Cookie Policy
Steleo Publishing Limited
Effective Date: 1st February 2025
Last Updated: 24/07/2026
Document Version: 1.1
Regulatory Framework: This Cookie Policy is drafted in accordance with the Privacy and Electronic Communications Regulations 2003 (as amended) ("PECR"), the UK General Data Protection Regulation, and the Data Protection Act 2018.
OUR APPROACH TO COOKIES: We use strictly necessary cookies — the ones required to sign you in, keep your session secure and operate the Service — without asking, as PECR permits. We also use analytics and advertising cookies, but only where you have given your prior consent through our cookie banner. These are switched off by default and stay off until you opt in. Session-recording (Microsoft Clarity) runs only with your analytics consent, only on signed-in account pages, and never on the document editor where your legal documents are shown.
1. Introduction and Legal Basis
This Cookie Policy ("Policy") sets out the manner in which Steleo Publishing Limited ("Steleo," "we," "us," or "our") employs cookies and similar technologies in connection with the BundleCreator.co service ("Service").
1.1 Company Information:
- Steleo Publishing Limited, a company incorporated in England and Wales (Company Number: 11891029)
- Registered Address: 167-169 Great Portland Street, London W1W 5PJ
- Contact: privacy@bundlecreator.co
- ICO Registration: ZB969283
1.2 Regulatory Compliance: This Policy is designed to meet the requirements of Regulation 6 of PECR, which requires that we:
- Provide clear and comprehensive information about cookies
- Obtain informed consent before storing or accessing non-essential cookies
- Provide users with the ability to refuse or withdraw consent
- Maintain records demonstrating compliance with consent requirements
2. What Are Cookies?
2.1 Technical Definition: Cookies are small text files containing strings of alphanumeric characters that are stored on your device (computer, tablet, or mobile telephone) when you visit a website. These files enable the website to recognise your device and remember certain information about your interaction with the site.
2.2 Cookie Categories: Cookies may be classified according to their:
- Duration: Session cookies (deleted when browser closes) or Persistent cookies (remain until expiry date or manual deletion)
- Origin: First-party cookies (set by BundleCreator.co) or Third-party cookies (set by external services)
- Purpose: Strictly necessary, functional, performance, or targeting cookies
2.3 Similar Technologies: This Policy also applies to similar technologies including:
- Local Storage and Session Storage (HTML5 storage mechanisms)
- IndexedDB (structured data storage in the browser)
- Web beacons and pixel tags (where applicable)
3. Cookies We Use
CONSENT-FIRST BY DESIGN: Strictly necessary cookies are always on, because the Service cannot run without them. Every other cookie — analytics and advertising — is off until you choose to turn it on. We use Google Consent Mode, so until you consent, our analytics and advertising tags load without setting cookies and without collecting identifying data. You can change or withdraw your choice at any time.
3.1 Strictly Necessary Cookies (No Consent Required):
These cookies are essential for the operation of our Service and are deployed pursuant to the "strictly necessary" exception under Regulation 6(4) of PECR. These cookies cannot be disabled without materially impairing Service functionality.
| Cookie Name | Purpose | Duration | Type |
|---|---|---|---|
| __clerk_* | Authentication session management and security (OAuth 2.0 Authentication Service) | Session / 7 days | First-party |
| __session | User session state and preferences | Session | First-party |
| csrf_token | Cross-Site Request Forgery protection (security) | Session | First-party |
3.2 Local Storage (Browser-Based Storage):
BundleCreator.co employs browser local storage and IndexedDB for application functionality. This storage:
- Stores application state and user preferences locally on your device
- Maintains session information during editing
- Preserves user interface settings and preferences
- Is classified as strictly necessary for application functionality
IMPORTANT NOTE: Clearing local storage or IndexedDB will delete application state and preferences. You may need to reconfigure your settings after clearing browser data.
3.3 Analytics and Advertising Cookies (Consent Required):
In addition to the strictly necessary cookies above, we use a small number of analytics and advertising technologies to understand how the site is used and to measure the effectiveness of our marketing. These are non-essential. Under Regulation 6 of PECR they require your prior consent, so they are switched off by default and are deployed only after you opt in through our cookie banner. We use Google Consent Mode: until you consent, the underlying tags load in a restricted state that sets no cookies and collects no identifying data.
| Cookie Name | Purpose | Duration | Type | Consent Category |
|---|---|---|---|---|
| _ga, _ga_* | Google Analytics 4 — distinguishes individual visitors and persists session state to measure how the site is used (set only after you consent to Analytics) | 2 years | Third-party | Analytics (consent required) |
| _gcl_au | Google Ads Conversion Linker — attributes a conversion (such as starting a trial) to the advertisement you clicked (set only after you consent to Advertising) | 90 days | Third-party | Advertising (consent required) |
| _clck, _clsk | Microsoft Clarity — persists a Clarity identifier and connects page views into a single session recording (signed-in account pages only; never the editor; set only after you consent to Analytics) | 1 day – 1 year | Third-party | Analytics (consent required) |
Plausible Analytics runs across the whole site to give us privacy-friendly visitor numbers. It is configured to be cookieless: it sets no cookies and stores no personal data or persistent identifiers on your device. Because it neither stores nor accesses information on your device, it falls outside the consent requirement in Regulation 6 of PECR and runs without a consent prompt.
