Legal

Cookie notice

A short page, because there is not much to report. Three third parties can run in your browser, and not one of them starts until you accept it or begin something yourself.

Last updated 19 August 2026

The short version

This site does not measure you unless you say it may. There is no advertising pixel, no session recording and no social embed anywhere on veyrareach.com. Google Analytics is the only measurement here, and it stays unloaded until you accept it in the banner. Two other third parties run in your browser, and only when you deliberately start something: Cloudflare Turnstile when you ask for a promotional code or begin checkout, and Stripe when you pay.

Typefaces are served from our own domain. Next.js self-hosts them as static assets at build time, so your browser never calls a font provider while you read this page.

What actually runs, and when

The table below is taken from the code rather than from a template. If a script is not listed here, it is not on the site.

WhoWhen it runsWhat it is forWhat it stores
VeyraEvery pageServing the site itselfNothing unless you accepted analytics. veyrareach.com sets no cookie of its own, and there is no login or session on the public site. If you accepted, Google Analytics sets its own cookies on this domain to recognise a returning visit; declining, or withdrawing later from the footer, leaves none.
Cloudflare TurnstileOnly when you open the checkout email step or the Summer Sweep claim boxProves the request comes from a person rather than a script, before an email address is acceptedTurnstile sets cf_clearance, which records that a challenge was passed so you are not asked again on every step, and __cf_bm, Cloudflare's bot management cookie, which expires after about 30 minutes. It also keeps short-lived values in browser storage while a challenge is running. None of it identifies you, none of it follows you to other sites, and Turnstile is built specifically not to profile the visitor.
StripeOnly on the checkout page, once you reach the payment stepTakes the payment and screens it for fraudStripe sets __stripe_mid, a machine identifier lasting about a year, and __stripe_sid, a session identifier lasting about 30 minutes. Both exist to spot card fraud, and Stripe describes them as necessary for that purpose. Worth knowing: Stripe.js is not loaded on the pricing page at all. It arrives only when you open the checkout, so these are not set by browsing the site and comparing plans.

What we do not do

  • No analytics unless you accept it. Nothing counts your visit, your scroll depth or your route through the site until you say yes, and a refusal is remembered.
  • No advertising or retargeting pixels, and no cross-site tracking of any kind.
  • No session recording or heatmaps.
  • No social network embeds, no comment widgets, no chat widget.
  • No video. The site has no video element and loads no player.
  • No selling or sharing of anything a cookie could hold. Your data is never resold and never pooled into someone else's model.

How to control cookies yourself

Every browser lets you see what a site has stored, delete it, and block future storage, usually under Settings and then Privacy. Blocking storage for veyrareach.com costs you nothing while you read the site. It will, however, break the checkout: Stripe cannot complete a payment or run its fraud checks without it, and the Turnstile challenge cannot record that you passed.

Changes to this notice

If we add a script that stores anything, this page changes on the same day and the date at the top changes with it. If that script is non-essential, a consent banner ships with it.

Questions

Write to hello@veyrareach.com. The privacy policy explains what happens to the data behind all of this, and the sub-processors page names every vendor involved.

Nothing measures you until you say yes

See what Veyra does with the data that matters instead: your pipeline, on your market.