Legal

Cookie & Storage Policy

Version 1.5 · updated 10 October 2026

1. What this policy covers

This policy explains how HotelSolutionsMod (https://www.holetsolutionsmod.com) uses browser storage — cookies and the localStorage API — when you browse the shop, read our guides or complete checkout. It sits alongside the Privacy Policy, which covers the personal data we process; here we deal specifically with what your own browser stores and sends. We keep this deliberately short in mechanism even though the legal background is long, because the honest summary is: this site stores your basket and your banner choice, and nothing else.

2. The legal background, in plain English

The rules that govern storage on this site are the Privacy and Electronic Communications Regulations 2003 (PECR), as amended to align with the UK GDPR. Regulation 6 requires consent for non-essential storage, while Regulation 6(4) exempts storage that is “strictly necessary” to provide a service the user explicitly requested. Our legal position, reviewed with our advisers, is that the two items below fall within the strict-necessity exemption: the basket exists only because you clicked “Add”, and the banner-choice record exists only to avoid re-asking you on every page. That is why our banner offers accept and decline as equal options, and why declining changes nothing about how the site works.

3. What we set

This site runs on a purely essential-storage policy:

ItemTypePurposeLifetime
Basket contents (module selections)Local storageKeep your selection between pagesUntil order completes or you clear it
Cookie choiceLocal storageRemember accept/decline of this notice12 months
Contact / checkout form dataNot stored locallySent directly with your submission—

4. Storage keys in detail

Key name (browser storage)ContainsWritten when
raaddons_cart_v1Your basket lines: module slug, display name, unit priceEach “Add” click
raaddons_ck_v1Banner choice value “accept” or “decline”Banner button press

Both keys live in first-party local storage scoped strictly to this domain. They are never synced to a server in the background, never read by any other site, and contain no identifiers — not even a pseudonymous user ID. Clearing browser storage resets everything including this notice status. Nothing synchronises off-device until you submit checkout or forms, and what you submit then is governed by the Privacy Policy rather than this document.

5. What we do not do

No advertising cookies, no social-media pixels, no cross-site identifiers and no third-party analytics beacons are placed by default. Specifically, we do not set: audience-segmentation tags, retargeting pixels, affiliate tracking parameters that persist in storage, fingerprinting scripts, session-replay tools, heat-mapping collectors, or any identifier that survives across different websites. If we ever add optional performance measurement, the banner will offer a genuine opt-in with equal-weight buttons before anything loads, and the description below explains how that would work.

6. Families we never load by default

  • Advertising exchanges, retargeting tags and cross-site identifiers;
  • third-party analytics beacons, session replay or heatmapping scripts;
  • social network widgets such as like boxes or embedded comment frames;
  • font-loading telemetry — webfonts arrive cached without tracking pings beyond standard CDN request logs held by the font provider.

7. Third-party content you may choose to visit

Two kinds of third-party interaction exist, both initiated by you rather than by us: (a) the Google Fonts stylesheet and font files that style this site — the font provider’s CDN receives a routine file-request log (IP address, user-agent, timestamp) which we never see and which we do not combine with anything; and (b) the hosted payment pages opened from the secure links we email after checkout — those pages are operated by the payment provider under its own cookie and privacy terms, and their storage only exists while you are on the provider’s domain. We advise reading the provider’s notice when you land there; returning to our site ends its storage session.

8. If optional categories appear later

Should performance measurement ever be introduced, it will arrive as an explicit banner category with equal-weight accept/decline buttons, disabled until you choose, recording aggregate statistics only (no session replay, no cross-site linkage). The banner will list every planned payload in plain language before activation, and decline will remain available permanently rather than as a dark-pattern second step. Any such change would also be announced on this page with a new version number and date, and to account contacts by email 30 days ahead where we hold an address.

9. Revisiting your choice

The notice reappears if you clear site storage. If you prefer assisted handling, email support@holetsolutionsmod.com noting “cookie preference reset” and include the property name tied to your last visit; we will walk you through the two-click manual path on your own device rather than setting anything remotely.

10. Your controls

You can clear site data in your browser settings at any time (Chrome: Settings → Privacy → Site data; Firefox: Settings → Privacy & Security → Cookies and Site Data; Safari: Preferences → Privacy → Manage Website Data; Edge: Settings → Cookies and site permissions). Declining this notice changes nothing functionally because only essential storage is used — consistent with Regulation 6(4) PECR via the strict-necessity route. If you believe a site feature has set something beyond the two keys listed in section 4, tell us and we will investigate and publish the finding here.

11. Questions and complaints

Questions about this policy go to support@holetsolutionsmod.com with “cookie policy” in the subject line; we answer within 5 business days. Complaints about our use of storage can also be raised with the Information Commissioner’s Office (ico.org.uk), which regulates PECR as well as data protection. This policy is reviewed at least annually and after any change in guidance from the ICO.

12. Category-by-category legal analysis

For completeness, here is how each common cookie category maps onto this site. Strictly necessary: represented solely by the two local-storage items in section 4; exempt from consent under Regulation 6(4) PECR, hence no consent wall and no banner blocking content. Preferences: none — the site holds no theme, language or accessibility preferences in storage; such choices, where they exist, live in the page markup itself. Statistics: none by default — we count nothing, which is a deliberate product decision: a shop that needs to watch its visitors measure by measure is a shop that has lost the plot. Marketing: none — no remarketing audiences, no lookalike seeds, no email-capture popovers. Should any of these categories ever be introduced, section 8 describes the consent-first procedure that would precede them, and this analysis would be rewritten to match reality rather than aspiration.

13. The banner itself, technically

The consent banner is a plain element in the page markup controlled by one inline script; it is not injected by a consent-management platform, does not call home, and its buttons write only the choice key described above. “Accept” and “Decline” have identical visual weight and identical consequence today — a deliberate symmetry. There is no “accept all” pre-ticked state, no scrolling-as-consent, no nagging re-prompt after decline, and no content withheld from decliners. If you use a browser extension that blocks scripts, the banner simply never appears and the site still works, because nothing it gates is required.

14. Relationship with the Privacy Policy

This document governs storage on your device; the Privacy Policy governs what happens to personal data once it reaches us. The two meet at two points: the banner choice key contains no personal data, and the basket contents become personal data only when you submit checkout, at which point the Privacy Policy’s retention and rights provisions take over. Neither document creates rights beyond the UK GDPR, PECR and the Consumer Rights Act 2015, and neither asks you to waive any.

15. Version history and review

This policy is owned by our privacy lead, reviewed at least annually, and re-issued whenever the storage behaviour of the site changes in any way — including reductions. We keep dated copies of prior versions and supply them on request, because a policy you cannot compare against its predecessor is a policy you cannot audit.

Version history: 1.5 (10 Oct 2026) — key names updated to current build, third-party section expanded; 1.4 (21 Sep 2026) — annual review, no material change; 1.3 (2 Jun 2026) — optional-categories procedure added.