The short version
We run our own website on our own servers. There are no advertising cookies, no social media trackers and no Google Analytics.
Three things here touch your device. Cookies make the site work, covering your basket, staying signed in, and your light or dark preference. A small measurement script counts visits, using a random number stored in your browser for 180 days. And a short server log of requests helps us spot faults.
If your browser sends a Do Not Track or Global Privacy Control signal, the measurement script does not run at all and the visit is never counted. That is a real switch rather than a promise. See How to control all of this.
Cookies we set
These are set by lucylovick.co.uk itself. All of them are needed for a feature you have asked for, so they do not require a consent banner.
| Cookie | What it does | How long it lasts |
|---|---|---|
| llds_store_cart | Remembers your uniform shop basket. It holds a random token only, never your name, address or card details. | 14 days |
| better-auth.session_token | Keeps you signed in to the parent portal, the student or teacher app, or Backstage. | 7 days, renewed while you use the site |
| better-auth.dont_remember | Records that you asked not to stay signed in. | Until you close the browser |
| better-auth.two_factor | Carries you through the two-step sign-in check. | 10 minutes |
| better-auth.trust_device | Staff only. Skips the two-step check on a device you have marked as trusted. | 30 days |
| llds_auth_theme | Remembers light or dark mode on the sign-in and staff pages. | 1 year |
On the live site the better-auth cookie names begin with __Secure-, for example __Secure-better-auth.session_token. The sign-in cookies are marked HttpOnly, Secure and SameSite=Lax, which means scripts cannot read them, they only travel over an encrypted connection, and they are not sent when another site links to us.
Storage in your browser
Some things are kept in your browser's own storage rather than in a cookie. Browser storage is never sent to us automatically the way a cookie is. We read it only when the page needs it.
| What is stored | Why | How long it lasts |
|---|---|---|
| Light or dark mode | So the site opens the way you left it | Until you clear your browser |
| A part-finished form | So a refresh or a lost connection does not wipe your answers | 7 days, then deleted automatically |
| Visitor and session identifiers | Counting visits, as described below | 180 days, and the current tab |
| Staff preferences and drafts | Sidebar width, panel positions, chosen columns, recent searches and unsent assistant messages | Until cleared |
Answers you give to a question we have marked as sensitive are never saved into a part-finished form. Neither is any step that contains one.
Visitor measurement
We count visits so we can see which pages help families find a class and which ones do not. This runs on our own servers. Nothing is sent to an advertising network and nothing is sold.
What is stored. A randomly generated identifier is placed in your browser's storage and kept for 180 days, so that several pages viewed in one visit, or a return visit, are not counted as separate strangers. It is a random number. It is not derived from anything about you or your device, and it is not linked to your name, your email address or your child's record, including when you are signed in.
What is recorded with it: the page path, how long the page was active, how far down it was scrolled, which links were clicked and which sections came into view, whether a video was played, whether you submitted a form, added to your basket or started checkout, how quickly the page loaded, the type (never the text) of any error, your broad device type, browser, operating system and language, the website you arrived from, and any campaign label in the link you followed (utm_source, utm_medium and utm_campaign, for example newsletter).
What is never recorded:
- Your IP address. It is not stored at all, in any form.
- Anything else after the ? in a page address. Campaign labels that look like an email address, a web address or a long code are discarded too.
- The full address of the site you came from. We keep the site's name only, for example google.com, and we discard it entirely if you moved between pages here.
- Any page in the parent portal, the student app, the teacher app or the staff area. Those are excluded before anything is sent.
- The text of any link you clicked, or the contents of any error message.
How long we keep it. Individual events are deleted after 90 days. Daily totals are kept for 2 years.
You can refuse it. We do not ask before counting a visit, but you can switch it off, as set out below. If you do, the site works exactly as before.
Server request logs
Separately from the above, our server keeps a short record of requests so we can find faults and abuse. This runs whether or not you are counted as a visitor.
Each entry holds the time, the path requested, the method and response code, how long it took, how much data moved, and a broad label for the browser and device. It also holds the query string and the referring address, both filtered to strip anything that looks like a token, password, email address or session key before writing.
These entries carry no IP address, no cookie value and no visitor or session identifier, so they cannot be tied back to the measurement above or to you. They are deleted after 14 days.
Embedded maps and video
Some pages embed content from other companies: a Google map on the Contact page, and occasionally a YouTube or Vimeo video. When one of those loads, that company can set its own cookies on your device and will see that you loaded the embed. We do not control those cookies and cannot switch them off for you.
Their own policies explain what they do: Google, YouTube and Vimeo.
If you would rather not load them, most browsers can block third-party content, and the rest of the page works without the embed.
Payments and security
Payments. When you buy uniform, we hand you over to Stripe's own checkout page to enter your card. That happens on Stripe's website rather than ours. We never see or store your card number, and any cookies at that point are Stripe's. See Stripe's privacy policy.
Security and delivery. Our website is served through Cloudflare, which protects it from attacks and speeds it up. Cloudflare may set its own security cookies, such as one that tells genuine visitors apart from automated bots. See Cloudflare's privacy policy.
Forms on other websites. If you fill in one of our forms embedded on another site, the form itself is still ours and behaves as described here.
How to control all of this
Turn off measurement. Switch on Global Privacy Control or Do Not Track in your browser. We check for both, on your device and again on our server. When either is set, the measurement script never starts, no identifier is stored, and anything that does reach us is discarded without being recorded. Form measurement stops too. GPC is built into Firefox, Brave and DuckDuckGo, and is available as an extension for Chrome, Edge and Safari.
Clear what is already stored. Clearing cookies and site data for lucylovick.co.uk in your browser settings removes everything on this page. Your basket and your sign-in will end as well.
Block third-party content in your browser settings to stop maps and video embeds loading.
Blocking the necessary cookies is possible but will break the thing they do. You will not be able to sign in or keep a basket.
You can ask us anything about this at [email protected]. How we handle personal information more generally is set out in our Privacy Policy.