COOKIES AND STORAGE TECHNOLOGIES POLICY
PURPOSE OF THIS POLICY
This Cookies and Storage Technologies Policy explains how Stratosphere Ventures Limited uses cookies and other technologies that store information on, or access information from, your computer, mobile telephone, tablet or other device when you visit or use our website.
It explains:
- what cookies and storage or access technologies are;
- which categories we may use;
- why we use them;
- when consent is required;
- when a statutory exception may apply;
- how third parties may be involved;
- how long relevant information may be retained;
- how you may accept, reject, object to or withdraw from particular uses; and
- how to contact us about our use of these technologies.
This Policy should be read alongside our Privacy Policy and Website Terms and Conditions.
WHO WE ARE
The website is operated by:
References to “Stratosphere Ventures”, “we”, “us” or “our” mean Stratosphere Ventures Limited.
APPLICABLE LEGAL FRAMEWORK
Our use of cookies and other storage or access technologies is governed principally by:
- the Privacy and Electronic Communications (EC Directive) Regulations 2003, commonly known as PECR;
- the UK General Data Protection Regulation;
- the Data Protection Act 2018; and
- the Data (Use and Access) Act 2025.
PECR regulates the storing of information on, and access to information stored on, a subscriber’s or user’s terminal equipment.
Where the information obtained through a storage or access technology constitutes personal data, or is combined with other information so that an individual is identifiable, UK data protection law also applies.
WHAT COOKIES ARE
Cookies are small data files that a website may place on a device when the website is visited.
Cookies may allow a website to:
- recognise a browser or device;
- maintain a session;
- remember a selection;
- support login or authentication;
- protect forms and systems;
- record consent or objection choices;
- understand website use;
- measure performance; or
- enable third-party functionality.
Cookies may contain identifiers, timestamps, preferences, technical data or other information relating to a website session or device.
OTHER STORAGE AND ACCESS TECHNOLOGIES
This Policy also applies to technologies other than conventional cookies where they store information on, or access information from, your device.
These may include:
- browser local storage;
- session storage;
- software development kits;
- tracking pixels;
- web beacons;
- scripts and tags;
- embedded resources;
- link-decoration technologies;
- navigational tracking;
- cache-based technologies;
- device or browser identifiers;
- application storage;
- server-assisted identifiers linked to device information; and
- device-fingerprinting techniques.
A technology does not fall outside PECR merely because it is not called a cookie.
FIRST-PARTY AND THIRD-PARTY TECHNOLOGIES
A first-party technology is set or controlled through the domain you are visiting.
A third-party technology is provided or controlled by another organisation whose service, content, software or functionality has been incorporated into the website.
Third parties may include, depending on the website’s current configuration:
- hosting and infrastructure providers;
- website security providers;
- analytics providers;
- email or form-processing services;
- video or media platforms;
- social-media platforms;
- booking or payment providers;
- font, map or content-delivery services; and
- other technology suppliers.
The current Cookie Register and preference centre must identify the relevant provider by name where a third party stores or accesses information through this website.
A general reference to unspecified “partners” does not replace the requirement to provide sufficiently clear information about relevant third parties.
SESSION AND PERSISTENT TECHNOLOGIES
A session cookie or session-storage item normally expires when you close your browser or when the relevant session ends.
A persistent cookie or persistent-storage item remains for a specified period or until:
- it expires;
- you delete it;
- the website replaces it;
- the relevant provider removes it; or
- your browser or device removes it.
The duration must be appropriate and proportionate to the purpose for which the technology is used.
OUR TECHNOLOGY CATEGORIES
We classify storage and access technologies according to their actual purposes rather than merely the label assigned by a supplier.
A technology used for more than one purpose will be assessed against each purpose. An exception will apply only where all applicable legal conditions are met.
8.1Communication technologies
These technologies may be used solely to enable or facilitate the transmission of a communication over an electronic communications network.
Examples may include technologies required for:
- routing information;
- network load balancing;
- preserving the sequence of transmitted data;
- detecting transmission errors; and
- delivering communications between your device and the website.
Where the sole-purpose communication exception applies, consent is not required under PECR.
8.2Strictly necessary technologies
These technologies are essential to provide a website service or function that you have requested.
