Every browser record, in one place.
This page is generated from the release's browser-storage inventory. It covers cookies, local storage and session storage used by the Mach Lilies website.
Page updated · 30 August 2026 · consent-gated Google Analytics 4 activated · inventory ml-browser-storage-v7
The current consent model
We use essential browser storage to remember your choice and support features you request. If you accept optional processing, Google Analytics 4 measures page use and registered interactions, and we keep the first and most recent bounded campaign labels and landing classifications for the fixed periods below so our forms can carry campaign context. Google Analytics may then create the two first-party cookies listed below. Advertising tags are not active.
The browser removes unknown query parameters immediately and captures or discards the recognised campaign labels after your choice. That cleanup cannot undo the initial query-bearing request already received by the website host, which may remain in hosting logs under the controls described in the privacy notice.
Optional analytics starts denied. The Google Analytics tag does not load, make a Google request or set an analytics cookie until you accept. After acceptance, only analytics_storage is granted; ad_storage, ad_user_data and ad_personalization remain denied. Advertising is not in use — off.
This control lets you accept optional analytics, reject it or manage the analytics choice. The same control appears in every page footer. Core pages, forms and the scorecard remain available when optional analytics is rejected.
Complete active storage inventory
The records below are the complete allowlist for browser storage created by this release.
The consent preference record
The first-party ml-consent-v7 local-storage record has schema version 1. It contains only the schema and policy versions, analytics state, fixed denied advertising state, UTC decision time and UTC expiry time. It contains no identifier, campaign attribution, URL or server receipt.
An acceptance or rejection follows the fixed lifetime in the inventory above and is not extended by return visits. A malformed, legacy, expired or differently versioned record is discarded and the site asks again. A material change to a provider, purpose, category, data field, retention period or cross-site processing also requires a new policy version and a fresh choice; an ordinary copy correction does not.
Activating Google Analytics is a material provider change, so this release uses the new ml-consent-v7 policy and asks every visitor again. An older choice cannot authorise Google Analytics. The closed Authority-article interaction labels remain limited to the reviewed types and contain no free text.
Withdrawal and provider limits
Withdrawing optional processing saves the denied choice, sends the loaded Google tag an immediate denied consent update, clears the consent-bound first/last attribution record, retired source keys and registered optional first-party identifier cookies, then reloads the same query-free page. The denied replacement does not load the tag, and no analytics event is sent about the withdrawal.
The cookie cleanup allowlist is exact names _ga, _gid, _gat, _fbp, _fbc and prefixes _ga_*, _gat_*, _gac_*, _gcl_*. Of these, only _ga and the stream-specific _ga_* cookie can be created by this release, and only after acceptance; the rest remain removal-only.
Google Analytics 4 is active only after acceptance and is the only remote measurement provider this release activates. Google Ads and Meta remain source-disabled: there is no advertising tag, transport or Content Security Policy origin for either. Activating an advertising provider would require a separate purpose, disclosure, material consent-policy version and fresh choice.
For personal-information processing outside browser storage, including Formspree enquiries and host logs, read the website privacy notice.