Cookies
1. What this covers
Cookies and anything equivalent — local storage, session storage, pixels and SDK identifiers. Audit the live site before writing this; the list must match reality, not intent.
2. Strictly necessary
Sign-in sessions, security tokens, load balancing. These need no consent, but they still need to be described.
3. Functional
Anything remembering a preference — chosen plan, player settings, language. Consent required.
4. Analytics
Name the tool, what it records, whether the data is aggregated, and the retention period. Consent required in the UK and EU.
5. Advertising
If you run remarketing or conversion pixels, list each one and its operator. This is the category most likely to attract a complaint, so be exact. If you run none, say so plainly.
6. Managing your choices
Explain how to change consent after the first visit — a link that reopens the banner is the usual approach — and how to clear cookies in the browser. Withdrawing consent must be as easy as giving it.
7. Table of cookies
Regulators expect a table: name, provider, purpose, type and duration, per cookie. Generate it from an actual scan of the deployed site rather than by hand.
8. Contact
Questions go to the privacy contact named in the privacy policy.