Cookie policy
Effective 27 July 2026 · Last updated 27 July 2026
Two measurement tools run on this site, and between them they set eleven cookies. This page names every one of them — who sets it, on which domain, and how long it lasts — says exactly what happens before you have chosen anything, and shows how to stop it. The numbers here were measured in a clean browser on 27 July 2026, not copied out of a vendor’s documentation.
The short version
- In most of the world nothing optional runs until you say so. Not “loaded but switched off” — not loaded. If we cannot tell where your browser reached us from, that is the treatment you get.
- In nineteen US states the law works the other way, and there the two tools start on load. The banner says so in its first sentence and one click stops them.
- Refusing is one click, the same size as accepting. No wall, no reduced version of the site, and once you have answered the banner does not come back on its own.
- If your browser sends Global Privacy Control, that settles it everywhere — every optional thing is off before anything can load, in every country, whether or not the law where you are requires it.
On this page: What this policy covers · What runs before you choose · The four categories · What this site stores itself · Every cookie the two tools set · What idpixel stores and sends · What runs if you say no · Global Privacy Control and Do Not Track · Changing your mind · What we cannot delete · Your browser's own controls · How long things are kept · What this site does not do · If any of this changes · The limits of this policy
What this policy covers
“Cookie” is the word everyone uses, but the rules that matter are not really about cookies. They are about anything a website puts on your device or reads back off it — cookies, local storage, session storage, anything else. So this page covers all of it, and where something is stored in local storage rather than in a cookie it says so, because that is a difference worth knowing and not a difference that changes your rights.
There are two kinds of storage on this site. The first kind is necessary to serve the pages and to remember what you have already told us — it is listed in full further down and it cannot be switched off, because switching it off would mean forgetting your own choice. The second kind is measurement, and it is optional everywhere on earth even where the law lets it start before you answer.
What runs before you choose, and why it depends on where you are
Privacy law is not the same everywhere, and pretending otherwise means either ignoring a rule or applying the strictest one to everybody. This site resolves which set of rules applies before the page is built, from the country and region your connection arrives with. Your IP address is not stored, your city is not read, and the only thing written down is one of three words.
| Where your browser reached us from | What runs before you answer | What the banner is |
|---|---|---|
| The EEA, the UK, Switzerland, Brazil and Quebecand anywhere we cannot place at all | Nothing. No third-party script is put into the page and no third-party server is contacted. | A choice. “Accept all” and “Reject all” are the same size and shape, one above the other, with nothing pre-ticked. |
| Nineteen US statesthose with a comprehensive consumer privacy law | Both measurement tools, on load. These statutes work by notice and opt-out rather than by asking first. | A notice at collection. It says collection has already started, and its main button is “Do not sell or share my information”. |
| Canada outside Quebec | Analytics only. Visitor identification and advertising stay off until you switch them on. | A choice, as above, with the same two buttons. |
Anything unresolved lands in the first row. A VPN, a proxy, a connection that arrives with no location at all, a corrupted cookie, or a US visitor whose state we cannot see: all of them are treated as opt-in. That is deliberate, and it is the one rule in this system with no exception — guessing the permissive way round is the only mistake that cannot be undone afterwards, because by then the script has already run.
Quebec is checked before Canada, so Law 25 gets the express consent it requires rather than the implied consent the rest of Canada allows. The list of nineteen US states lives in one place in the code and is reviewed every six months; a state that is missing from it is treated as opt-in, never the other way round.
Why each row is what it is, in one line each: in the EEA and the UK, storing or reading anything non-essential on your device needs consent first; Switzerland and Brazil are handled the same way because consent is the honest basis for third-party session recording; Quebec requires express consent for profiling and tracking technology; the US states named above give you a right to opt out of sale, sharing and targeted advertising rather than a right to be asked first; and Canada accepts implied consent for non-sensitive analytics given clear notice, which is what the third row is.
The four categories
The preferences panel — reachable from the button in the corner of any page, or from cookie preferences in the footer — has one switch per category, and this is what each one governs.
- Strictly necessary — always on. Serving the pages, remembering your accessibility settings, and remembering this choice. It is listed by name in the next section. None of it tracks you and none of it goes anywhere else.
