Legal
Cookie policy
How this site uses browser technologies and keeps social updates first-party.
1Summary
We do not use analytics or advertising tags in the public site code reviewed for this policy. Our first-party Facebook feed is synchronised by our server and served from carelianlog.co.uk, so simply viewing it does not load a Facebook or Elfsight widget in your browser.
Because the public site does not ask to use an optional tracking category, it does not display a cookie-consent banner. Technologies needed for security, form protection, administration and delivery remain described below.
2Technology inventory
| Provider / item | Purpose | When it runs | Storage and choice |
|---|---|---|---|
| First-party Facebook feed | Shows recent posts published by Carelian Log Buildings. | Local feed data and re-encoded media load from this website. | No feed preference or third-party social cookie is created. Opening a post link is a separate visit to Facebook. |
| Cloudflare security and delivery | Routes traffic, protects the site and responds to malicious or abnormal requests. | When a request passes through the site's delivery and security layer. | Security technologies may be used where necessary to deliver and protect the service. |
| Cloudflare Turnstile | Protects contact and administration forms against automated abuse. | Only on a page where the configured security check is required. | Necessary for the protected form; it cannot be submitted until the check succeeds. |
| MapTiler / MapLibre and CARTO / Leaflet maps | Shows our contact location and project locations. | When the relevant map enters view or is used. | Our map implementations are designed not to create cookies. Tile and style requests are made to the named map provider. |
| Administration session and CSRF cookies | Authenticates authorised administrators and protects account changes. | Only when an administrator signs in or uses a protected administration function. | Strictly necessary for the requested secure administration service. |
carelian:projects-list-scroll in session storage | Restores your position when you return from a project detail to the project list. | While you browse and scroll the project listing in the current browser tab. | Functional session-only state. It is removed when the tab session ends or when you clear site data. |
| Website fonts and images | Provides the site's visual presentation. | When a page needs the relevant asset. | Served from this website; no Google Fonts browser request is required. |
This is a code and configuration inventory as at 22 August 2026. We review it when the site's providers or functionality change.
3How the social feed works
A scheduled server process obtains posts published by our own Facebook Page through Meta's official Pages API. It keeps only the post text, date, Facebook link and one display image. Images are validated, stripped of embedded metadata, re-encoded and served from our domain.
We do not reproduce Facebook comments or commenter details. No Facebook JavaScript, iframe, tracking pixel, Like control or Share control is loaded with the feed.
4Your choices
You can use browser controls to inspect, block or clear site data. Blocking technologies that are necessary for security may prevent protected forms or the administration area from working.
Following a Facebook, Google Maps or other external link is your choice and creates a separate visit governed by that provider's information and controls.
A legacy carelian-cookie-consent-v1local-storage value may remain on devices that used the site before 22 August 2026. The current site does not read or update it, and you can remove it through your browser's site-data controls.
5More information
Read our Privacy policyfor information about personal data, service providers and your rights. The Information Commissioner's Office also publishes current guidance about storage and access technologies.
6Contact
Questions about this policy can be sent to [email protected].