and the consent implementation must be updated before deployment so the actual cookies, purposes, providers, retention and user choices are accurately described.
5. Affiliate links and tracking
The declared business model is affiliate publishing, but no affiliate partner or monetised outbound link is currently configured. As a result, the current site code does not set affiliate-network tracking cookies.
If affiliate links are added later, the operator should document whether the partner uses cookies, click identifiers, server-side attribution or other tracking. Where consent is legally required, the tracking should not activate before that consent is obtained.
6. reCAPTCHA, Maps and other third-party embeds
Google reCAPTCHA and Google Maps are not loaded because no keys or map configuration were supplied. No embedded video player, social-media pixel or advertising network is included in the current build.
Ordinary external text links to official resources do not, by themselves, load the destination website while you remain on Creative Dynamics. If you choose to follow an external link, the destination may set its own cookies under its own policy.
7. How to control or delete storage
You can usually view, block or delete cookies through browser privacy settings. You can also clear local site data, which removes the Creative Dynamics privacy-notice localStorage key. The exact menu differs between browsers and devices.
Blocking all cookies may prevent the contact form’s session-based security feature from working correctly. Reading the public content does not require an account or marketing cookie.
8. Consequences of blocking
If the PHP session cookie is blocked, the contact form may fail because the anti-forgery token cannot be reliably tied to a session. You can still contact the published email address directly.
If localStorage is blocked or regularly cleared, the site may show the privacy notice again because it cannot remember that the notice was dismissed.
9. Do Not Track and browser signals
Because no behavioural advertising or analytics script is active in the current build, the site does not need to translate a Do Not Track signal into a change in marketing behaviour. If tracking tools are added in future, browser and consent signals should be reassessed as part of that implementation.
10. Changes to this policy
This policy must change when the actual technology changes. Adding GA4, GTM, Cookiebot, reCAPTCHA, Maps, an affiliate network, embedded media or a new form platform would require a new review of the storage and data flow.
11. Contact
Questions about cookies or browser storage can be sent to [email protected] or through the contact page.