Skip to content
Heathrow
About this site · Legal

Cookies policy for Heathrow Airport Info

This policy lists every cookie the site sets, who sets it, what it does, and how long it lasts. The list is short. Two cookies come from Google Analytics, which counts visits so the site knows which pages need work, and two come from Cloudflare, which serves the site and keeps it safe from automated abuse. There are no advertising cookies, no social-media trackers, and no third-party marketing tags of any kind. The analytics can be switched off with the switch on this page.

On this page (5 sections)

About this policy

This is the cookies policy for heathrowairport-info.co.uk, in force from the date in the footer at the top of this page. It sits alongside the site's privacy policy (which covers the broader data picture) and the site's legal notice (which covers the rest of the terms). All three are linked from the footer on every page on the site.

What cookies the site sets

Four cookies, from two sources, plus a clear statement of what is not here.

Google Analytics: two first-party cookies

The site uses Google Analytics 4 to count visits and see which pages are used. It runs on the live site only, so nothing is recorded while the site is being developed. Google Analytics 4 does not log or store your IP address: it is used briefly to derive a coarse, city-level location and then discarded. The site loads no advertising or remarketing tag of any kind, so no advertising cookies are set from here. It does set two first-party analytics cookies:

Name Set by Purpose Duration
_ga Google Analytics Tells one visitor from another using a randomly generated ID, so a return visit is not counted as a new one. Holds no name or personal detail. About 2 years
_ga_<id> Google Analytics 4 Holds session state for GA4. The <id> is the site's own measurement stream identifier. First-party. About 2 years

The two-year figure is the default maximum. In practice browsers cut it shorter: Google Chrome caps first-party cookies at about 400 days for a visitor who does not return, and Apple Safari can reduce it to as little as 7 days.

Cloudflare: two strictly-necessary cookies

The site is served through Cloudflare, so every request passes through its CDN and security layer, which sets a small number of strictly-necessary cookies to keep the site safe from automated abuse:

Name Set by Purpose Duration
__cf_bm Cloudflare Bot management. Holds a one-way encrypted bot score for the current session. Site-specific and not used to track you between sites. 30 minutes from your last request
cf_clearance Cloudflare Challenge passage. Only set if Cloudflare has issued a challenge to your browser (for example, after an unusual request pattern) and you have passed it. Proves the device has been verified. 30 minutes by default

Both cookies are first-party (issued under the site's own domain), site-specific (a separate value is generated per site, not shared across the wider Cloudflare network), encrypted, and contain no profiling or marketing data. The __cf_bm cookie is the only one most visitors will see; cf_clearance only appears if a challenge has been issued at the network layer.

Advertising, social and third-party trackers: none

The site sets no advertising cookies and embeds no third-party trackers. There is no Google Ads or DoubleClick tag, no Google Tag Manager container, no Facebook Pixel, no X (Twitter), LinkedIn, TikTok or Pinterest tracking, no marketing-automation tag, and no advertising network code. There are no social-share widgets that load tracking scripts, and no embedded YouTube, Vimeo, X, Facebook or Instagram players on any page. If a future embed is ever added that changes this position, this policy will be updated in the same commit.

How to control cookies

The quickest way to switch the analytics off is the switch on this page. It works on this device and browser, takes effect straight away, and the site works normally either way.

Analytics on this device

Checking your current setting.

The switch saves a single flag in this browser (it sets no cookie) and holds on this visit and every later one, until you turn it back on or clear this site’s data. It only covers this device and browser. For something more durable, or to cover every site at once, use one of the browser-level methods below.

Beyond the switch above, there are two browser-level routes that cover every device you use. The Google Analytics Opt-out Browser Add-on stops Google Analytics running on every site you visit, not just this one; it is a browser extension, so it needs installing once and then applies everywhere. Blocking or deleting cookies in your browser removes the _ga cookies and stops Google Analytics 4 recognising a return visit, and many browsers and privacy extensions block analytics scripts outright. Either way, the site itself loads and works exactly the same.

Blocking the Cloudflare cookies is possible too, but they are there to serve the site safely, so the main effect is that you may see a Cloudflare verification step on some visits before the page loads. The site will still load normally once the challenge passes. The major browser vendors publish their own cookie controls and help pages:

For technical questions about the cookies described above or any other matter covered by this policy, raise it through the channels on the contact page.

Changes to this policy

The date at the foot of this page is the effective date of the current version. The policy is updated whenever the cookies the site actually sets change (for example, if a new CDN-layer cookie is introduced or removed by Cloudflare, or if the analytics provider changes), or whenever the UK legal state moves. The post-DUAA position is recent and the ICO has signalled that further guidance updates are likely; this page tracks them alongside the privacy policy.