Cookie & Storage Policy
The current build is intentionally light on tracking technology.
Last updated: 6 October 2026
1. What cookies are
Cookies are small text files placed by a website or third party in a browser. Similar technologies include localStorage and sessionStorage, which can store small values in the browser without using a traditional cookie.
2. What this site currently uses
Organlaxo uses browser localStorage to remember the choice to continue with essential-only storage. The key used by the supplied JavaScript is organlaxo-consent. The contact form also uses a PHP session for a CSRF token; depending on server configuration, PHP sessions commonly rely on an essential session cookie.
3. Essential purpose
The local preference prevents the same essential-storage notice from appearing on every page view. The session token helps confirm that a contact-form submission originates from the user’s browsing session and reduces certain forms of abuse.
4. Analytics
GA4 is not active because no Measurement ID has been supplied. The integration field is empty. If GA4 is added later, the cookie and consent descriptions must be updated to reflect the actual configuration.
5. Google Tag Manager
GTM is not active because no container ID has been supplied. No placeholder container is loaded.
6. Advertising and affiliate cookies
No advertising tag or active affiliate destination has been configured in this build. The site therefore does not claim that affiliate or advertising cookies are presently set. Future monetised links may involve partner-side tracking and would require updated disclosure.
7. Cookiebot
Cookiebot is not active because no Domain Group ID has been supplied. The small native notice is not represented as Cookiebot.
8. reCAPTCHA and Maps
Google reCAPTCHA and Google Maps are not loaded because keys/locations were not supplied. This avoids claiming data transfers that do not currently occur through those services.
9. Duration
The essential localStorage preference remains until the user clears it in the browser or site code changes it. PHP session duration depends on server configuration and browser behaviour.
10. First and third parties
The current preference value is first-party browser storage. Hosting and email infrastructure may process technical information separately under their actual configurations. No active third-party analytics script is bundled by default.
11. Managing storage
Users can clear site data through browser privacy settings. Blocking essential session storage may prevent the contact form from working correctly because CSRF protection depends on session state.
12. Consent withdrawal
Because the supplied build uses only the stated essential preference/session behaviour, there is no active analytics-consent toggle. If non-essential technology is added, the consent interface should be expanded before activation so users can make an informed choice.
13. Changes
This policy must be reviewed whenever analytics, advertising, affiliate tracking, embedded maps, anti-spam services or other browser-storage technologies are added.
14. Contact
Questions about site storage can be sent to [email protected].