Depending on the website’s actual functionality, they may support:
- secure page delivery;
- fraud and abuse prevention;
- website or form security;
- authentication;
- maintaining an authorised administrative session;
- processing a form submission;
- load balancing;
- technical fault detection;
- recording a selection you have expressly made;
- preserving a requested session; or
- remembering your cookie or privacy choices.
A technology is not strictly necessary merely because it is useful to us, improves our commercial performance or makes analytics, advertising or marketing easier.
Strictly necessary technologies may operate without consent where the statutory conditions are met.
8.3Statistical technologies
Statistical technologies may be used to collect information about how visitors use the website with a view to improving the website or service.
This may include aggregate information about:
- the number of visits;
- pages viewed;
- broad user journeys;
- average time spent;
- device or browser categories;
- referral sources;
- page-loading performance;
- bounce or exit rates;
- aggregated interactions; and
- coarse location information that does not identify an individual.
We may rely on the statutory statistical-purposes exception only where all applicable requirements are satisfied, including that:
- the sole purpose is collecting statistical information about use of the website or service;
- the information is used with a view to improving the website or service;
- resulting information is aggregate statistical information;
- it is not used to identify, profile, monitor or make decisions about particular visitors;
- individual-level information is not retained longer than necessary for aggregation;
- any third-party provider acts only on our behalf for the permitted improvement purpose;
- the information is not combined with unrelated data;
- the technology is not used for advertising or cross-site tracking;
- clear and comprehensive information is provided; and
- a simple and free means of objecting is available.
Where these requirements are not met, we will not rely on the statistical-purposes exception. Consent must be obtained before the relevant non-exempt technology operates.
8.4Appearance and functionality technologies
These technologies may be used to adapt or enhance how the website appears or functions in accordance with a user’s preference or device.
This may include:
- adapting layouts for screen dimensions;
- remembering a language choice;
- applying a selected visual theme;
- adjusting functionality to suit device capability;
- remembering an accessibility preference; or
- supporting another user-selected presentation preference.
We may rely on the appearance or functionality exception only where:
- the purpose falls within the statutory exception;
- any related personal-data processing is limited to what is necessary;
- the technology is not used for behavioural profiling or advertising;
- clear and comprehensive information is provided; and
- a simple and free means of objecting is available.
This exception does not cover selecting content or advertising based on inferred interests, browsing history or behavioural profiles.
8.5Functional technologies requiring consent
Some technologies may provide optional features or convenience but fail to satisfy the requirements of the strictly necessary or appearance exceptions.
These may include optional:
- embedded media;
- enhanced personalisation;
- social-media functionality;
- third-party content;
- chat functions;
- advanced preferences; or
- integrations not essential to a service you requested.
Where no exception applies, these technologies will be disabled until valid consent is given.
8.6Marketing and advertising technologies
Marketing and advertising technologies may be used to:
- measure advertising effectiveness;
- attribute conversions;
- build audiences;
- monitor campaigns;
- recognise users across services;
- personalise advertising;
- cap advertising frequency;
- conduct advertising-related market research; or
- support behavioural advertising.
We will not use a PECR exception for online-advertising purposes.
Where such technologies are used, valid consent must be obtained before they store information on or access information from your device.
At the date of this Policy, no statement in this section should be interpreted as confirming that marketing or advertising technologies are active unless they are identified in the current Cookie Register and preference centre.
8.7Emergency-assistance technologies
PECR contains a limited exception relating to the use of storage or access technologies whose sole purpose is to identify the geographical position of a user’s device to provide emergency assistance.
Our ordinary public website is not intended to provide an emergency-assistance service.
We will not rely on this exception unless the website’s functionality and the circumstances genuinely satisfy its statutory conditions.
TECHNOLOGIES THAT REQUIRE CONSENT
Unless a valid statutory exception applies, we must obtain valid consent before storing information on, or accessing information stored on, your device.
Consent must be:
- freely given;
- specific;
- informed;
- unambiguous;
- demonstrated by a clear affirmative action;
- capable of being evidenced; and
- capable of being withdrawn.
We will not treat any of the following as valid consent:
- continuing to browse;
- inactivity;
- silence;
- closing a banner without making a choice;
- a pre-selected setting;
- a pre-ticked box; or
- acceptance that is bundled unnecessarily into general Website Terms.
Non-exempt technologies must not operate before the required consent has been obtained.
ACCEPTING AND REJECTING TECHNOLOGIES
Where consent is required, the website’s consent mechanism should provide a genuine choice.
