Skip to main content
ZAAPTO

Regulation 6, Privacy and Electronic Communications (EC Directive) Regulations 2003

Storage on your device

Chapter three of the ZAAPTO handbook. Each chapter takes one boundary and states what crosses it. This one takes the shortest boundary of the lot: the line between a web server and the browser you are reading this in.

Effective 15 August 2026 Handbook chapter 3 ZAAPTO LTD, company number 16938315

1. The boundary this chapter describes

Every page ZAAPTO publishes sits behind one edge that you control outright: the line between a web server and the machine in your hands. Files travel across it one way, requests the other, and a small part of what travels is permitted to stay behind on your hardware after the tab closes. An inventory of that residue is the whole subject of this chapter.

The handbook deliberately keeps its boundaries apart. Whatever a browser leaves on your equipment belongs here. Whatever travels onward — into ZAAPTO's hands, to a supplier, or out of the country — belongs to the privacy notice, which is laid out to the same plan.

Four words are worth fixing before the inventory starts. A cookie is a short labelled string a server asks a browser to keep and to hand back on later visits to the same name. Local storage and session storage are roomier stores that a page's own script can write and read. IndexedDB is a small database inside the browser with much the same character. A service worker is a script that installs itself on your device and can go on answering requests after you have navigated away.

Regulation 6 governs all of them at once, because the rule it states is about writing to and reading from a reader's equipment rather than about any single technique. Listing only cookies would leave three quarters of the boundary undescribed, so all of it is described.

2. What this site writes across it

zaapto.uk is a set of static documents. Nothing here carries a sign-in, a basket, a saved position, a preference switch or a language choice, so there is no function whose job is to remember you between one page and the next.

The consequence at this boundary is straightforward: for its own purposes, this website asks your browser to retain nothing at all. No identifier is written into a cookie. No key is placed in local or session storage. No database is opened. No service worker is registered. There is no tracking pixel, no measurement beacon, and no routine that tries to recognise your device by the shape of its configuration.

That follows from how the site was built rather than from a promise made about it. Pages are delivered with a content security policy that enumerates every host a page may talk to. Two font hosts are on that list. A measurement script has nowhere on this site to send a reading, because the policy the server issues would refuse the connection.

Short version. Sections 3 and 4 are the only crossings that produce anything at all, and both are open to inspection by the method in section 7.

3. Storage the delivery platform may write

The pages reach you through Cloudflare, which ZAAPTO uses as its hosting and delivery provider and which acts on ZAAPTO's instructions. Where that platform decides a request is worth screening, its protection layer can put a short-lived entry on the browser that made it. Two such entries are possible on this domain.

Entries the delivery platform may place while serving zaapto.uk
Entry Placed by Occasion Job it does Lifespan Permission needed
__cf_bm Cloudflare, acting on ZAAPTO's instructions On a request the platform screens for automated traffic Tells a person browsing apart from a script, so the site stays reachable while being crawled hard Roughly half an hour after the most recent request None. It is strictly necessary to a service you asked for
cf_clearance Cloudflare, acting on ZAAPTO's instructions Only where a security challenge has been shown to you and answered Records that the challenge was answered, so it is not put to you again on the following page Whatever the challenge configuration allows, normally under an hour None, on the same footing

Scroll the table sideways where your screen is too narrow to hold it.

Neither entry carries a name, a preference, a profile or an advertising identifier, and neither is read back by ZAAPTO. A given visit may produce one of them, both, or neither, which is why this chapter says the platform may write and does not promise you a fixed result.

4. What crosses without being stored

Three things cross this boundary and leave nothing behind on your device. They still belong in the inventory, because a reader who checked only the cookie jar would miss all three.

4.1 Lettering

These pages are set in Newsreader and Instrument Sans. Your browser collects the font files themselves from fonts.gstatic.com, having first collected the small stylesheet that names them from fonts.googleapis.com. Collecting a file is not the same as keeping one: neither request creates an entry on your device. What each request does do is show Google the network address your connection came from, which browser and operating system you are running, and which page needed the lettering. That is a disclosure travelling outward rather than storage staying behind, so it is dealt with at the right boundary — in the privacy notice, where Google is named as a recipient and the position on data leaving the country is set out.

4.2 The request line

Loading any file produces a record at the server end: an address, a moment in time, a path, a response code, a browser string. That record sits with the hosting provider, not with you, and it is inventoried in the privacy notice along with how long it survives.

4.3 Your browser's own cache

The stylesheet, the script, the icon and the font files are held by your browser so that a second page arrives faster than the first. Caching is your browser's housekeeping rather than a store this site controls. It holds documents, not conclusions about you, and emptying it costs you nothing but one slower page load.

6. Refusing the crossing

None of this needs taking on trust, and most of it can simply be switched off at your end.

  • Blocking cookies for this domain in your browser's per-site permissions stops the platform entries in section 3 from persisting. A security challenge may then appear more often than it otherwise would, since the note that you had already answered one was the thing being kept.
  • A content blocker, a privacy extension, or any setting that refuses requests to other hosts will stop the font collection described at 4.1. Pages then draw in a serif and a sans already installed on your machine. Every word survives the substitution; only the shapes of the letters change.
  • Script is not load-bearing here. Switching JavaScript off costs you a question list that no longer folds shut and a header that stops reacting to scroll. All the text stays where it is and stays readable.

Browser controls move between versions and between platforms, so the dependable route is your own browser's help pages under site permissions or content settings. A menu path printed on this page would be stale before long, and a stale instruction is worse than none.

7. Auditing the boundary yourself

Your browser already ships with developer tools. Open them, go to whichever panel is labelled for storage, and read off the entries recorded against zaapto.uk. Then move to the panel that lists network activity, which names every host a page reached for. Hold both readings against sections 2, 3 and 4.

This chapter is written so that the check takes about a minute and so that its result is unambiguous. If your browser shows you something the inventory above does not account for, that is worth an email to [email protected], and it will be treated as a defect in the page rather than a difference of opinion.

8. Revisions to this chapter

The inventory describes the site as it stands on the date printed at the top. Should a function ever be added that genuinely has to remember something about a reader, this chapter is rewritten before that function goes live, and the strictly-necessary reasoning in section 5 will not be stretched over the top of it. A change of that kind moves the effective date and the chapter number stays the same.

Questions about anything written here go to [email protected]. The other two chapters of the handbook are the privacy notice, which follows the same data across every boundary ZAAPTO deals with, and the terms of use, which states what is agreed at each of them.