About this policy
Last updated: 28 July 2026
This policy explains what cookies and similar technologies are; which technologies we currently use; why we use them; which providers may receive information; how long they may remain on a device; and how users can accept, reject or manage them.
It is intended to provide information to users internationally, including users in the United Kingdom, European Union, European Economic Area and United States. It should be read together with our Privacy Policy.
1. What are cookies?
Cookies are small text files placed on a computer, smartphone, tablet or other device when a website is visited. They allow a website to recognise a device or browser and may enable essential functions, maintain security, keep users signed in, remember preferences, measure usage, diagnose technical problems and improve performance.
Cookies do not normally contain complete documents, passwords or files. However, cookie identifiers and information associated with them may constitute personal data under applicable privacy laws.
2. Session and persistent cookies
Session cookies normally expire when the browser is closed. Persistent cookies remain until their stated expiry date or until they are deleted through the browser.
A stated lifetime is the maximum intended duration. A cookie may be removed sooner if browser data is cleared, consent is withdrawn, private browsing is used or a browser applies a shorter limit.
3. First-party and third-party cookies
First-party cookies are set through RAIUC.org. Third-party cookies are set or accessed by an external provider whose service is used on the website.
Some third-party services use a first-party cookie name while receiving information generated through that cookie. The relevant provider is identified in this policy.
4. Similar technologies
This policy also covers technologies that perform similar functions, including browser local storage, session storage, authentication tokens, tracking pixels, tags, scripts, device identifiers and security or bot-detection signals.
References to cookies generally include these similar technologies unless the context indicates otherwise.
5. Categories used on RAIUC.org
Strictly necessary technologies are required to deliver and secure the website, remember cookie choices, process requested forms, operate secure member sessions, protect private administration and prevent fraud, abuse or malicious traffic. They cannot be disabled through our cookie settings because requested services may not work properly without them.
Optional analytics technologies help us understand visitor numbers, pages viewed, navigation, approximate device, browser and general geographic information, performance, errors and interaction with page layouts. Google Analytics and Microsoft Clarity are activated only after analytics permission is given through our cookie controls.
RAIUC.org does not currently use cookies for targeted or behavioural advertising. We do not use cookie-derived information to create advertising profiles or display personalised advertisements.
6. Strictly necessary cookies and storage
The following technologies were confirmed in our website and live-service review on 19 July 2026. Exact security and authentication names may change when a provider updates its service.
- raiuc_cookie_consent — set by RAIUC.org to record whether optional analytics and services have been accepted or rejected; first-party cookie; retained for approximately 180 days.
- __cf_bm — set by Cloudflare to help identify and manage automated, malicious or suspicious traffic; security cookie; normally retained for approximately 30 minutes.
- cf_clearance — may be set by Cloudflare after a visitor successfully completes a security challenge; retained according to the applicable Cloudflare security setting.
- Supabase authentication storage — maintains a signed-in member session using browser local storage and secure authentication tokens; retained until logout, token expiry or browser storage is cleared.
- Administrative authentication storage — protects the private RAIUC administration area; normally retained for the authenticated session.
- Temporary form and security state — may support form processing, validation, rate limiting and protection against duplicate or abusive submissions; normally session-based or short-term.
7. Google Analytics
Google Analytics may load in denied-consent mode before analytics permission is given. In this mode, analytics storage and advertising storage are denied and Google Analytics cookies are not set by RAIUC. Google Analytics becomes fully active, with analytics storage granted, only after the visitor accepts optional analytics through our cookie controls.
When analytics consent is granted, Google Analytics may process the page viewed, access time, referring page, approximate location derived from an IP address, browser and device information, screen size, navigation events and pseudonymous browser or session identifiers.
We use this information to produce website statistics and improve the website. We do not intentionally send names, certificate-form contents, contact-message contents or passwords to Google Analytics.
- _ga — distinguishes one browser or visitor from another for statistical reporting; first-party analytics cookie; created only after analytics consent; default maximum duration up to two years, subject to browser restrictions and configuration.
- _ga_<container-id> — maintains analytics session state; first-party analytics cookie; created only after analytics consent; default maximum duration up to two years, subject to browser restrictions and configuration.
8. Microsoft Clarity
Microsoft Clarity is activated only after analytics cookies are accepted. The live scan confirmed that the Clarity script does not load before consent and loads after consent. Advertising storage is denied in the RAIUC configuration.
Clarity may collect page visits, clicks, taps, scrolling, navigation, device and browser characteristics, approximate location, screen size, performance information, pseudonymous session identifiers, interaction recordings and aggregated heatmaps.