Users must be able to:
- accept the relevant non-exempt technologies;
- reject the relevant non-exempt technologies;
- make category-level choices where appropriate;
- obtain further information before deciding; and
- withdraw or alter consent later.
Rejecting non-essential or other non-exempt technologies should be no more difficult than accepting them.
The design must not use misleading wording, obscured controls, unequal friction or interface techniques intended to pressure users into accepting.
Strictly necessary technologies may remain active because they are required to provide requested functions or maintain essential security.
OBJECTING WHERE AN EXCEPTION APPLIES
Where we rely on the statistical-purposes or appearance or functionality exception, we must provide a simple and free means of objecting.
The website’s cookie or privacy controls should therefore allow you to object to relevant exempt statistical or appearance technologies without:
- paying a fee;
- creating an account unnecessarily;
- navigating through disproportionate steps;
- suffering a material reduction in an unrelated service; or
- being asked repeatedly after an objection has been recorded.
Where technically practicable, an objection should prevent further storage or access for the relevant purpose.
Limited storage may be necessary to remember the objection itself.
WITHDRAWING OR CHANGING A CHOICE
You may change your cookie and storage-technology choices at any time through the website’s Cookie Settings, Privacy Settings or equivalent persistent control.
Withdrawing consent must be as easy as giving it.
Changing a choice will ordinarily affect future use of the relevant technologies. It may not automatically remove information already:
- stored on your device;
- transmitted before withdrawal;
- lawfully aggregated;
- anonymised; or
- retained where another lawful basis and applicable legal obligation permit retention.
You may separately delete cookies or website storage through your browser or device settings.
COOKIE PREFERENCE RECORD
We may store a strictly necessary preference record to remember whether you:
- accepted;
- rejected;
- objected;
- withdrew;
- selected particular categories; or
- dismissed a notice in a manner that does not amount to consent.
The preference record may include:
- a consent or preference identifier;
- selected categories;
- the policy or banner version;
- the date and time of the choice;
- the method used;
- the expiry date; and
- technical information necessary to apply or evidence the choice.
This information will not be used for unrelated advertising or profiling.
The preference record will be retained only for an appropriate period and renewed where necessary to maintain an accurate, current choice.
CURRENT COOKIE AND TECHNOLOGY REGISTER
The website must maintain a current register identifying the storage and access technologies actually deployed.
The register forms part of this Policy and should be available through the website’s cookie-preference interface or immediately adjacent policy content.
For each technology, the register must state, as applicable:
- name or identifier;
- provider;
- first-party or third-party status;
- category;
- purpose;
- information stored or accessed;
- whether consent is required;
- the applicable exception, where relied upon;
- duration or expiry;
- when the technology is activated;
- whether information is transferred to another country; and
- a link to relevant third-party information where appropriate.
The register must reflect the website’s real technical behaviour.
We will not knowingly invent, omit or misclassify technologies in the register.
A supplier’s default classification does not remove our responsibility to verify the technology’s actual operation and purpose.
CURRENT REGISTER FORMAT
The live website should present the register in substantially the following format:
| Technology | Provider | Category | Purpose | Consent or exception | Duration |
|---|---|---|---|---|---|
| Cookie preference storage | Stratosphere Ventures Limited | Strictly necessary | Remembers your cookie and storage-technology choices so those choices can be applied on future visits. | Strictly necessary for providing and remembering the cookie-choice function requested by the visitor. | 12 months |
| Secure administrative session | Stratosphere Ventures Limited | Strictly necessary | Maintains secure authenticated access for authorised administrative users. | Strictly necessary to provide the secure sign-in session requested by an authorised user. | Up to 12 hours or until sign-out |
| External delivery of display and body typefaces | Google LLC (Google Fonts) | Appearance and functionality | Delivers the typefaces used in the site's design (Inter, Bebas Neue, Cormorant Garamond, Manrope). When the browser requests a font file, Google receives the request, including the visitor's IP address, as an unavoidable technical consequence of that HTTP request. No cookie or storage item is set on this domain by the font endpoints themselves. | You can enable or disable external font delivery through the site's Cookie Settings. Where disabled, the site renders using system typefaces and no request is made to Google. | Per-request (no persistent cookie set) |
WEBSITE ANALYTICS
The website may use analytics to understand aggregate use and improve performance, content and navigation.
