Cookie Notice
Last updated: 14 May 2026 · Version 1.1 (Global)
This Cookie Notice explains how Spotlight21 Ltd (“Spotlight21”, “we”, “us”, “our”) uses cookies and similar technologies on spotlight21.com and any related applications, what they do, and how you can manage your preferences.
It complements our Privacy Policy and Website Terms of Use. Capitalised terms not defined here have the meaning given in those documents.
1. What are cookies?
Cookies are small text files placed on your device when you visit a website. They allow the site to recognise your device, remember your preferences and provide a better experience. Similar technologies include local storage, session storage, pixels, SDKs and device fingerprinting — references to “cookies” in this notice cover those technologies too.
Cookies are described by:
- Origin — first-party (set by spotlight21.com) or third-party (set by another domain we use, such as a payment processor or analytics provider).
- Duration — session cookies are deleted when you close the browser; persistent cookies stay until they expire or you delete them.
- Purpose — what the cookie does (see Section 3).
2. Our legal basis for using cookies
We rely on different legal bases depending on the cookie category and your location:
- Strictly necessary cookies are required for the site to work and are set without consent under the UK PECR / EU ePrivacy Directive exemption for “strictly necessary” cookies.
- Functional, analytics and marketing cookies are set only with your consent in the UK, EEA, Switzerland, Quebec and other jurisdictions that require opt-in consent.
- US residents in CPRA / VCDPA / CPA / CTDPA / UCPA / TDPSA / OCPA states may opt out of any “sale” or “sharing” of personal information performed via cookies — see the “Do Not Sell or Share My Personal Information” link in our footer and our US Privacy Notice.
3. Cookies we use
3.1 Strictly necessary (always on)
| Name | Purpose | Duration |
|---|---|---|
br_session | Keeps you signed in after authentication. First-party, HTTP-only. | Session |
lang (local storage) | Remembers your preferred language for next visit. | 12 months |
cookie_consent | Stores your cookie-consent choices so we don’t re-ask. | 12 months |
__stripe_* (third-party) | Stripe fraud-prevention and Strong Customer Authentication at checkout. Set by stripe.com. | Up to 1 year |
3.2 Analytics (consent required)
If you accept analytics cookies, we use them to understand how visitors find and use the site so we can improve it.
| Name / Provider | Purpose | Duration |
|---|---|---|
| Plausible / GA4 (subject to choice) | Aggregate page views, traffic sources, conversion paths. IP addresses are truncated. | Up to 24 months |
br_anon_id | Anonymous visitor identifier used for funnel analytics. Not linked to any account until you log in. | 12 months |
3.3 Marketing (consent required)
We currently do not serve third-party advertising cookies for cross-context behavioural advertising. If we introduce them, they will appear in our consent banner before any data is collected, and you can refuse without losing functionality.
4. Managing your preferences
On your first visit you’ll see a consent banner letting you accept all, reject non-essential, or open Preferences to fine-tune by category. You can change your choice any time:
- Click the Cookie preferences link in our website footer.
- Clear your
cookie_consentcookie via your browser settings, then reload the page. - Use your browser’s built-in cookie controls (Chrome, Safari, Firefox, Edge).
- Enable “Do Not Track” or Global Privacy Control (GPC) — we honour GPC signals as an opt-out for US state laws that require it.
Blocking strictly necessary cookies may break sign-in, checkout or your language preference. Blocking analytics / marketing cookies will not stop you from using the site.
5. Third-party cookies
Some cookies are set by partners that help us operate the site. Their use of data is governed by their own privacy and cookie policies:
- Stripe — payment processing and fraud screening (stripe.com/cookies-policy/legal).
- AWS / Cloudflare — site hosting, security (DDoS protection cookies are strictly necessary).
- Analytics provider (where consented) — privacy policy of the chosen provider applies.
6. International transfers
Where a cookie partner is located outside the UK / EEA, we rely on the safeguards described in Section 9 of our Privacy Policy (UK IDTA, EU SCCs or adequacy decisions).
7. Changes to this Notice
We update this Notice when we add, change or remove cookies. The “Last updated” date at the top shows the current version. Material changes will be re-prompted in the consent banner.
8. Contact
Questions or to exercise rights regarding cookies: hello@spotlight21.com or write to Data Protection, Spotlight21 Ltd, 128 City Road, London, EC1V 2NX, United Kingdom.