⚠ DRAFT v1 · not yet approved, not in force
Legal

Cookie Policy

DRAFT v1 · not yet approved, not in force
This policy explains what cookies and similar technologies — including browser local storage — Hume's website and intake application use, why, and how to control them. Read it alongside our Privacy Policy, which explains how we handle personal data generally.

1. What this covers

1.1 A cookie is a small text file a website asks your browser to store, usually sent back to a server automatically on later requests. Local storage is a similar browser feature, but it isn't automatically sent to a server — a site has to read it deliberately. We use both terms below because we currently use one and not the other.

1.2 This policy covers cahootconsulting.com, hume.cahootconsulting.com (when live), and the Hume intake application.

2. What we actually use today

2.1 We do not currently set any cookie on our own domain. The only thing our site stores in your browser today is your cookie-banner choice — Accepted or Rejected — held in local storage under the key hume_cookie_consent, not as a cookie.

2.2 Analytics is built into the site but switched off. The code that would load Google Analytics 4 and set analytics cookies is present, but the analytics ID is currently blank and our content security policy would block the analytics script from loading in any case. No analytics cookie is set today. If we switch analytics on, we will update this policy first, and it will still only load if you have accepted.

2.3 Payment happens off our site, not on it. Ordering redirects you to Stripe's own hosted checkout page. Stripe may set cookies at that point, but on stripe.com / checkout.stripe.com — never on our domain. We don't receive, read, or control those cookies. See Stripe's own cookie and privacy policies, published on stripe.com, for what Stripe itself sets.

2.4 Our hosting provider may set strictly necessary cookies of its own. The site is served via Cloudflare, whose content-delivery and security network can set strictly necessary cookies to protect it (for example, telling a legitimate visitor apart from automated abuse). These are outside our control, are never used for advertising or analytics, and — being strictly necessary — don't require your consent under PECR. [We will name any such cookie specifically once confirmed against our live Cloudflare configuration — not yet done at time of drafting.]

3. Current cookie / local-storage table

NameTypeSet byPurposeDuration
hume_cookie_consentLocal storage — not a cookieHume (this site)Remembers your Accept / Reject choice so we don't ask againUntil you clear your browser's site data
Analytics cookies (e.g. _ga, _ga_*)CookieGoogle Analytics 4Would measure site usageNot currently set — analytics is switched off
Stripe checkout cookiesCookieStripe, on stripe.com / checkout.stripe.com onlyPayment sessionSession — set by Stripe, not by us
Cloudflare security cookies (if any)CookieCloudflareStrictly necessary — abuse / bot mitigationNot yet confirmed at time of drafting

4. Your choices

4.1 The banner shown on your first visit lets you Accept or Reject. Today, that choice only ever gates whether analytics would load if it were switched on — nothing else on the site currently depends on it.

4.2 You can change your choice at any time via "Cookie settings" in the footer.

4.3 You can also control cookies through your own browser settings, and clear local storage through your browser's site-data settings.

5. Changes to this policy

5.1 We will update this page whenever what we actually use changes — in particular when analytics is switched on, or once any Cloudflare-set cookie is confirmed and can be named here.

6. Contact

6.1 Questions about this policy: cath@cahootconsulting.com.


Document control

VersionDateAuthorNotes
DRAFT v11 Aug 2026AI draftInitial draft, built from a factual audit (localStorage vs cookie, GA4 dormant, Stripe off-domain, Tally retired per D-048, Cloudflare-native cookies unconfirmed) rather than assumption. Not yet reviewed or approved.