What this Policy covers
This Policy explains cookies, pixels, tags, local storage, software-development kits and similar technologies used on bespokelearning.io and, where stated, the Bespoke portal. It should be read with the Privacy Policy.
A cookie is a small text record stored by a browser. Similar technologies may store a preference locally or send a request containing an identifier. “First party” means set for our domain; “third party” means a separate provider can read or receive it.
Our global opt-in approach
Only strictly necessary technologies may operate before your choice. Analytics, session replay, personalisation and advertising technologies remain off until you affirmatively enable the relevant category. Reject All is presented with prominence equivalent to Accept All, and refusing does not block the core public site.
Consent is specific by category, freely given and withdrawable. We store the choice itself so we do not ask on every page. We ask again after a material change or when the saved choice expires, normally within 12 months. Withdrawing consent stops future optional tracking but cannot delete data a provider lawfully received before withdrawal; you may also exercise privacy rights.
Technology categories
Cookie names can change when a provider updates its service, and not every listed name appears for every visitor. Browser developer tools show the current records on your device. A technology that becomes non-essential is not treated as necessary merely because a provider labels it that way.
| Category | Purpose and representative technologies | Normal duration |
|---|---|---|
| Strictly necessary — always active | Remember consent (bespoke_learning_consent in local storage), provide security and load balancing, prevent fraud or bots, preserve a transaction or authenticated portal session. Providers such as reCAPTCHA, hosting or the portal may set security cookies. | Session to 12 months; a security record may last longer when reasonably needed. |
| Analytics — optional | Measure pages, navigation, errors and performance through tools such as Google Analytics, Microsoft Clarity or equivalent. Representative names may include _ga, _ga_*, _clck and _clsk. | Session to 14 months where configurable; some provider security identifiers may be shorter. |
| Marketing — optional | Measure campaigns, conversions and audiences through Google Ads, Meta or equivalent. Representative names may include _gcl_au, _fbp and _fbc. | Typically up to 90 days, except a provider may use a shorter or legally permitted disclosed period. |
| Preferences — optional | Remember non-essential display, language, media or feature choices and embedded-service settings. | Session to 12 months depending on the preference. |
Third-party services
Depending on the page and your choices, the site may connect to Vercel for hosting and performance, Google for tag management, analytics, ads or bot protection, Microsoft for Clarity analytics, Meta for advertising measurement, Trustpilot for review widgets, and media, booking or support providers embedded on a page. A direct click to an external service is also governed by that provider’s policy.
Optional scripts are loaded only after the matching consent on pages controlled by Bespoke. A provider may still receive basic connection data when you deliberately play embedded media, open an external widget or follow its link; we identify this where practical. Strictly necessary bot or security services may operate without optional consent, but are limited to that purpose.
How to manage your choices
- Use the button below or “Cookie Settings” in the footer to accept, reject or change categories at any time.
- Use browser settings to view, block or delete cookies and site storage. Blocking necessary storage can affect portal login, security or saved choices.
- Use provider opt-out tools where offered. A browser’s private mode or clearing storage may cause the banner to appear again.
- Where legally required and technically supported, a recognised Global Privacy Control signal is treated as an opt-out of marketing and sale/sharing. We do not interpret a generic Do Not Track signal where no common legal or technical standard defines its effect.
Children and advertising
We do not knowingly use children’s information for behavioural advertising. The public website applies the same opt-in controls to every visitor because reliable age and location inference from a browser can itself be intrusive. A parent may manage the browser choice and contact privacy@bespokelearning.io about a child’s data.
Regional rules and legal basis
For visitors in the EU, EEA and UK, storing or accessing non-essential information on a device requires consent under applicable ePrivacy rules, and subsequent personal-data processing must also have a GDPR legal basis. In Canada, Hong Kong and elsewhere, we apply the same opt-in standard globally while preserving any additional local right.
Necessary technologies are used to provide a requested service, maintain security and remember privacy choices. Optional technologies rely on consent. Withdrawing consent is as easy as giving it.
Changes and contact
We update this Policy and the consent interface when categories, purposes or providers materially change. We will not silently convert an optional purpose into a necessary one. Questions or rights requests may be sent to privacy@bespokelearning.io.