Before analytics operates without consent under the statistical-purposes exception, we must verify that:
- the sole purpose is eligible statistical analysis;
- information is used only to improve the website or service;
- results are aggregated;
- visitors are not tracked or profiled individually;
- the technology is not connected to advertising;
- individual-level data is removed when no longer needed for aggregation;
- any provider acts as a processor solely on our instructions;
- data is not combined with unrelated datasets;
- a simple, free objection mechanism is available; and
- all relevant details appear in the live register.
Where an analytics configuration involves:
- unique user tracking;
- persistent visitor profiles;
- advertising attribution;
- cross-site measurement;
- demographic profiling;
- session replay;
- individual click recording;
- conversion sharing;
- combining activity with external account data; or
- another purpose outside the exception,
the relevant technology must remain disabled until valid consent is obtained.
HOSTING, SECURITY AND INFRASTRUCTURE
Our hosting, content-delivery, database, security and infrastructure providers may process technical information needed to:
- deliver pages;
- route traffic;
- maintain availability;
- balance server load;
- identify technical faults;
- prevent abuse;
- secure forms;
- authenticate authorised access;
- protect systems; and
- investigate security events.
A technology will be treated as exempt only where its actual purpose and use meet the relevant statutory conditions.
Security terminology alone does not make a technology strictly necessary.
Security information may also constitute personal data and will be processed in accordance with our Privacy Policy.
CONTACT FORMS
Our contact form may use storage or access technologies where reasonably necessary to:
- transmit the submission;
- prevent duplicate submissions;
- detect automated abuse;
- apply rate limits;
- protect the form;
- preserve a requested session; or
- maintain essential functionality.
Any technology used for unrelated analytics, advertising, profiling or marketing will not be treated as strictly necessary merely because it appears on the same page as the form.
Submitting a form does not amount to consent to unrelated non-essential technologies.
AUTHORISED ADMINISTRATIVE ACCESS
Restricted administrative or studio areas may use technologies required to:
- authenticate an authorised user;
- maintain a secure session;
- prevent unauthorised access;
- enforce session expiry;
- protect against forgery or session misuse; and
- preserve essential security settings.
Where these technologies are essential to provide the secure access requested by an authorised user, the strictly necessary exception may apply.
Administrative session technologies must not be repurposed for unrelated tracking, advertising or behavioural profiling.
EMBEDDED CONTENT
The website may include or later introduce embedded content, such as:
- video;
- audio;
- maps;
- calendars;
- booking tools;
- social-media content;
- payment interfaces; or
- third-party forms.
Embedded providers may seek to store or access information when a page loads or when you interact with the content.
Where possible, we will use privacy-enhancing settings and prevent non-exempt third-party technologies from loading before the required choice.
Where appropriate, embedded content may be:
- blocked until consent is given;
- activated only when you choose to use it;
- presented through a privacy-enhanced mode; or
- replaced with an external link.
The live register must name relevant embedded providers and describe their purposes.
EXTERNAL LINKS AND SOCIAL MEDIA
The website may link to third-party websites or social-media pages.
A normal link does not, by itself, necessarily cause the third party to store or access information through our website. Once you follow the link, the third party’s website and technologies are governed by its own terms and privacy information.
Where we embed third-party plugins, pixels, scripts or social-media functionality that operates on our website, the relevant technology must be assessed and disclosed in the live register.
Tracking through social-media plugins or advertising tools requires consent where no statutory exception applies.
BROWSER AND DEVICE CONTROLS
Most browsers and devices allow you to:
- view stored cookies;
- delete cookies;
- block cookies;
- restrict third-party cookies;
- clear local storage;
- prevent cross-site tracking;
- control site permissions; or
- configure privacy preferences.
The precise controls depend on your browser, operating system and device.
Blocking all cookies or storage may affect:
- secure sessions;
- form functionality;
- preference records;
- authorised login;
- accessibility settings; or
- other requested features.
Browser controls supplement, but do not replace, the website’s obligation to provide compliant information and choices.
DO NOT TRACK, GLOBAL PRIVACY SIGNALS AND BROWSER PREFERENCES
Some browsers or extensions transmit privacy preference signals such as “Do Not Track” or other opt-out indicators.
Not every signal has the same technical meaning or legal status.
Where a signal reliably communicates a relevant objection or choice and can reasonably be honoured, we will consider it as part of our privacy controls.
You should continue to use the website’s Cookie Settings to record specific choices where available.
