Skip to main content
Shield Data Systems

Legal

Cookie notice

No cookies of our own and nothing that needs consent, so no banner. Two things still reach past the page and both are described here in full, along with how to check the claim yourself.

Effective 11 August 2026Version 1.0Privacy Act 1988 (Cth)

01The position in short

This website sets no cookies of its own. No analytics, no advertising, no tracking pixel, no session recording, no fingerprinting, no attempt to recognise you when you come back.

There is no consent banner, because there is nothing here to consent to.

Two things do reach past the page, and both are described in full below: a strictly necessary security cookie our hosting provider may set, and a request to Google's font servers for the two typefaces this site uses.

That is the whole notice. Everything after this is the reasoning and the detail, for anyone who wants to check the claim rather than take it.

02The Australian rule, which is not the European one

Australia has no cookie consent regime. There is no local equivalent of the European ePrivacy Directive, no statutory requirement to obtain permission before setting a cookie, and no obligation to show a banner. A banner on an Australian website is a design decision, and often an imported one.

What does apply is the Privacy Act 1988 (Cth). Where a cookie or a similar technology collects information about an individual who is reasonably identifiable, that information is personal information and the Australian Privacy Principles apply to it in the ordinary way: APP 3 on when it may be collected, APP 5 on telling you, APP 6 on what may then be done with it, APP 11 on keeping it safe and destroying it.

So the questions worth answering are not "did the user click accept". They are: did you need it, did you say so, and do you use it only for what you said. This page answers those three.

If you are reading from the European Economic Area or the United Kingdom, where consent would be required for anything beyond strictly necessary storage: there is nothing beyond strictly necessary storage here, so the position is the same.

03Why there is no banner

A consent banner exists to collect permission for storage that is not strictly necessary. There is none on this site, so a banner would be asking you to agree to nothing.

That is worse than leaving it out, for two reasons. It trains people to dismiss a control that genuinely matters on other sites. And it implies that something is being collected, which would make our own notice misleading in the opposite direction from the usual one.

If analytics, advertising or any other non-essential storage is ever added here, three things will happen before it loads: this page will be updated first, you will be asked, and refusing will be exactly as easy as accepting, with no pre-ticked boxes and no button that is quieter than the other one.

04What is actually stored on your device

Everything this website may store on your device
NameSet byPurposeLifetimeConsent needed
__cf_bmCloudflare, our hosting providerTells automated traffic from human traffic so abuse can be blocked. Strictly necessary to deliver the site30 minutes, refreshed while you are activeNo
cf_clearanceCloudflareSet only if you are shown a challenge and pass it, so you are not challenged again on every pageUp to 30 daysNo

That is the complete list. We set nothing ourselves, and neither of those is readable by us as an identifier for you. They exist because a website that can be hit by anything on the internet needs some way to tell a browser from a bot.

Nothing else is written. No local storage, no session storage, no IndexedDB, no cache entry used as an identifier, and no service worker.

05What this site does not do

Stated as a list, because an absence is easier to check than a promise.

  • No Google Analytics, and no Plausible, Fathom, Matomo, Umami or any other analytics product.
  • No advertising, no advertising cookies, no remarketing tag.
  • No Meta pixel, no LinkedIn Insight tag, no TikTok pixel, no conversion tracking of any kind.
  • No session recording, no heatmap, no scroll depth tracking, no rage click detection.
  • No A/B testing tool.
  • No embedded video, map, social widget, chat widget or comment system, each of which normally brings its own cookies with it.
  • No form, and therefore no form analytics. The only way to contact us is an email address you type into your own mail client.
  • No visitor identification or company lookup product of the kind that turns an IP address into a sales lead.
  • No fingerprinting, canvas or otherwise.
  • No third party JavaScript at all. The one script on the site is our own, it is served from this domain, and it handles the mobile menu and a fade.

You do not have to believe any of that. Open the Network and Application panels in your browser's developer tools and reload the page: what you find there is the authoritative answer, and it should match this list exactly. If it does not, that is a defect and we would like to hear about it.

06The one outbound request

The site loads two typefaces, Lora and Roboto Mono, from Google Fonts at fonts.googleapis.com and fonts.gstatic.com. That request tells Google's servers your IP address, your user agent and the page that referred you. Google states that the Fonts service sets no cookies and that the requests are not used for advertising or profiling.

It is still a request to a third party that you did not ask to make, and describing it accurately is better than omitting it because it is common. Self hosting the two files would remove it entirely and it is on the list of things to do.

If you block those two hosts, at the network level or with an extension, the site works perfectly well. It falls back to a serif and a monospace face already on your device, and no functionality depends on the download.

There is no other outbound request. No content delivery network for scripts, no icon service, no image host, no error reporting endpoint. Every other file the page needs comes from this domain.

07Server logs are not cookies, but you should know about them

Every web server records the requests it receives, and ours is no exception. Our hosting provider logs the IP address, the timestamp, the path requested, the user agent and the response code.

None of that is stored on your device, so it is not a cookie and it has nothing to do with consent. It is still personal information under the Privacy Act, and leaving it out of a page called "what this site collects" would make the page dishonest by omission.

The logs sit with the provider on its own cycle, currently under 30 days. They are used for delivering pages and defending against abuse, and for nothing else. We do not copy them into a database of ours, we do not join them to anything, and we do not analyse them for traffic reporting.

08Controlling storage yourself

Every major browser lets you block cookies, delete the ones already set, and inspect exactly what a site has stored. Blocking the two Cloudflare cookies described above may mean you are challenged more often, but the site will still work.

  • Chrome: Settings, then Privacy and security, then Third-party cookies, and Site data for what is already stored.
  • Safari: Settings, then Privacy, then Manage Website Data.
  • Firefox: Settings, then Privacy and Security, then Cookies and Site Data.
  • Edge: Settings, then Cookies and site permissions.

A private or incognito window discards everything at the end of the session, which for this site changes almost nothing, because there is almost nothing to discard.

09Do Not Track and Global Privacy Control

Both signals are honoured. That is an easy commitment to make here, because there is nothing to switch off: if either header is present, no additional storage or processing happens, and the same is true if neither is.

We say it anyway. A site that quietly ignores these signals has made a decision it would generally rather you did not notice, and stating the position costs a sentence.

10The service would not use cookies either

Cookies are a browser mechanism, and the verification service is not a browser product. A rehearsal runs against a customer's backup on a schedule, with no user, no browser and no session.

If a customer dashboard is ever built, it will need at minimum a session cookie to keep somebody signed in, and that is a strictly necessary cookie in anybody's classification. When it exists it will be added to the table above, with its name, its lifetime and its purpose, before it ships rather than after.

11If this changes

Anything that stores information on your device beyond what is listed on this page gets added to the table first, with a new effective date, before it goes live. Where the law that applies to you requires consent, we will ask before it loads rather than after.

We do not publish previous versions as separate pages, but we keep them. If you want to know what this page said on a particular date, ask and we will send you that version.

12Questions and complaints

Email [email protected]. A question about this page is answered within 5 business days. A privacy request is answered within 30 days.

If our answer does not satisfy you, you can complain to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au. There is no fee, you do not need a lawyer, and you do not need our agreement.

SHIELD DATA SYSTEMS PTY LTD, an Australian proprietary company, ACN 696 553 036, ABN 46 696 553 036, New South Wales, Australia. The full account of what we hold and why is in the privacy policy.