Legal
Cookie Policy
Draft for review
This document is supplied for completion and adoption. Highlighted fields are still to be completed, and it has not yet been reviewed by a solicitor for publication.
Golden Transfers is a trading name of Golden Transfers Ltd. This policy covers cookies, local storage, session storage and similar device technologies on [COMPLETE: Golden website and relevant booking domains]. Contact [COMPLETE: privacy email and correspondence address]. GT08 explains how we use personal information more broadly.
This document does not assume that Golden Transfers uses the same website, booking platform or cookies as another trading brand. Complete the inventory from the actual deployed site and embedded services before publishing a factual list. No cookie names, suppliers or expiry periods have been invented.
1 How technologies are used
Cookies and similar technologies may maintain a booking session, remember a privacy choice, protect a form, measure website use or attribute advertising. The applicable rules depend on purpose and operation, not whether an item is labelled first party, session-only, security or essential. Server logs and information copied into booking records have separate retention periods from browser storage.
We use storage/access without consent only where a valid legal exception applies. Optional advertising and other non-exempt technologies require a specific informed choice before they operate. Narrow statistical or appearance exceptions may apply only where all conditions are met, including information and a simple free objection route where required; we do not assume general analytics qualifies.
2 Your choices
The deployed controls must offer a clear way to accept optional purposes, reject them or select categories. Changing a choice must be as easy as making it. Optional categories must not be preselected, and continuing to browse or accepting booking terms is not cookie consent. An ordinary booking/enquiry must remain available without optional advertising consent.
Use [COMPLETE: actual Cookie preferences control/link and location] to change choices. On withdrawal, the relevant optional activity must stop and accessible optional storage be removed where appropriate. Already loaded suppliers may require additional controls or a reload. We will request a fresh choice when purposes materially change or a previous choice is no longer valid; there is no universal statutory expiry period to copy without assessment.
3 Booking payment and third party components
An embedded dispatch form, payment component, tracking page, map or anti-spam service may contact another organisation and access device information. Identify its contracting provider, purposes, actual storage, duration and relevant privacy information. A frame using lazy loading may load without a click; that setting is not a consent mechanism.
Necessary booking/payment session functions may qualify for an exception, but optional measurement inside a supplier’s component needs separate assessment. A supplier’s own description is not sufficient evidence that every item is essential. Golden remains responsible for the choices and data sharing it determines through its integration.
4 Browsers and offline bookings
Browser controls can delete or restrict storage. Clearing preference storage may make the site ask again, and blocking necessary session functions may interrupt a booking. If a form fails, contact [COMPLETE: booking email or telephone] for an accessible alternative.
A telephone-only booking does not itself place cookies on the caller’s device merely because staff use a dispatch system. Opening a payment, booking or tracking link is a separate online activity covered by the relevant information and controls.
5 Effective date and updates
Effective date: [COMPLETE: date after inventory and implementation checks]. We will update the policy when technologies, purposes or suppliers change and communicate material changes appropriately. Questions can be sent to the privacy contact above.
6 Management inventory and implementation record
Retain this section internally after producing the completed public inventory. Create one row per actual technology. Blank rows are not an assertion that a technology is active.
| Inventory field | Evidence required |
|---|---|
| Identity | Exact name, provider legal entity, domain and whether first or third party. |
| Function | Actual purpose, data accessed, recipients and link to the user’s requested service. |
| Storage | Cookie, localStorage, sessionStorage, pixel, SDK or other access; duration and server retention separately. |
| Lawful route | Consent category or precise exception with supporting assessment. |
| Timing | Behaviour before choice, after each category, during booking/payment and after withdrawal. |
| Documentation | Current provider information, scan evidence, policy version and review owner. |
Test a clean browser and the complete embedded journey. Include mobile and third-party-storage restrictions where material. Confirm category-specific withdrawal, version/age logic, changes of purpose, advertising identifier capture and whether data is copied into emails or booking records. Do not assume a configuration file reveals all hosting/CDN or embedded-provider behaviour.
Production domains suppliers inventory reference and check date
Consent categories exception assessments and approved refresh rule
Implementation owner sign off and next review
Reference: ICO guidance on storage and access technologies.