Clarity is used to understand whether pages and controls are clear and usable. We do not intentionally use Clarity to capture passwords or the contents of sensitive form fields. We periodically review masking and analytics settings as website forms and features change.
- _clck — retains a pseudonymous Clarity user identifier and preferences for RAIUC.org; first-party analytics cookie; typically up to one year.
- _clsk — connects page views into a Clarity session; first-party analytics cookie; typically approximately one day.
- CLID — identifies when Clarity first observed a browser on a site using Clarity; third-party analytics cookie; provider-controlled duration.
- ANONCHK — indicates whether a Microsoft browser identifier is transferred for certain purposes; short-term third-party cookie.
- MR — indicates whether a Microsoft browser identifier should be refreshed; short-term third-party cookie.
- MUID — identifies a browser visiting Microsoft services; third-party cookie used by Microsoft for operational, analytics and other stated purposes; provider-controlled duration, potentially up to one year.
- SM — supports synchronisation of Microsoft browser identifiers; third-party session cookie.
8.1 Live Users administration view
With analytics permission, a short-lived first-party session signal supports the administrator-only Live Users view. It uses an anonymous session identifier and does not create a permanent visitor profile.
- The signal is sent approximately every 25 seconds while the website remains open.
- The associated server record expires after approximately 90 seconds without a signal.
- No IP address, full URL query string or precise location is retained in the live-session record.
- Rejecting or withdrawing optional analytics prevents future live-session signals.
9. Cloudflare security technologies
RAIUC.org is delivered through infrastructure protected by Cloudflare. Cloudflare may use cookies and technical signals to distinguish human visitors from automated traffic, detect malicious requests, mitigate denial-of-service attacks, enforce rate limits, complete security challenges and maintain website availability and integrity.
These technologies are treated as strictly necessary because they protect the website, its forms and its users. RAIUC does not use them for advertising.
10. Member authentication and local storage
RAIUC uses Supabase to provide member registration, email confirmation, login, logout and password-reset functionality. When a member signs in, Supabase may place a signed authentication token in browser local storage so the website can recognise the member during an authenticated session.
This storage may contain or represent a Supabase account identifier, access token, refresh token, token-expiry information and authentication-session information. It does not store the member’s readable password.
Authentication storage is necessary when a user asks to create an account or sign in. It can be removed by signing out or clearing the website’s browser storage, although doing so will end the session.
11. Cookie consent and preferences
On an initial visit, users may accept optional cookies, reject optional cookies or manage settings. Strictly necessary technologies operate regardless of this choice. Optional analytics technologies are activated only when the analytics option is accepted.
A record of the preference is stored for approximately 180 days. After that period, or if the cookie is removed, the website may ask for a new choice.
Users may change or withdraw their choice at any time by selecting Cookie settings in the website footer. Withdrawing consent prevents future optional analytics use on that browser and the website will attempt to remove relevant first-party analytics cookies. Some information already transmitted or cookies held under another domain may remain until deleted, expired or removed through the browser.
Withdrawal does not affect processing that lawfully occurred before consent was withdrawn.
12. United Kingdom and European requirements
For users in the United Kingdom, relevant requirements may include the Privacy and Electronic Communications Regulations, UK GDPR and Data Protection Act 2018. We use strictly necessary technologies without consent where the applicable exemption permits and rely on consent for optional analytics cookies and similar technologies.
For users in the European Union or European Economic Area, relevant requirements may include the ePrivacy Directive as implemented under national law, EU GDPR and applicable national laws. Where required, non-essential technologies are not activated until consent is given, and consent may be withdrawn as easily as it was given.
13. United States requirements
The United States does not currently have one general federal cookie law equivalent to the European ePrivacy framework. Cookies, online identifiers, IP addresses and browsing information may nevertheless be personal information under federal or state laws.
Depending on applicability and location, relevant laws may include the California Consumer Privacy Act as amended, the Colorado Privacy Act, Connecticut Data Privacy Act, Virginia Consumer Data Protection Act, other state privacy laws and Federal Trade Commission consumer-protection requirements.
RAIUC does not currently sell personal information obtained through cookies or use cookies for cross-context behavioural or targeted advertising. If our practices change, we will update this policy and provide any legally required choice or opt-out mechanism.
14. Other countries
Visitors may access RAIUC.org from countries with their own privacy and electronic-communications laws. We aim to apply a consistent standard of transparency, data minimisation, security, meaningful choice, consent for optional analytics and accessible preference controls.
This policy does not claim that one set of wording automatically satisfies every requirement in every jurisdiction. Local requirements may apply depending on the visitor’s location and the nature of our activities.
15. Sale, sharing and targeted advertising
RAIUC does not currently sell or rent personal information collected through cookies, use behavioural-advertising cookies, display personalised advertising or use analytics cookies to make significant decisions about individuals.
