Cookie Policy
Last updated: 16 September 2026
“Cookies” here means cookies and anything else stored on or read from your device, including local storage and session storage. This page lists every one of them this site uses, what it is for and how long it lasts.
The short version: until you press Accept in the banner, this site stores exactly one thing on your device, and that one thing is the record of what you pressed. The only other things that ever load are the ones you ask for by using them, a video, the booking panel or an enquiry form, and each of those is set out below.
What we store without asking
One item, and only after you answer the banner: your decision itself, kept in local storage under the key loco:consent. Without it we would have to ask you on every page. It holds your choice and the date you made it, nothing else, and it is never sent to us or to anyone else.
The one exception is anything you ask for by pressing a button: the booking panel and the videos. Nothing of Calendly’s or Vimeo’s is loaded, and nothing is stored, unless you press “Book a free 30-minute call” or play a video. What each of them stores is set out below.
Using one of the enquiry forms works the same way. The moment you first click or type into a field, the page loads Google’s reCAPTCHA v3, the spam-scoring service that tells an automated submission from a real person. It is not on the page while you are only reading, and it shows you no puzzle to solve. Once it loads it sets one cookie, _GRECAPTCHA, which is listed in the table below. We treat it as strictly necessary rather than optional: without it the forms would be filled in by software all day and genuine enquiries would be lost in the noise. Since 16 September 2026 the forms depend on it, so if you block scripts from google.com, or run with JavaScript off, the form will tell you it cannot send and point you at our email address and phone number instead.
Analytics, only if you accept
If you press Accept, we load Google Analytics 4 through Google Tag Manager. It tells us how many people visit, which pages they read and which pages lead to an enquiry, which is how we decide what to write next.
Alongside the pages you view, we record a small number of actions on them: sending the enquiry form, pressing a phone number or an email address, pressing play on a video, and opening or completing a booking in the Calendly panel. Each one is recorded with the page it happened on. A completed booking also carries Calendly’s own reference for that booking, which is a random identifier rather than your name or your email address. Nothing you type into a form or into the booking panel is sent to Google Analytics.
Google Tag Manager runs in consent mode with everything denied by default. Before you accept, no Google analytics script runs and no analytics data leaves your browser. If you press Reject, none of it ever runs.
Google Signals and advertising features are switched off. We set no advertising cookies and we do no cross-site tracking. Two cookies on this site are set by companies you have no relationship with: Google’s _GRECAPTCHA, which appears only once you start filling in an enquiry form, and Stripe’s fraud-screening cookie inside the Calendly booking panel, which appears only if you open that panel. Both are listed in the table below, and neither is used for advertising.
Every cookie and storage item
Scroll the table sideways for the full detail
| Name | Purpose | Type | Duration | Provider |
|---|---|---|---|---|
loco:consent |
Remembers whether you accepted or rejected analytics, so the banner is not shown again | Local storage, first party. Essential | 183 days (six months), then we ask again. It also goes if you clear your browser storage or change your choice | Loco Digital |
loco:source |
Holds the page you arrived on and the button that brought you to the enquiry form, so we can see which page led to an enquiry. Written only after you accept analytics | Session storage, first party. Analytics | Deleted when you close the tab | Loco Digital |
_ga |
Tells one browser apart from another so visits can be counted | Cookie, first party. Analytics | Up to 13 months. Google asks for 2 years, but browsers cap a script-set cookie at 400 days | Google (Analytics 4) |
_ga_LHXGHNQEN4 |
Keeps the state of the current analytics session | Cookie, first party. Analytics | Up to 13 months, capped the same way at 400 days | Google (Analytics 4) |
_GRECAPTCHA |
Set by Google’s reCAPTCHA so it can tell an automated submission from a person filling in one of our enquiry forms. Written only after you start using a form, never on a page you are just reading | Third-party cookie, set by google.com. Strictly necessary | Six months | Google (reCAPTCHA v3) |
Vimeo player cookies and storage, including __cf_bm |