- Analytics and session recording — Microsoft Clarity. Records how pages are used — clicks, scrolling, mouse movement, the pages you view — and replays them as sessions and heatmaps so we can see where a page is confusing. Microsoft runs it, and Microsoft sets its own identifiers in the process, including one it uses for advertising. That last part is why this category is named honestly rather than as plain “statistics”.
- Visitor identification — idpixel. Gives your browser a durable identifier so a returning visit can be recognised, and sends the activity of your visit to its own collector. It is the one most people would not expect, so it gets its own switch and its own section below.
- Advertising and data sharing. Covers using what is collected for advertising, and sharing or selling it as those words are defined in US state privacy law. No advertising tag runs on this site today — the switch exists before the tag does, so that if one is ever added it is already governed by a choice you have already made.
What this site stores itself
All of it is strictly necessary, all of it stays on this domain, and none of it is sent to anyone else or used to recognise you anywhere but here.
| Name | Kind | Lasts | What it is for |
|---|---|---|---|
sdg_region | Cookie | 30 minutes | Which of the three sets of rules below applies to your browser. Its whole value is one of three words |
sdg_gpc | Cookie | 30 minutes | Whether your browser sent a Global Privacy Control signal. Its whole value is 0 or 1 |
sdg_dc_unlock | Cookie | 30 days | Only if you unlock the Design Center with its shared password — remembers that you did. Not readable by page scripts |
sdg:consent | Local storage | Until you change it or clear this site's data | Your own choice: which categories you allowed, when, and which version of this page asked |
sdg:a11y | Local storage | Until you reset the toolbar or clear this site's data | The accessibility toolbar's settings — text size, spacing, contrast, reading guide, and any profile you applied |
Two of those deserve a note. sdg:a11y is written on your first page load holding the toolbar’s default settings, whether or not you ever open the toolbar — it is a settings file with nothing in it yet, not a record that you were here. And sdg:consent is the only reason you are not asked about cookies on every page: it holds your answer, the date you gave it and which version of this page was on screen at the time. Clearing it is the same as never having answered.
Every cookie the two measurement tools set
Measured on 27 July 2026 in a clean browser profile with nothing else running: eleven cookies, under nine names. MUID and MR are each set twice, on two different Microsoft domains, and they are listed twice here for that reason. Only two of the eleven are on this site’s own domain; the other nine belong to Microsoft and to Cloudflare in front of idpixel.
| Cookie | Domain it is set on | Lasts | What it is for |
|---|---|---|---|
_clck | This site's own domain, written by Clarity | 1 year | Identifies your browser to Clarity across visits |
_clsk | This site's own domain, written by Clarity | 1 day | Ties the pages of one visit into a single recorded session |
CLID | www.clarity.ms | 1 year | Identifies your browser to Clarity's own service |
MUID | bing.com | 13 months | Microsoft's cross-site identifier. Microsoft also uses it for advertising |
MUID | clarity.ms | 13 months | The same identifier, set a second time on Clarity's domain |
SRM_B | c.bing.com | 13 months | A Microsoft identifier on its collection domain |
MR | c.bing.com | 7 days | Microsoft measurement |
MR | c.clarity.ms | 7 days | The same, set a second time on Clarity's domain |
ANONCHK | c.clarity.ms | 10 minutes | Microsoft measurement |
SM | c.clarity.ms | Until you close the browser | Microsoft synchronisation between its own domains |
__cf_bm | cdn.idpixel.app | 30 minutes | Cloudflare bot filtering in front of the idpixel script |
The thirteen-month one is the one to notice. MUID is Microsoft’s cross-site identifier. It is set on bing.com, which means it is not confined to this site, and Microsoft uses it for advertising as well as for measurement. It is disclosed here in the same words we would use if it were ours, because a visitor deciding whether to accept should be deciding about that and not about an abstraction.
What is asserted above is what was observed: the name, the domain and the lifetime, read out of a real cookie jar. What each Microsoft cookie does inside Microsoft’s own systems is Microsoft’s to describe, and it is not restated here as though we had verified it. Accepting means your browser contacts seven hosts — www.clarity.ms, scripts.clarity.ms, c.clarity.ms, h.clarity.ms, c.bing.com, cdn.idpixel.app and collector.idpixel.app. Refusing means it contacts none of them.
