Cookies: what does and does not reach your device
This page describes what this site stores on your device and reads back. Not in categories that could mean anything, but with the keys named, so you can check it in your own browser.
The short answer, and the law behind it
This site sets no cookies of its own. We do measure how the site is used, with Microsoft Clarity, but deliberately in its cookieless mode: nothing is placed on your device or read from it for that, and you are not followed from page to page. Exactly how that measurement works is set out further down this page. There is no advertising pixel on the site, we build no profile of you and we share nothing with advertising networks. The party hosting the site may set a technical cookie to keep out attacks; that one is in the table below.
In two places your browser does store something, both on the MyParcel Dashboard pages and both because you clicked something yourself. That stays on your own device. The table below says precisely what it is.
That is why there is no cookie banner
Regulation 6 turns on a single act: storing information on your device, or gaining access to information already stored there. If that act does not happen, the consent requirement does not arise. The same regulation carves out storage that is strictly necessary to provide a service you have explicitly requested.
That is our whole position. The measurement stores nothing. The two keys below exist only because you asked for a preference to be remembered. A banner would be asking your permission for something that is not happening, and a consent request for an act that never takes place is not caution, it is a false statement in a friendly typeface. So there is none.
The test itself has four steps, and only the last one produces a banner. Drawn out, with where this site sits at each step:
# The moment anything does reach Q4, the order is fixed: this page is rewritten first, the thing is switched on second.
# The statute is regulation 6 PECR for the United Kingdom, checked on 25 August 2026; in Ireland the national ePrivacy rules carry the same act-based test.
If that ever changes, the new part stays blocked until you actively say yes, and the choice really does appear with it. The order matters and it is not negotiable: write it down here first, switch it on afterwards.
What happens to your data once you fill in a form or work with us is in the privacy statement. This page is only about what is placed on and read from your device.
What is actually stored
This is the complete list. It does not come from a template: we went through the code of the site itself on 12 August 2026 and wrote down only what is really in it.
# The bar that runs across the three drawers is the check we do in a clean browser session before every release.
# Both filled keys stay in your own browser: they do not come to us and they do not go to anyone else.
# You can throw them away whenever you like; nothing breaks, you only lose that display choice.
From a third party there is at most the security cookie of the hosting provider, to keep out bot traffic. We do not set it and we do not read it. The measurement with Clarity runs in cookieless mode, so _clck and _clsk are not in your browser.
| What | Kind of storage | What for, and on which page | How long |
|---|---|---|---|
| mp-plan | Session storage, sessionStorage | Remembers which package you clicked, so that the text and the button after it match your choice. Only on the MyParcel Dashboard start page | Until you close the tab |
| myparcel-dashboard-preview-preferences | Local storage, localStorage | Remembers your display choices: light or dark, density, accent colour, which screen it opens on, which figures and columns you see. Only in the MyParcel Dashboard demo | Until you clear your browser storage |
| Security cookie of the hosting provider | Cookie | Keeping out bot traffic and attacks. May appear on any page. We do not set it, we do not read it and it does not serve to recognise or follow you | According to Cloudflare's settings |
The first two go nowhere. They are not sent to us, not shared with any other party and not linked to anything beyond the screen where you set them. You can throw them away at any moment, and nothing breaks if you do.
The exact name and lifetime of Cloudflare's security cookie depend on the settings at the hosting provider. We are recording those, together with the retention period of their logs. We do not put a name or a period on this page that we have not checked.
The measurement: Microsoft Clarity, without cookies
We measure how this site is used with Microsoft Clarity, a Microsoft service. We do that deliberately in cookieless mode: before the script loads, we give Clarity the fixed signal that there is no consent for cookies. Clarity then places nothing on your device and reads nothing from it. The cookies Clarity would use with consent, _clck and _clsk, are therefore not in your browser. You can check that yourself in your browser storage.
So what does go to Microsoft? Which pages are viewed, where people click and scroll, how the mouse moves, and technical data such as browser, device and country. What you type into input fields is masked by Clarity in every mode and is not sent to Microsoft.
Microsoft keeps recordings of page visits for 30 days. Recordings marked as favourite and a random sample from them stay up to nine months. Those are the periods Microsoft states itself in the Clarity documentation, and they are Microsoft's and not ours. The data sits with Microsoft in the Azure cloud, and Microsoft processes it partly under its own terms. That is why Microsoft also appears in our register with the parties that decide in part for themselves what they do.
We accept the downside of this mode: without cookies every page view counts as a separate session. We cannot recognise you when you come back and we cannot see which pages you look at one after the other. That makes the figures coarser, and we think that is a fair price for measuring without putting anything on your device.
Do not want this measurement either? Block the address clarity.ms in your browser or ad blocker; the site keeps working. Clarity also supports the Global Privacy Control signal from your browser.
What is not on this site
Explicitly, because this is usually the question behind the question:
- No Google Analytics and no Google Tag Manager.
- No Hotjar and no Mouseflow. The only measurement is Microsoft Clarity, in the cookieless mode described above.
- No advertising pixel from Google, Meta or LinkedIn, and no remarketing lists.
- No chat widget and no A/B testing tool. The only third party script is Clarity's, above.
- No embeds that load by themselves, such as a YouTube player or a Google Maps map in the page.
The fonts no longer come from outside either. They used to be fetched directly from Google, which meant your browser connected to a Google server on every visit. Since 12 August 2026 they sit on our own server. So no font request goes to Google any more.
What these choices let us know and not know is stated honestly: we see how many page views there are and where people click and drop out, but we cannot recognise visitors or follow them across pages. Every view stands apart from the last. If we ever want to measure more than that, it can only be done with a real choice in advance, and then it will say so here.
