NORTH DEAN MILL STUDIOS · POLICY REVIEW
Cookie policy
These policies include the agreed studio rules. Marked details are still being finalised before public bookings open.
Review draft — 1 October 2026. Optional analytics and advertising tracking are disabled in this release. The remaining publication checks concern staff-authentication and form-security storage on the deployed site.
Who is responsible
NORTH DEAN TRADING LTD, trading as North Dean Mill Studios. Company number 15054395. Registered office: 128 City Road, London, United Kingdom, EC1V 2NX. Contact hello@ndms.uk. Our privacy notice explains other uses of personal information and your rights.
Essential storage only
We use cookies and similar browser storage where needed to provide security, staff sign-in and remember your privacy choices. We do not currently load Google Analytics or Meta advertising pixels. Optional tracking is not required to browse or request a booking.
Cookie preferences is available at the bottom of the website. It explains each purpose. Selecting “Keep essential only” remembers that you have seen the notice; it does not grant marketing consent. If browser storage is blocked, optional tracking still stays off, although the notice may appear again.
What we store
| Storage | Purpose | Duration and context |
|---|---|---|
| ndms_review_access cookie | Lets an authorised reviewer pass the website's shared password page. | Seven days. Used while the site is password protected. |
| ndms-consent local storage | Remembers the essential-only preference and when it was saved. | Six months, or until you clear browser storage. Material changes may require a fresh choice. |
| Supabase staff authentication cookies | Keeps authorised studio administrators signed in. These are not customer accounts. | Authentication expiry/refresh and logout control access. The library's cookie maximum age is 400 days; actual deployed cookie names and expiry must be verified before final publication. |
| Cloudflare Turnstile | Protects enquiry forms from automated abuse. | A verification token is valid for five minutes and can be used once. Pre-clearance is disabled, so this widget does not issue a cf_clearance cookie to bypass security rules. Cloudflare processes browser/security signals for verification; see its Turnstile privacy information. |
Local storage remains in your browser and is not the same as a cookie automatically attached to requests. We use it here only to remember the privacy notice choice. The six-month preference refresh is not a guarantee that every browser physically deletes the stored entry on that date.
Existing optional cookies
Our site removes recognised Google Analytics and Meta first-party cookies that it can access, including _ga, _gid, _gat, _fbp and _fbc families, when the preferences component loads. It does not use them for new tracking. Browser controls let you delete other stored data, including cookies on third-party domains that our site cannot erase.
Payments and external websites
Stripe's separately hosted checkout has its own privacy and cookie information. Our preferences do not control storage on Stripe or other external websites. We do not embed advertising pixels on our payment pages.
Your browser settings
You can clear or restrict cookies and site storage through your browser. Blocking essential storage may prevent staff sign-in, review access or other essential functions from working correctly. Clearing the preference causes the information notice to reappear.
Future optional tools
If we introduce optional analytics or advertising, we will update this policy with the tools, purposes and lifetimes before activating them, and ask for separate choices where consent is required. Rejecting optional tracking will be as easy as accepting it. A previous essential-only choice is not permission to add new tracking.
See our privacy notice or email hello@ndms.uk about this policy.
Questions? hello@ndms.uk
