We advertise on Google, and we want to know which of those adverts actually bring
people to this site; we also want to understand, in general terms, how visitors use
the site once they arrive. Both are run through Google Tag Manager,
which loads Google Ads conversion tracking and
Google Analytics, and it is the only tracking of any kind on this
website. There is no session recording, no fingerprinting, no advertising network
beyond Google, and no data broker.
Nothing loads until you press Accept
The first time you arrive, a notice appears at the foot of the page with two buttons,
Decline and Accept. Until you press one of them, no Google code has
been loaded, no request has been made to Google, and no cookie has been set. This is
worth stating precisely, because it is stronger than what most sites do: many load the
advertising or analytics code immediately and merely instruct it not to use cookies
yet, which still tells the advertiser that you were here. We do not do that. If you
press Decline, or simply never answer, your visit is never reported to
anyone.
The two buttons are the same size and either one takes a single press. Declining is
not made harder than accepting, and nothing on this site is withheld from you if you
decline — every page works exactly the same either way.
What we store, either way
Whichever button you press, we remember your answer so we do not ask again on every
page. That answer is kept in your own browser’s local storage, on your device,
under a single name (surglasses-consent) holding one word: whether you
accepted or declined. It is not a cookie, it is never sent to our server or anyone
else’s, and it is the only thing this site stores on your device if you decline.
Clearing your browsing data removes it, and the notice will then ask you again.
What Google receives if you accept
If you accept, your browser loads Google Tag Manager from
googletagmanager.com. Two things then happen. Google is told when you open
certain pages — the home page, the contact page and three product pages —
when you click one of our info@surglasses.com email links, and when a contact
form is successfully sent, which is how we measure advertising conversions.
Separately, Google Analytics records, in the ordinary way any site using it does,
which pages you view and how you move around the site, so we can understand how it is
used. Either way, Google receives your IP address and the identifiers in the cookies
it sets. Google acts as an independent controller of that data under its own privacy
policy; its cookies are set from Google’s own domains and typically last up to
two years unless you clear them.
What is never sent to Google is the content of your enquiry. Your
name, email address, phone number, organisation and message go into an email to us and
nowhere else. The conversion report says that a form was sent, not what was in it.
Changing your mind
Clear this site’s stored data in your browser and the notice will appear again on
your next visit, so you can choose the other answer. To remove the cookies Google has
already set, use your browser’s own controls, or Google’s advertising
settings. Declining or clearing does not delete measurements already reported to
Google; write to us at info@surglasses.com
if you want us to help with a request to Google about that.
The security check on the contact form
The contact form carries an automated security check supplied by
Cloudflare, called Turnstile. It is there for one reason: without it
the form is used to send us advertising, which is not a hypothetical — it began
happening as soon as this site went live. The check looks at your browser and decides
whether you are a person or a script, usually without asking you to do anything.
We have to be straight with you about how this one differs from the Google
measurement above, because the difference matters. It loads without asking
you first. We cannot put it behind the Accept button, because a check that
only runs after you have agreed to it is no protection at all — the automated
senders would simply decline. It is limited instead: it runs on
the contact page and nowhere else on this site, so no
other page you read contacts Cloudflare at all.
Running the check means your browser contacts Cloudflare, which receives your IP
address and technical information about your browser and device, and may store a
short-lived value in your browser for the purpose of that check. What comes back to
us is a pass or a fail and nothing more. Cloudflare is not sent your name, your
message or any other field on the form, we receive no information about you from
Cloudflare, and none of this is used for advertising or shared with Google.
If you would rather not use the form at all, email us at
info@surglasses.com and no check is involved.
Everything else on this site is still served by us
Apart from the Google tag and the Cloudflare check described above, every font, image,
video, stylesheet and script on this site comes from our own domain. There is no
content delivery network, no embedded map, no embedded video player and no social
media widget. The YouTube, LinkedIn, X and Facebook icons in the footer are ordinary
links: nothing is sent anywhere until you choose to click one, and then you are on
that company’s site under its own privacy policy.
One further cookie exists and it is not about visitors at all. When a member of our
staff signs in to the news or events editor to publish something, that sign-in sets a
single session cookie, which is strictly necessary for the sign-in to work and is
discarded when they log out. It is never set for you.