We will not describe the absence of a universally adopted signal standard as permission to disregard choices made through our own controls.
PERSONAL DATA OBTAINED THROUGH TECHNOLOGIES
Information obtained through cookies or other storage and access technologies may constitute personal data where it relates to an identified or identifiable person.
Depending on the technology, this may include:
- internet protocol address;
- device identifiers;
- browser details;
- timestamps;
- page activity;
- referral information;
- session identifiers;
- consent choices;
- approximate location;
- authentication information; and
- interaction data.
Where personal data is processed, our Privacy Policy explains:
- our purposes;
- lawful bases;
- legitimate interests;
- recipients;
- international transfers;
- retention;
- security;
- individual rights; and
- complaint arrangements.
Consent under PECR and a lawful basis under the UK GDPR are related but distinct legal requirements. Satisfying one does not automatically satisfy the other.
INTERNATIONAL PROCESSING
Some technology suppliers may process information outside the United Kingdom.
Where this involves personal data, we will apply the international-transfer requirements described in our Privacy Policy.
The live register or related privacy information should identify relevant providers and explain material international-processing arrangements where required.
RETENTION AND DURATION
We will not retain a cookie or continue accessing information for longer than is reasonably necessary and proportionate to its purpose.
When determining an appropriate duration, we consider:
- the nature of the purpose;
- whether the technology is session-based or persistent;
- the sensitivity of the information;
- user expectations;
- security requirements;
- whether a shorter period would achieve the purpose;
- supplier defaults;
- legal obligations;
- whether information is aggregated or anonymised; and
- the risk to individuals.
We will not rely solely on a browser’s maximum cookie lifetime to determine an appropriate duration.
The verified duration of each deployed technology must appear in the live register.
CHILDREN
The general website is directed towards business and professional audiences and is not specifically designed for children.
We do not knowingly use advertising or profiling technologies to target children through the website.
Where the website introduces functionality likely to be accessed by children, we will assess the technology against:
- applicable data protection law;
- PECR;
- the Children’s Code where relevant;
- the child’s age and understanding;
- data minimisation;
- privacy by default; and
- the need for parental involvement or consent.
TECHNOLOGY AUDITS
We will review the website’s storage and access technologies periodically and when material technical changes occur.
An audit may include:
- inspecting browser storage;
- reviewing source code and scripts;
- examining network requests;
- checking tags and embedded resources;
- verifying third-party services;
- identifying cookies and local storage;
- checking expiry periods;
- testing the website before and after consent;
- testing rejection and withdrawal;
- verifying objections;
- checking mobile and desktop behaviour;
- identifying undocumented technologies;
- removing unnecessary technologies; and
- updating the live register and this Policy.
The audit should be performed on the production website from a clean browser environment and, where appropriate, across multiple devices and routes.
CHANGES TO PROVIDERS OR TECHNOLOGIES
We may change a technology or provider where reasonably necessary for security, functionality, performance or business operations.
Before introducing or materially changing a technology, we should assess:
- its purpose;
- information stored or accessed;
- whether personal data is involved;
- the provider’s role;
- third-party use;
- transfers;
- retention;
- applicable PECR exception;
- whether consent is required;
- whether an objection mechanism is required; and
- whether this Policy, the live register or consent interface must be updated.
A new non-exempt technology must not be activated merely because the Policy contains a broad category capable of describing it.
CHANGES TO THIS POLICY
We may update this Policy to reflect:
- legal or regulatory developments;
- updated ICO guidance;
- new or removed website functionality;
- changes to providers;
- changes to technologies;
- corrected classifications;
- modified durations;
- revised consent or objection controls; or
- improvements in transparency.
The current version will display its effective date.
Where a material change affects a previous consent or significantly changes a purpose, provider or use, we will seek a fresh choice where legally required.
COMPLAINTS AND QUESTIONS
Questions, objections or complaints about cookies or other storage and access technologies may be sent to:
Please include:
- the device or browser used;
- the website page concerned;
- the approximate date and time;
- the technology or issue identified;
- relevant screenshots or technical details where available; and
- the outcome sought.
Data protection complaints will be handled under the complaints procedure in our Privacy Policy.
INFORMATION COMMISSIONER’S OFFICE
You may raise a concern with the Information Commissioner’s Office, the UK supervisory authority responsible for PECR and data protection law.
Telephone: 0303 123 1113
Further information is available through the ICO’s official website.