Skip to content
Heathrow
About this site · Legal

Cookies policy for Heathrow Airport Info

This policy lists every cookie the site sets, who sets it, what it is for, and how long it lasts. The list is short. The site's analytics provider is cookieless. The only cookies you will encounter are the strictly-necessary ones the Cloudflare CDN and security layer set automatically to keep the site safe from automated abuse. There is no consent banner because nothing here requires consent under UK law as it stands after the Data (Use and Access) Act 2025.

On this page (5 sections)

About this policy

This is the cookies policy for heathrowairport-info.co.uk, in force from the date in the footer at the top of this page. It sits alongside the site's privacy policy (which covers the broader data picture) and the site's legal notice (which covers the rest of the terms). All three are linked from the footer on every page on the site.

What cookies the site sets

The site's data footprint is deliberately small. Three categories of storage technology are worth covering, even though only one of them actually sets a cookie on your device.

Cloudflare Web Analytics: no cookie

The site uses Cloudflare's Web Analytics product to count visits and judge which pages need work. Per Cloudflare's current position, the product is cookieless and server-side: it does not set any client-side cookies, does not use local storage, and does not fingerprint visitors via the IP address or User-Agent. Measurement happens at Cloudflare's edge network without writing anything to your browser. There is nothing here for you to consent to, because nothing is stored on your device.

Cloudflare CDN and security: strictly-necessary cookies

The site is hosted on Cloudflare Pages, which means every request to the site passes through Cloudflare's CDN and security layer. That layer sets a small number of strictly-necessary cookies to keep the site safe from automated abuse:

Name Set by Purpose Duration
__cf_bm Cloudflare Bot management. Holds a one-way encrypted bot score for the current session. Site-specific and not used to track you between sites. 30 minutes from your last request
cf_clearance Cloudflare Challenge passage. Only set if Cloudflare has issued a challenge to your browser (for example, after an unusual request pattern) and you have passed it. Proves the device has been verified. 30 minutes by default

Both cookies are first-party (issued under the site's own domain), site-specific (a separate value is generated per site, not shared across the wider Cloudflare network), encrypted, and contain no profiling or marketing data. The __cf_bm cookie is the only one most visitors will see; cf_clearance only appears if a challenge has been issued at the network layer.

Third-party trackers, ad pixels, social plug-ins

None. The site does not embed Google Analytics, Google Tag Manager, Facebook Pixel, X (Twitter) tracking, LinkedIn Insight, TikTok Pixel, Pinterest tag, marketing automation tags, advertising network code, or any other third-party tracker that sets cookies. There are no social-share widgets that load tracking scripts. There are no embedded YouTube, Vimeo, X, Facebook, or Instagram players on any page. If a future embed is ever added that changes this position, this policy will be updated in the same commit.

Why there is no consent banner

The legal basis sits under Regulation 6 of the Privacy and Electronic Communications Regulations 2003 (PECR) as amended by the Data (Use and Access) Act 2025, which came into force on 5 February 2026. Schedule A1 of PECR now lists five circumstances in which storage or access to a device is permitted without consent: communication, strictly necessary, statistical purposes, appearance, and emergency assistance. The Information Commissioner's Office finalised its current guidance on the use of storage and access technologies on 29 April 2026.

Applied to this site: the __cf_bm and cf_clearance cookies fall under the strictly necessary exemption, because both are essential to the site being served safely to the user requesting it (without bot protection at the CDN layer, the site could not stay online under sustained automated load). Cloudflare Web Analytics, being cookieless and server-side, falls outside PECR entirely, since no storage or access happens on the user's device.

The site does not set any cookie that requires consent under current UK law. A consent banner asking permission to set cookies that already qualify under the exemptions would mislead rather than inform, and the ICO's narrow interpretation of the exemptions cuts both ways: it forbids inflating the exempt set, and equally forbids inventing a consent step where the law does not require one.

How to control cookies in your browser

You can block, delete, or limit cookies through your browser's settings. Doing so will not affect Cloudflare Web Analytics, because that product does not set cookies in the first place. It may affect Cloudflare's bot detection, which means the site may issue a verification challenge on subsequent visits (you would see a Cloudflare challenge page rather than the site loading immediately). The site itself will still load normally once the challenge passes.

The major browser vendors publish their own cookie controls and help pages:

For technical questions about the cookies described above or any other matter covered by this policy, raise it through the channels on the contact page.

Changes to this policy

The date at the foot of this page is the effective date of the current version. The policy is updated whenever the cookies the site actually sets change (for example, if a new CDN-layer cookie is introduced or removed by Cloudflare), or whenever the UK legal state moves. The post-DUAA position is recent and the ICO has signalled that further guidance updates are likely; this page tracks them.