Set by Vimeo inside the player, and only after you press play, to run playback, remember settings such as volume and quality, and tell a real visitor from a bot. We load the player with its “Do Not Track” option on, so it sets no analytics or advertising cookies: on our own test, pressing play set one cookie, Vimeo’s Cloudflare bot-management cookie __cf_bm |
Third-party cookies and storage, set by vimeo.com in the player frame | __cf_bm expires after 30 minutes without activity. Anything else Vimeo stores runs from the length of the session up to about one year. Vimeo sets these durations and can change them |
Vimeo.com, Inc. |
Calendly cookies and storage, including __cf_bm and _cfuvid |
Set by Calendly inside the booking panel, and only after you press “Book a free 30-minute call”, to run the booking form, remember your progress through it and tell a real visitor from a bot | Third-party cookies and storage, set by calendly.com in the booking panel | __cf_bm expires after 30 minutes without activity. Cloudflare publishes no duration for _cfuvid. Anything else Calendly stores runs up to about one year. Calendly sets these durations and can change them |
Calendly LLC |
m on m.stripe.com |
A device identifier Stripe sets for Calendly, and only after you open the booking panel, so that Calendly can screen paid bookings for card fraud. Our consultations are free and we take no payment through the panel, but the check loads with it all the same | Third-party cookie, set by m.stripe.com inside the booking panel | Set by Stripe, which decides how long it lasts and can change that. Clearing cookies in your browser removes it | Stripe, Inc., for Calendly LLC |
Loaded only when you press play, book or use a form
Three case studies and the marketing and video page carry videos hosted by Vimeo, and the contact page and the closing section of most pages carry a button to book a call through Calendly. Neither company’s code is on the page when it loads: you see a still image or a button, and only when you press play or “Book a free 30-minute call” does the Vimeo player or the Calendly booking panel load. At that point your browser talks to them directly, sending your IP address and browser details, and anything they store from then on is covered by Vimeo’s privacy policy or Calendly’s privacy notice rather than this one. The Vimeo player is always loaded with its “Do Not Track” setting on, which is why it sets no analytics or advertising cookies. Calendly’s own cookie banner is switched off inside the panel because this page is where we tell you about it.
The enquiry forms behave the same way, except that what loads is a check rather than something you can see. There are two of them: the form on the contact page and the short form in the closing section of most pages. As soon as you click or type into a field on either, your browser loads Google’s reCAPTCHA v3 from google.com and it sets the _GRECAPTCHA cookie listed above. It watches how the form is filled in and works out a score for how likely it is that a person rather than a bot is filling it. When you press send, our server passes that score’s token and your IP address to Google to be checked, and gets the score back. Google’s handling of that is covered by Google’s privacy policy and Google’s terms of service. If a score comes back too low for us to tell you from a bot, the form says so and gives you our email address and phone number, so an enquiry is never simply swallowed. If reCAPTCHA never loads at all, because JavaScript is off or google.com is blocked, the form cannot send: it says that too, keeps everything you typed on screen, and gives you the same two ways to reach us.
One thing about the booking panel is worth spelling out, because it is not obvious and it is not ours. The panel is Calendly’s software, and it brings Calendly’s own suppliers in with it. When we opened it on a fresh browser that had rejected analytics, the panel loaded code from Stripe (card-fraud screening), Segment and Sprig (Calendly’s own product analytics and in-app surveys) and Airbrake (Calendly’s error reporting), and Stripe set the device cookie listed in the table above. We do not receive anything from any of them, we cannot switch them off, and none of it happens unless you press the button. If you would rather not load it at all, email hello@loco.ie or call +353 1 554 7325 and we will book the call for you.
Changing your mind
Use “Cookie settings” in the footer of any page. Withdrawing consent is exactly as easy as giving it, and it takes effect straight away: the analytics tags stop running, and you can delete the cookies already set through your browser.
You can also block or delete cookies in your browser settings at any time. Nothing on this site depends on the optional ones, so blocking them will not break anything.
Questions
Email hello@loco.ie or call +353 1 554 7325. How we handle personal data more generally is set out in our Privacy Policy.