Every browser record, in one place.
This page is generated from the release's browser-storage inventory. It covers cookies, local storage and session storage used by the Mach Lilies website.
Page updated · 20 July 2026 · ML-017 attribution and consent disclosure reviewed 20 July 2026 · inventory ml-browser-storage-v2
The current consent model
We use essential browser storage to remember your choice and support features you request. With your permission, we keep the first and most recent bounded campaign labels and landing classifications for the fixed periods in the inventory below so our forms and booking handoff can carry campaign context. Google Analytics and advertising tags are not active in this release.
The browser removes unknown query parameters immediately and captures or discards the recognised campaign labels after your choice. That cleanup cannot undo the initial query-bearing request already received by the website host, which may remain in hosting logs under the controls described in the privacy notice.
Optional analytics starts denied. Advertising is not in use — off. The four consent signals analytics_storage, ad_storage, ad_user_data and ad_personalization default to denied. The site makes no Google or Meta request, including a cookieless measurement ping, before permission. There are no regional exceptions, URL passthrough or stored advertising consent.
This control lets you accept optional analytics, reject it or manage the analytics choice. The same control appears in every page footer. Core pages, forms and the scorecard remain available when optional analytics is rejected.
Complete active storage inventory
The records below are the complete allowlist for browser storage created by this release.
The consent preference record
The first-party ml-consent-v3 local-storage record has schema version 1. It contains only the schema and policy versions, analytics state, fixed denied advertising state, UTC decision time and UTC expiry time. It contains no identifier, campaign attribution, URL or server receipt.
An acceptance or rejection follows the fixed lifetime in the inventory above and is not extended by return visits. A malformed, legacy, expired or differently versioned record is discarded and the site asks again. A material change to a provider, purpose, category, data field, retention period or cross-site processing also requires a new policy version and a fresh choice; an ordinary copy correction does not.
Withdrawal and inactive providers
Withdrawing optional analytics takes effect without a page reload. It stops future optional processing, clears the consent-bound first/last attribution record and retired source keys, blanks those fields in website forms, restores undecorated Cal links and removes precisely registered optional first-party identifier cookies if any are found. No analytics event is sent about the withdrawal.
The cleanup-only cookie allowlist is exact names _ga, _gid, _gat, _fbp, _fbc and prefixes _ga_*, _gat_*, _gac_*, _gcl_*. These entries cover removal only: this release does not create or permit any of them.
Google Analytics 4, Google Ads and Meta are dormant. This release contains no Google or Meta tag loader, transport or Content Security Policy origin, so accepting optional analytics does not activate them. Before any provider is activated, its actual purpose, data, retention, transfers and controls must be reviewed, this notice must change materially, and the site must ask again.
For personal-information processing outside browser storage, including Formspree enquiries, Cal bookings and host logs, read the website privacy notice.