The analytics and advertising technologies we use are:
- Google Tag Manager: A tag-management container that loads and governs the analytics and advertising tags below. Tag Manager itself does not set analytics or advertising cookies; it controls when the tags that do are allowed to run, honouring your consent choice.
- Google Analytics 4: Measures how visitors find and use the site (pages viewed, journeys taken, broad device and location data) so we can improve it. Sets the
_gacookies listed above — only after you consent to Analytics. Category: Analytics. - Google Ads conversion tracking: Lets us see which advertisements led to actions such as starting a trial, so we can measure and manage our marketing spend. Sets the
_gcl_aucookie listed above — only after you consent to Advertising. Category: Advertising. - Microsoft Clarity: Records anonymised session replays and heat-maps of how people interact with the application, helping us find and fix usability problems. Clarity runs only on signed-in account pages (such as your dashboard, bundle list and settings) and is deliberately excluded from the document editor, so the contents of your legal documents are never captured. It sets the
_clckand_clskcookies listed above — only after you consent to Analytics. Category: Analytics. - Plausible Analytics: A cookieless, privacy-friendly measurement tool used site-wide. It sets no cookies and stores no identifier on your device, so no consent prompt is required (see the note beneath the table above).
We do not use social-media tracking pixels, we do not sell your personal data, and we do not share it with advertising networks or data brokers for their own purposes.
3.4 How You Control Cookies and Manage Your Consent
When you first visit BundleCreator.co you are shown a cookie banner. Strictly necessary cookies are always on because the Service cannot function without them. Analytics and Advertising cookies are off by default. You can:
- Accept all — turn on Analytics and Advertising cookies;
- Reject non-essential — keep only the strictly necessary cookies; or
- Manage preferences — turn Analytics and Advertising on or off individually.
Your choice is remembered on your device and you can change or withdraw it at any timeusing the “Cookie settings” link in the website footer. Withdrawing consent is as straightforward as giving it, and stops the relevant cookies being set going forward. Cookies already set before you withdraw can be cleared using your browser controls (see section 5).
Legal basis.Strictly necessary cookies are deployed under the “strictly necessary” exemption in Regulation 6(4) of PECR and do not require consent. All Analytics and Advertising cookies are deployed only on the basis of your consent under Regulation 6 of PECR, which we treat as consent meeting the UK GDPR standard — a freely given, specific, informed and unambiguous indication of your wishes. Cookieless Plausible Analytics falls outside Regulation 6 because it does not store or access information on your device.
4. Third-Party Services and Their Cookies
4.1 Authentication Service:
We employ OAuth 2.0 authentication services. Our authentication provider may set cookies necessary for secure authentication, session management, and security protection. These cookies are classified as strictly necessary under PECR.
- Provider: OAuth 2.0 authentication service (US-based, GDPR compliant)
- Purpose: Authentication, session management, security
- Legal Basis: Strictly necessary for service provision
- Data Transfer: Standard Contractual Clauses (SCCs) for UK-US transfers
- SOC 2 Type II Certified: Our authentication provider maintains comprehensive security and privacy certifications
4.2 Content Delivery Network (Vercel/AWS):
Our Service is delivered via Vercel's content delivery network and may employ cookies for:
- Load balancing and performance optimisation
- DDoS protection and security
- Geographic routing
These cookies are classified as strictly necessary for service delivery and security.
4.3 Payment Processing:
When you make a payment, our payment processing service (PCI DSS Level 1 certified) may set cookies necessary for:
- Fraud detection and prevention
- Secure payment processing
- PCI DSS compliance
These cookies are classified as strictly necessary for payment security and fraud prevention.
- Certifications: PCI DSS Level 1, SOC 2 Type II, ISO 27001
4.4 Google (Tag Manager, Analytics 4 and Ads):
We use Google services to measure site usage and marketing effectiveness. These run only with your consent (see sections 3.3 and 3.4).
- Provider: Google Ireland Limited / Google LLC
- Services: Google Tag Manager, Google Analytics 4, Google Ads conversion tracking
- Purpose: Usage analytics and advertising measurement
- Legal basis: Consent (Regulation 6 PECR; UK GDPR Article 6(1)(a))
- Data transfer: Data may be transferred to the United States under the UK Extension to the EU–US Data Privacy Framework and/or the ICO-approved Standard Contractual Clauses with supplementary safeguards.