One other third party exists, and only if you ask for it. Opening Book a call loads a scheduling calendar from LeadConnector (api.leadconnectorhq.com, with a sizing script from link.msgsndr.com). Nothing is requested from either until you open that dialog — not on page load, and not at all if you never press it — so it is not part of the choice above. Refusing cookies does not remove it, because it is not tracking: it is the calendar you asked to see.
What idpixel stores, and what it sends
idpixel keeps nothing in a cookie of its own — the only cookie in its column above belongs to Cloudflare, which sits in front of it. What it uses instead is local storage, and because those keys are identifiers rather than settings they are described here in full rather than filed with the accessibility toolbar.
idp_anonymous_id— a random identifier for this browser, in the shape of a UUID. It is what makes a second visit recognisable as the same browser as the first.idp_visitor_id— measured empty on a first visit. It is the slot an identified visitor’s identifier would go in.queue.followed by a number — activity waiting to be sent to idpixel’s collector.
The contents of that queue were read directly rather than guessed at. One page view carries: the path, the page title and the full URL of the page you are on; the page you arrived from; your browser’s user-agent string; your language; your time zone; your screen size, window size and pixel density; the random identifier above; and timestamps. Together that is enough to recognise a browser, which is exactly what it is for. All of it is switched off with the visitor identification switch, and all of these keys are deleted when you switch it off.
What runs if you say no
Nothing. That is a measurement, not a promise: on a clean browser profile, after “Reject all”, no third-party host was contacted, the Clarity object did not exist on the page, and not one of the eleven cookies above was created.
There are four ways to say no, and they all work:
- Reject all— the same size button as Accept, directly below it, at the same level. Not hidden behind “customise”, and not styled to look like less of a button.
- The X in the corner of the banner — in the opt-in regions this is a refusal, recorded as one. It does not quietly dismiss the question and leave it unanswered.
- The Escape key — the same as the X.
- Your browser’s Global Privacy Control setting — the next section.
Nothing is withheld from you for refusing. There is no wall, no second version of the site, no delay, and no follow-up. Once an answer of any kind is stored the banner does not reappear on its own — it comes back only if you ask for it, or if a category ever changes what it means, in which case the old answer no longer covers the new question and everyone is asked again.
In the nineteen US states, closing the notice with the X is a dismissal rather than a decision: nothing changes about what is being collected, and every right on this page stays exactly as available. The notice stays down for thirty days so it is not nagging you on every page, and the footer link and the corner button remain there the whole time.
Global Privacy Control and Do Not Track
Global Privacy Control is a setting your browser sends on your behalf, so you can express the preference once instead of on every site. Firefox and Brave send it by default; other browsers can with an extension. This site reads it three ways — as a request header before the page is even built, as a browser property once the page is running, and in its older Do Not Track form — because no single one of those covers every browser.
If any of the three says opt out, then in every country, not only where the law compels it: every optional category is switched off before anything can load, the banner never appears at all, the decision is recorded so it survives your next visit, and the preferences panel and the do not sell or share page both show you plainly that the signal was seen and honoured. That confirmation is deliberate — a decision made silently on your behalf is not much use to you.
It is an opt-out and not a lock. If your browser sends the signal but you want something on anyway, the preferences panel will still let you turn it on.
Changing your mind
Taking it back is as easy as giving it, which is the standard the law sets and also just the decent way round. Three routes, all permanent fixtures: cookie preferences in the footer of every page, the button in the bottom corner of every page, and the do not sell or share page for the specific US right.
Switching something off does three things, in this order. The cookies and stored keys that belong to it and that we can reach are deleted — measured: _clck and _clsk gone, idp_anonymous_id, idp_visitor_id and the queue. key gone. Then the page reloads. Then it loads without those scripts, and stays that way.
The reload is not cosmetic and it is not us being cautious. A third-party script that has already started cannot be removed from a page that is open — it can only be stopped from loading on the next one. Any consent tool that claims to switch a live session recorder off without a reload is describing something that does not happen.
What we cannot delete
A website can only delete cookies on its own domain. Nine of the eleven cookies in the table above are not on ours, so when you withdraw, they survive. That was measured too, and rather than imply a clean sweep, here is exactly what is left behind: CLID, both copies of MUID, both copies of MR, SRM_B, ANONCHK, SM and __cf_bm.
