Your current choice
Checking your saved preference…
This page explains every cookie and similar storage technology used on designedbyanthony.com and our related subdomains (admin.designedbyanthony.com, clients.designedbyanthony.com, cdn.designedbyanthony.com, designedbyanthony.online).
How consent works on this site
When you first visit, a banner appears at the bottom of the screen. Nothing optional runs until you accept it — on a first visit, before you choose, this site sets no cookies at all.
You have two choices, and both are one click:
- Accept all — allows the first-party analytics described below.
- Reject non-essential — nothing optional ever loads.
Either choice is recorded in a first-party cookie named anthony_cookie_consent, which stores only the word all or essential. It is strictly necessary (it is what stops us asking you again), lasts 365 days, and is set with SameSite=Lax and the Secure flag over HTTPS. It contains no identifier and is never sent to a third party.
The banner is our own code — a few lines of plain JavaScript in the page. There is no third-party consent-management platform involved.
Changing your mind
Go to this page (Cookie Policy, linked in the footer of every page) and use “Change or withdraw my choice” at the top. That clears the record and brings the banner straight back, so withdrawing is exactly as easy as granting.
You can also delete the anthony_cookie_consent cookie in your browser to reset the choice.
Always-on (essential — no consent required)
Strictly necessary to load the site, keep it secure, or function as you’d expect. The GDPR and the ePrivacy Directive both treat strictly-necessary cookies as consent-exempt.
| Vendor | Cookie / storage | Purpose | Retention |
|---|---|---|---|
| ANTHONY. (first-party) | anthony_cookie_consent | Stores your consent choice so we don’t ask again | 1 year |
| Cloudflare (CDN + WAF) | __cf_bm, cf_clearance, cf_chl_* | Bot mitigation, DDoS protection, challenge-response | Session to 30 days |
| Cloudflare Turnstile | cf_turnstile_* (challenge solve) | Anti-spam on the audit + contact forms | Session |
| Cloudflare Access (admin / client-portal subdomains only) | CF_Authorization, CF_AppSession | Authenticates admin and client-portal sessions. Not set on designedbyanthony.com itself. | 24 hours |
Optional — Analytics
| Vendor | Cookie | Purpose | Retention | |---|---|---|---| | VertaFlow pixel (our own product, first-party) | None | Counts page views and conversion events so we can see which pages work and which are broken. Served from our own domain and written to our own analytics store. We do not sell or share it. | No cookie is set |
The VertaFlow pixel loads only if you chose “Accept all”. It is served same-origin from designedbyanthony.com/vf/… rather than a third-party ad domain, and it sets no cookie and stores no identifier in your browser.
If you reject, the pixel script is never added to the page at all — it is not loaded-then-disabled.
Error monitoring
We use Sentry to capture JavaScript errors and Worker exceptions so we can fix crashes. Sentry sets no browser cookies here and records no session replays of normal visitors. If an error fires, it transmits the error stack, the URL, and your browser/OS string — but no form input values, no email addresses, and no cookies.
What is NOT on this site
For clarity, none of the following are used anywhere on designedbyanthony.com:
- Google Analytics (any version), Google Ads tags, or Google Tag Manager
- Cloudflare Zaraz or any other third-party tag manager
- Amplitude, Mixpanel, or any third-party product-analytics SDK
- Facebook / Meta pixel, LinkedIn Insight Tag, TikTok Pixel, X conversion tracking
- Retargeting or advertising pixels of any kind
- Session replay tools (Hotjar, FullStory, Mouseflow, etc.)
- Fingerprinting libraries
- The IAB Transparency & Consent Framework (we run no advertising vendors, so there is nothing for it to govern)
Payments and signing
Contracts are signed through VertaFlow, our own platform. When you reach the payment step, card details are entered into Stripe Elements, which Stripe serves and which sends card data directly to Stripe — we never receive or store your card number. Stripe sets its own cookies on that step for fraud prevention; those are strictly necessary to take a payment and are described in Stripe’s own privacy policy.
Questions
Email anthony@designedbyanthony.com with any cookie or data question. We respond personally within one business day.