These are choices and not obligations, and they cost us something: coarser figures, no retargeting, no chat widget. What they buy back is a page that loads only what it says it loads. That reaches further than privacy, because every third party script is also a request your visitor waits for and a host that can go down without you noticing. It is one of the first things we take apart in an SEO assignment, and one of the reasons we build in WordPress the way we do rather than stacking plugins that each pull in their own tracker. What your own site stores and calls today you can find out yourself, with the method described two sections down.
Clearing or blocking it yourself
You do not have to ask us to remove any of this. Everything above sits in your own browser and you remove it there yourself.
- All at once. In your browser settings you clear the data for a site, usually under a heading like privacy, cookies or site data. Search there for theseo.nl.
- Just close the tab. The package choice from the first row disappears as soon as you close the tab. Nothing further to do.
- Block it in advance. Set your browser so that sites may store nothing and this site still works. Only the dashboard demo will then start with the default display every time.
What you lose by clearing: the demo is back on its default settings and the site has forgotten the package you clicked. There is no more than that, because no more is stored.
What happens if something is ever added
Suppose we later did want to measure with cookies, or embed a video. Then these rules apply, and they are not optional:
- Anything that is not strictly necessary stays blocked until you actively say yes to it. Not loaded and removed afterwards, simply not loaded.
- Refusing is as easy as accepting. Equal buttons, no hidden second step, no box already ticked.
- You choose per purpose. Yes to one is not yes to another.
- You can always withdraw your choice. As soon as there is a choice screen, the link Cookie settings sits at the bottom of every page. Withdrawal works forwards: what happened before stays lawful, from that moment it stops.
- Refusing costs you nothing. The site keeps working.
This is how we would divide it, with the longest period we allow ourselves. Note what the fourth column is and what it is not: these are our own maximums and not statutory periods. Neither PECR, nor the ePrivacy Directive, nor the GDPR or the UK GDPR states a number of months for cookies. The thirteen months below come from a recommendation by the French supervisory authority CNIL that we adopted as an upper bound; no regulator in the United Kingdom, Ireland or the Netherlands applies that period as a standard.
| Category | What for | On what basis | Our own maximum |
|---|---|---|---|
| Necessary | Session, security, blocking abuse, protecting forms, remembering your cookie choice | Needed for the service you asked for, or our interest in keeping the site secure | The session, and at most twelve months for a choice that has to be kept |
| Preference | Light or dark, language, which columns you see | Consent, unless it is purely a setting you switch on yourself | At most twelve months |
| Analytics | Counting visits, measuring how pages perform | Consent | At most thirteen months, shorter where we can |
| Marketing | Advertising, retargeting, profiles across sites | Consent | According to the inventory in force at that time, never longer than what it says |
Today only the first row applies, and within it only the security cookie of the hosting provider. The Clarity measurement falls outside this table for as long as it puts nothing on your device; if it ever started using cookies, it would belong in the Analytics row and the choice would come first. The rest describes what would apply, not what happens.
Cookies here are not only cookies, incidentally. The same rules apply to everything placed on or read from your device: local storage, session storage, pixels, and recognition based on your device. Regulation 6 is written in exactly those terms, which is why we are too.
Links outward and payment pages
The site has links to places that are not ours. They load only when you click them, and are not quietly preloaded.
- Book a call. That button opens Google's calendar page. Only after your click does your browser connect to Google, and Google's cookies and terms apply there.
- Payment links. Paying happens on a Stripe page. That page belongs to Stripe, with their own cookies and their own statement.
- Downloads and repositories. Some downloads sit on GitHub. There too, their own policy applies after your click.
The free tools on this site work differently from what you might expect. What you enter goes to our own server, and that server talks to the parties doing the computation on your behalf. So your browser makes no connection to a third party itself, and nothing of that work is kept on your device. Which parties those are and what they get is in the privacy statement.
How we check that this is true
A cookie statement is only worth something if somebody holds it against reality. We do that like this, before every release:
- We open the site in a clean browser session, with no earlier cookies or storage.
- We record what network traffic arises and what ends up in cookies, local storage and session storage.
- We put that outcome next to our internal inventory and next to this page. If they differ, nothing goes live until it matches.
- A host, script or key we do not recognise is automatically a no. Not something to work out later.
Two things we cannot see for you. Extensions in your own browser can store something or add scripts themselves; we have no sight of that and no influence over it. And the network layer of the hosting provider can set a security cookie, as described above.
See something appear on your device that is not listed here? We want to know. Email it to sales@theseo.nl and we will find out and change this page, or the site.
Questions, complaints and changes
Questions about this page go to sales@theseo.nl, with the word cookies in the subject line. You get an answer from a person.
If we cannot resolve it together, you can complain. For the personal data side that is the supervisory authority where you are: the Autoriteit Persoonsgegevens in the Netherlands, the Information Commissioner's Office if you are in the United Kingdom, the Data Protection Commission if you are in Ireland. The routes are set out in full on the privacy statement.
For the electronic communications side of the storage rule there is a separate enforcement route in some countries. We do not name a body here, because we have not verified which one is competent for that specific route in the United Kingdom and in Ireland, and the rule on this site is that an authority without a source does not go on a page. If you want to lodge that kind of complaint and cannot find the right door, email us and we will look it up with you rather than guess at it.
If something changes on the site, this page changes with it. The order there is not optional: write down here what is coming first, only then switch it on. The version is at the top and the date of the last change is below.
This statement belongs with the privacy statement and the terms and conditions. Where they conflict, those two prevail over what is written here.
Last changed on 25 August 2026