On this page
Effective date: 19 July 2026
Last updated: 24 August 2026
This policy describes the cookies and similar request signals used on veyrastone.com. It should be read with the Privacy Notice.
1. Current consent model
The Site uses a self-hosted VeyraStone consent banner. It is not CookieYes, OneTrust, or another hosted consent platform.
On a visitor’s first public page view, analytics, advertising, personalization, and optional functionality storage are denied. The external Google Analytics tag is not requested until the visitor explicitly accepts analytics. The visitor can accept analytics or reject non-essential storage. Advertising and marketing storage remain denied because no public advertising or marketing tag is active.
The Site honors the browser’s Global Privacy Control signal by recording a privacy-preserving choice and keeping non-essential storage denied. Cookie settings can be reopened at any time from the footer.
2. Strictly necessary storage and security cookies
| Name or category | Provider | Purpose | Typical duration |
|---|---|---|---|
veyra_consent |
VeyraStone | Stores consent version, choice, timestamp, and whether Global Privacy Control was detected. It uses Secure, SameSite=Lax, and site-wide path attributes. |
Up to 12 months |
wordpress_logged_in_*, wordpress_sec_*, and related WordPress login cookies |
VeyraStone / WordPress | Authenticate authorized administrators. These are not public visitor accounts and are set only around administrator login and authenticated use. | Session or the selected administrator login period |
Security or challenge cookies, which may include cf_clearance or __cf_bm |
Cloudflare | Record a passed security challenge or support bot and abuse protection when the applicable Cloudflare feature is triggered. They are not guaranteed to appear for every visitor. | Controlled by Cloudflare and the triggered security feature |
The consent choice is stored in the veyra_consent cookie only. An earlier implementation also wrote the same choice to local storage; the current code removes that obsolete local copy.
3. Analytics cookies and signals
The Site uses Google Analytics 4 measurement ID G-HM3Z9SQXS7.
Before analytics consent
The Site uses a basic-consent approach. The external Google tag is blocked, and the Site does not send Google Analytics events, cookieless measurement pings, or the consent state to Google before analytics consent. A small first-party queue exists in the page only to apply a stored choice; it does not itself make a Google network request.
After analytics consent
Google Analytics may set first-party cookies such as:
| Name | Purpose | Duration |
|---|---|---|
_ga |
Distinguishes a browser for analytics measurement. | Controlled by Google Analytics and the configured property; commonly up to two years |
_ga_HM3Z9SQXS7 |
Maintains session state for this Site’s measurement stream. | Controlled by Google Analytics and the configured property; commonly up to two years |
Analytics events may include page use, Web Vitals, scroll depth, outbound-link and file-download interactions, selected inquiry intent, RFQ start and step completion, validation-error counts, contact-email clicks, and successful form submission. RFQ analytics contain only an approved event name, a step number from one to four, and one of the approved inquiry-intent labels. They do not send the form’s name, email, company, free-text message, material, dimensions, quantity, destination, timeline, or document requirements.
For Google’s current explanation of basic and advanced consent behavior, see Google’s consent mode overview. For Analytics cookie details, see Google’s Analytics cookie documentation.
4. Functional and marketing categories
No separate public language-preference, dark-mode, personalization, advertising, retargeting, Pinterest, LinkedIn, Meta, Microsoft Clarity, or Google Ads tag is active at the date above. The consent interface does not grant functional or marketing storage.
If one of those services is added later, the code, banner, Privacy Notice, and this inventory must be updated before activation. A prior consent choice will not be treated as consent to a newly introduced purpose without an appropriate re-prompt.
5. Server logs are not browser cookies
Hostinger and Cloudflare receive ordinary HTTP request information such as IP address, date and time, requested URL, user agent, referrer, and response status to deliver and protect the Site. These server-side records are not stored in the visitor’s browser, but they are personal information in some jurisdictions and are covered by the Privacy Notice.
6. Change or withdraw your choice
Select Cookie settings in the footer to reopen the consent controls. Rejecting non-essential storage updates the local consent state and replaces the consent cookie with the new choice. If Google Analytics was loaded after an earlier grant, the current page updates the Google consent state to denied; on the next page load the external tag is not requested.
You can also clear Site data in the browser. Clearing veyra_consent causes the banner to ask again. Browser settings can block cookies, but blocking strictly necessary security or administrator cookies may affect the related functions.
7. Browser privacy signals
The Site checks navigator.globalPrivacyControl where the browser exposes it. A Global Privacy Control signal keeps analytics and marketing storage denied. “Do Not Track” is not used as the consent control because it is not implemented consistently; the visible consent choices and Global Privacy Control are the supported mechanisms.
8. Changes and contact
This inventory should be reviewed whenever a plugin, analytics tag, CDN security mode, form, or marketing integration changes. The date above identifies the current version.
Cloudflare documents the security cookies its services may set in its official cookie reference.
Questions can be sent to sales@veyrastone.com with the subject “Cookie question.”