Google Analytics and Microsoft Clarity receive information as analytics providers. Their handling of information is also governed by their contractual terms and privacy documentation.
Some US laws use the word sharing for advertising or cross-context behavioural profiling even where no money changes hands. RAIUC does not currently use its cookies for those purposes.
16. Global Privacy Control and Do Not Track
Some browsers and extensions transmit Global Privacy Control, Do Not Track or other privacy signals. RAIUC does not currently sell personal information or use targeted-advertising cookies, so there is presently no sale or targeted-advertising activity for such a signal to opt out of.
Where applicable law requires a recognised browser signal to be honoured, we intend to treat it in accordance with that law. Because browser standards continue to develop, Do Not Track signals are not interpreted consistently by all providers. Visitors can always reject optional analytics through the RAIUC cookie controls.
17. International transfers
Google, Microsoft, Cloudflare, Supabase and hosting providers may process information outside a visitor’s country, including in the United States.
Where required, international transfers should be protected through applicable safeguards, which may include adequacy regulations or decisions, standard contractual clauses, the UK International Data Transfer Addendum, provider security and data-protection commitments or other recognised mechanisms. Further information is provided in our Privacy Policy.
18. External websites, sharing and embedded services
RAIUC.org may link to third-party websites, including LinkedIn and authoritative AI-related sources. A normal link does not necessarily set that third party’s cookies while a visitor remains on RAIUC.org. After following the link, the external website may set cookies under its own policy.
The LinkedIn certificate-sharing function opens LinkedIn as an external service. Once LinkedIn is opened, LinkedIn’s privacy and cookie practices apply. RAIUC does not control cookies set directly by external websites.
RAIUC.org does not currently embed YouTube videos or intentionally activate advertising cookies. If embedded video, maps, social-media widgets, payment services or other external content are introduced, we will review the consent mechanism and update this policy.
19. Google reCAPTCHA
Google reCAPTCHA v2 is active on the Contact Us form, the Advertising enquiry form and at the final stage of a new certificate application. It is a necessary security service used to prevent spam, automated submissions, fraud and misuse. It operates independently of the optional analytics-cookie choice because the protected forms cannot be submitted securely without the check.
When the reCAPTCHA component loads or is completed, Google may use cookies or similar identifiers and process technical and behavioural information, including IP address, browser and device information, referring page, date and time, mouse or keyboard interactions and security signals. The exact cookies, identifiers and duration are controlled by Google and may vary according to the visitor’s browser, Google account status and risk assessment.
RAIUC does not use reCAPTCHA for advertising or website analytics. Google’s handling of information is governed by its Privacy Policy at https://policies.google.com/privacy and Terms of Service at https://policies.google.com/terms. Blocking Google scripts or cookies may prevent the protected forms from working; anyone unable to complete the check may contact privacy@raiuc.org for an accessible alternative.
20. Children
RAIUC.org is intended for organisations and business users. It is not designed or directed specifically to children under 13, and we do not knowingly use cookies to profile children or deliver targeted advertising to them.
If you believe a child has provided personal information through the website, please contact us.
21. Managing cookies through a browser
Most browsers allow users to view or delete stored cookies, block third-party or all cookies, clear local storage, restrict tracking and use private browsing.
Blocking all cookies or storage may prevent preferences being remembered, member login sessions, secure account functions, forms, security checks or private administrative access from working. Rejecting analytics cookies will not prevent ordinary public pages from being used.
- Google Chrome: support.google.com/chrome/answer/95647
- Apple Safari: support.apple.com/en-gb/guide/safari/sfri11471/mac
- Microsoft Edge: support.microsoft.com/en-us/microsoft-edge
- Mozilla Firefox: support.mozilla.org/en-US/products/firefox
22. Data retention
Cookie retention depends on its purpose, the expiry configured by RAIUC, provider settings, browser restrictions, whether browser data is cleared and whether consent is withdrawn.
Analytics providers may retain information on their systems for periods that differ from the lifetime of a browser cookie. Server-side retention is addressed in our Privacy Policy and the relevant provider’s documentation.
23. Changes to this Cookie Policy
We may update this policy when technologies are added or removed, providers change their services, website functionality changes, authentication or security arrangements change, legal requirements change, or retention periods and consent controls change.
The revised policy will be published with a new Last updated date. Where a change materially affects optional processing, we may ask users to make a new consent choice.
24. Contact us
For questions about this Cookie Policy, cookie controls or how information is handled, contact:
RAIUC.org
2 Prospect Road
Dullatur
G68 0AN
Scotland
United Kingdom
Email: privacy@raiuc.org
- Next review due: 28 July 2027