What changes is that nothing on this site touches them again: the scripts that read and refresh them no longer load, so they are no longer being updated or extended, and they expire on the schedule in the table — ten minutes for the shortest, thirteen months for the longest. If you want them gone now, your browser can do in one step what this site is not able to do at all: the next section.
Your browser’s own controls
Every browser has a privacy or settings screen that can clear stored data for a single site, block cookies for a single site, or block third-party cookies everywhere. Blocking third-party cookies stops nine of the eleven above from ever being set, whatever this site does. A private or incognito window discards everything when you close it. Most browsers also have tracking protection switched on somewhere in the same screen.
This site works with all storage blocked. Two things change, and neither of them is a penalty: the accessibility toolbar cannot remember your settings between visits, and the cookie banner will ask again next time, because your answer had nowhere to be saved.
The accessibility toolbar also has its own “reset all settings” button, which clears everything it saved without touching anything else.
How long things are kept
- Your choice stays in your browser with no expiry date, until you change it or clear this site’s data. Nothing on our side expires it.
- The cookies in the two tables last exactly as long as those tables say — thirty minutes for the region cookie, ten minutes to thirteen months for the measurement ones.
- The decision itself is also sent to this site. When you accept, refuse, change or withdraw, a small message goes to this domain — never to a third party — carrying which set of rules applied, the three on/off values, a timestamp, two version numbers and the path of the page you were on. It carries no IP address, no cookie contents, no identifier and no free text, and nothing comes back. Refusals are recorded as carefully as acceptances, because being able to show that we stopped matters more than being able to show that you agreed.
- That message becomes a line in our hosting provider’s runtime log and is kept for as long as that provider keeps such logs, which is a short window. It is not a database, it is not searchable by person, and this site does not claim to maintain a consent record beyond what your own browser holds.
- Serving a page still involves a server, and that server keeps ordinary request records — the page, the time, your IP address, your browser’s user-agent string. Those are not cookies, they are not optional for any website, and they are covered in the privacy policy.
What this site does not do
Measured across nineteen pages on a clean browser with no choice made: not a single third-party host was contacted on any of them. Concretely, that means there is no Google Analytics, no tag manager, no advertising or conversion pixel, no social buttons, no embedded map, no third-party chat widget, and no font loaded from anyone else’s network. The typefaces and the video on the home page are served from this domain.
When you send the contact form, the message is delivered by an email service from our server after you press send. Your browser never contacts it, and it sets nothing on your device. It is named in the privacy policy with the others who process anything on our behalf, which is where it belongs.
If any of this changes
If a tool is added, this page names it, its cookies, their domains and their lifetimes in the same release the tool ships in — never afterwards. If a tool is removed, it comes off this page in the same release. The date at the top changes either way.
If a category ever changes what it covers, the answer you gave about the old meaning is retired rather than reused, and you will be asked again. Reusing a consent given to a different question is the quiet failure this is designed to prevent.
The limits of this policy
Everything above is stated as narrowly as it can honestly be stated. These are the edges, said plainly rather than left to be discovered:
- We can name, date and time every cookie we observed, and we do. What Microsoft and idpixel do with what they collect inside their own systems is governed by their own notices, and it is not restated here as though we had verified it.
- We cannot delete a cookie on a domain that is not ours. Withdrawal stops the scripts and clears what is on this domain; the rest expires on its own schedule or goes when you clear your browser.
- The list of US states with a comprehensive privacy law changes every legislative session. It is reviewed every six months, and a state missing from it is treated as opt-in — the stricter side, never the weaker one.
- This site does not keep a searchable record of who consented to what. Your browser holds your answer; our side holds a short-lived log line with no identifier in it. That is described exactly as it is in the section above rather than dressed up as a record system.
- No response time is promised on this page, because a promise about timing is one the code cannot keep on its own. Messages to the address below reach Ian directly.
Asking a question about any of this
Write to hello@spiderdigitalgroup.com or call 202-318-5500. Spider Digital Group is a remote studio working across the United States, founded and run by Ian Ciamarra in North Carolina. You can ask what has been collected for your browser and have it deleted, and you do not have to give a reason or prove who you are to change any setting on this page.
Effective 27 July 2026. See also the privacy policy, the do not sell or share page, the terms of use and the accessibility statement. Or change your cookie choices now.
