Version 0.1 (draft) — dated 2026-07-18. This document has not yet been reviewed by a solicitor and must not be relied on as final.

Cookie Policy

Status: DRAFT v0.1 — 2026-07-18. Not yet reviewed by a solicitor.

This Cookie Policy explains how Factory London (operated by Embedism Limited, company no. 11939367) uses cookies and similar technologies on this website. It should be read alongside our Privacy Policy.

1. Our approach: essential cookies only

At launch, Factory London uses only strictly necessary (essential) cookies. We do not use any analytics, advertising, tracking, or marketing cookies.

Under the Privacy and Electronic Communications Regulations (PECR), cookies that are strictly necessary to provide a service you have requested (such as keeping you signed in to view your quote, or protecting a form submission from forgery) are exempt from the requirement to obtain consent. Because we do not currently set any non-essential cookies, we do not display a cookie consent banner.

Forward-looking note (engineering/product): if analytics, marketing pixels, or any other non-essential cookie is added to the Service in future, a compliant consent banner and cookie-preference mechanism must be implemented, and this policy must be updated, before that cookie is set. Do not add analytics/marketing scripts without first revisiting this document and the consent requirement.

2. Cookies we use

Cookie namePurposeTypeDurationSet by
fl_session (example name — confirm against implementation)Maintains your session after you click a magic link, so you can view and act on your quote or order without re-clicking the link on every pageStrictly necessarySession / short-lived (e.g. expires with the magic link's validity window)Factory London (first party)
fl_staff_session (example name — confirm against implementation)Maintains a logged-in staff member's authenticated session in the admin area, issued via Google OAuth (Auth.js/NextAuth)Strictly necessarySession, cleared on logout or expiryFactory London (first party)
fl_csrf (example name — confirm against implementation)Cross-Site Request Forgery (CSRF) protection token, ensuring form submissions (e.g. accepting a quote, uploading a file) genuinely originate from our own siteStrictly necessarySessionFactory London (first party)

(Exact cookie names are set by the application framework and may differ slightly from the illustrative names above; this table should be kept in sync with the actual implementation as part of code review — see docs/07-security-gdpr.md.)

We do not set, and have no current plans to set:

  • analytics cookies (e.g. Google Analytics, Plausible, etc.);
  • advertising or retargeting cookies;
  • third-party social media tracking cookies;
  • any cookie used to build a profile of your browsing behaviour across other websites.

3. Other similar technologies

We do not currently use browser local storage or similar technologies to store personal data beyond what is functionally required for the session mechanisms above. If this changes, this policy will be updated.

4. Managing cookies

Because we only use strictly necessary cookies, blocking them may prevent core parts of the Service from working — for example, you may not be able to stay on a magic-link-authenticated quote page, or submit forms protected by CSRF tokens. You can still control cookies generally through your browser settings; see your browser's help documentation for instructions.

5. Changes to this policy

If we introduce any analytics, marketing, or other non-essential cookies in future, we will update this policy, implement an appropriate consent mechanism as described in §1, and note the change here with a new version number and date.

6. Contact

Questions about this Cookie Policy: [PRIVACY CONTACT EMAIL — PLACEHOLDER].

Document status: DRAFT v0.1, last updated 18 July 2026. Prepared as part of the Factory London design package; to be reviewed by a qualified solicitor before publication, and kept in sync with the actual cookies implemented in the codebase.