Cookie Policy

Version: 1.0

Effective date: 24 July 2026

Last updated: 24 July 2026

This policy explains how hionet uses cookies, pixels, local storage and similar technologies on hionet.com, the account area and checkout. Read it with the Privacy Notice.

1. Categories and consent

  • Strictly necessary: login, security, checkout, fraud prevention, load balancing and recording cookie choices.

  • Preferences: optional settings and interface choices.

  • Analytics: Cloudflare Web Analytics and Google Analytics measurement.

  • Marketing: Google Ads, Meta Pixel, TikTok Pixel and affiliate attribution.

Non-essential analytics and marketing technologies are disabled until an affirmative choice is recorded, except where a specific statistical technology qualifies for a legal exemption and is configured within that exemption. “Reject” must be as easy to use as “Accept”.

2. Current technology inventory

The exact identifiers can vary when providers update their products, browser restrictions apply or a payment page is hosted by a provider. The following describes the technologies hionet currently enables or may enable in the relevant flow.

Name or technology

Provider

Purpose

Category

Party

Typical duration

paymenter_session or equivalent session cookie

hionet / self-hosted Paymenter

Account login, cart, checkout and session security

Strictly necessary

First party

Session or up to 2 hours after inactivity, depending on configuration

XSRF-TOKEN or equivalent

hionet / self-hosted Paymenter

Prevent cross-site request forgery

Strictly necessary

First party

Session or up to 2 hours

cookieConsent

hionet cookie-banner extension

Records accepted or declined cookie choice

Strictly necessary

First party

6 months

Cloudflare security cookies, such as __cf_bm or cf_clearance, where triggered

Cloudflare, Inc.

CDN, DDoS mitigation, bot and security checks

Strictly necessary

First party or third party depending on delivery

About 30 minutes for __cf_bm; up to 1 year for challenge clearance

Cloudflare Web Analytics script

Cloudflare, Inc.

Aggregate site measurement

Analytics

Third party

Designed to operate without a persistent client identifier; request data may still be processed by Cloudflare

_ga and _ga_<container-id>

Google Analytics

Distinguish browsers and measure website use

Analytics

First party identifiers used by Google

Up to 2 years

_gcl_au and related Google Ads identifiers

Google

Advertising conversion measurement and attribution

Marketing

First/third party

Commonly up to 3 months; some Google advertising identifiers may last longer under Google's policy

_fbp and Meta Pixel events

Meta

Advertising measurement, attribution and audiences

Marketing

First/third party

Commonly up to 3 months

_ttp, _tt_enable_cookie and related TikTok identifiers

TikTok

Advertising measurement, attribution and audiences

Marketing

First/third party

Commonly up to 13 months

Payment provider security and checkout technologies

Stripe or PayPal

Payment authentication, fraud prevention and checkout

Strictly necessary for the selected payment

Third party

Set and retained under the provider's current cookie notice

Paymenter affiliate/referral identifier

hionet / self-hosted Paymenter

Attribute an order to an affiliate or campaign

Marketing

First party

For the configured referral campaign period, and no longer than 90 days

Cloudflare Turnstile, live chat and embedded video are not currently used. Provider-hosted payment pages may use additional strictly necessary identifiers that hionet cannot name in advance because they depend on the selected payment method and fraud checks.

3. Managing choices

Use Cookie settings in the website footer or cookie banner to accept or reject categories and change a previous choice. Browser controls can also delete or block cookies, but blocking necessary technologies may prevent login, security or checkout functions.

Consent choices are retained for 6 months unless a material change requires a new choice sooner. hionet recognises Global Privacy Control as an instruction to reject non-essential marketing and sale/share processing where technically supported. Browser “Do Not Track” is not treated as a consent signal because it is not consistently defined.

4. Provider information and international processing

Cloudflare, Google, Meta, TikTok, Stripe and PayPal may process identifiers and event information outside the United Kingdom. The Privacy Notice and Subprocessors and Data Locations explain roles and transfer safeguards. Their own privacy and cookie notices also apply to processing they carry out as independent or joint controllers.

5. Implementation requirement

The installed cookie-banner extension records acceptance or decline. It does not, by itself, guarantee that Google Analytics, advertising pixels or affiliate scripts are blocked. hionet configures those scripts so they do not load or store non-essential identifiers before consent and removes or disables them after withdrawal. The live configuration must be rechecked whenever a script, Paymenter extension or marketing provider changes.

6. Contact and changes

We may update this policy when technologies or law change. Material additions to non-essential purposes will not override an existing choice without fresh consent where required.

Contact hionet at [email protected], 07448927304, or Flat 1, The Granaries, Bepton Road, Midhurst, GU29 9LU, United Kingdom.