- More information: Google Privacy Policy
4.5 Microsoft Clarity:
We use Microsoft Clarity for anonymised session replay and heat-maps on signed-in account pages only, never on the document editor, and only with your Analytics consent (see section 3.3).
- Provider: Microsoft Corporation
- Purpose: Usability analysis through anonymised session recordings and heat-maps
- Legal basis: Consent (Regulation 6 PECR; UK GDPR Article 6(1)(a))
- Data transfer: Data may be transferred to the United States under the UK Extension to the EU–US Data Privacy Framework and/or ICO-approved Standard Contractual Clauses.
- More information: Microsoft Privacy Statement
5. Your Rights and Controls
5.1 Browser Controls: Most web browsers allow you to control cookies through browser settings. You may:
- Block all cookies
- Block third-party cookies only
- Delete cookies after each browsing session
- Set browser to prompt before accepting cookies
WARNING: Blocking strictly necessary cookies will prevent the Service from functioning correctly. You will be unable to:
- Log in to your account
- Create or edit bundles
- Access encrypted documents
- Use core Service features
5.2 Managing Browser Cookies:
- Chrome: Settings → Privacy and security → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy → Manage Website Data
- Edge: Settings → Cookies and site permissions
5.3 Local Storage Management: To clear local storage and IndexedDB:
- Chrome: Developer Tools (F12) → Application → Clear storage
- Firefox: Developer Tools (F12) → Storage → Clear All
- Safari: Develop menu → Empty Caches
IMPORTANT NOTE: Clearing local storage will delete your application state and preferences. You will need to log in again and reconfigure your settings. Your documents remain securely stored on our servers and will be accessible after you log back in.
5.4 Your GDPR Rights: Under UK GDPR, you have the right to:
- Access: Request copies of your personal data
- Rectification: Correct inaccurate personal data
- Erasure: Request deletion of your personal data
- Restriction: Limit processing of your data
- Portability: Receive your data in a machine-readable format
- Objection: Object to processing based on legitimate interests
To exercise these rights, contact: privacy@bundlecreator.co
6. International Data Transfers
6.1 Third-Party Processors: Certain third-party services (authentication, payment processing) are based in the United States. We ensure compliance with UK GDPR requirements for international transfers through:
- Standard Contractual Clauses (SCCs) approved by the ICO
- Supplementary measures including encryption and access controls
- Transfer Impact Assessments (TIAs) evaluating risks
- Contractual commitments regarding data protection
6.2 Data Protection Architecture: Your document content is protected with AES-256 encryption at rest via cloud database infrastructure and TLS 1.3 encryption during transmission. Third-party services are carefully selected and bound by contractual data protection obligations.
7. Legal Professional Privilege
7.1 Privilege Protection: BundleCreator.co is designed specifically to preserve legal professional privilege. Our strictly necessary cookies and local storage:
- Enable secure transmission of documents with AES-256 encryption at rest and TLS 1.3 in transit
- Support role-based access controls to restrict document access
- Maintain the confidentiality required for privileged communications through comprehensive security measures
- Comply with SRA Principles and BSB Core Duties regarding confidentiality
7.2 Professional Responsibility: Legal professionals using BundleCreator.co remain responsible for:
- Maintaining appropriate device security
- Using strong passwords and authentication
- Complying with professional conduct rules
- Assessing risks to client confidentiality
For comprehensive information, see our Legal Professional Privilege Statement.
8. Changes to This Policy
8.1 Notification of Changes: We may update this Cookie Policy to reflect:
- Changes in our cookie usage
- Changes in applicable law
- Changes to third-party services
- Technological developments
8.2 Material Changes: If we make material changes to this Policy, we will:
- Update the "Last Updated" date at the top of this document
- Notify you via email (if you have an active account)
- Display a prominent notice on the Service
- Obtain fresh consent if required by law
8.3 Review Obligation: We recommend reviewing this Policy periodically to stay informed about our cookie practices.
9. Contact and Complaints
9.1 Contact Information: For questions or concerns regarding this Cookie Policy, please contact:
- Email: privacy@bundlecreator.co
- Post: Data Protection Officer, Steleo Publishing Limited, 167-169 Great Portland Street, London W1W 5PJ
9.2 Supervisory Authority: You have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- ICO Website: https://ico.org.uk
- ICO Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
9.3 Resolution Process: We are committed to resolving complaints promptly and fairly. Upon receiving your complaint, we will:
- Acknowledge receipt within 48 hours (excluding weekends)
- Investigate thoroughly and respond within 30 days
- Provide a detailed explanation of our findings and any remedial action
- Inform you of your right to escalate to the ICO if dissatisfied
10. Technical Specifications
10.1 Cookie Lifespan:
- Session Cookies: Deleted when browser closes
- Authentication Cookies: Maximum 30 days (configurable)
- Security Cookies: Session-based or until logout
10.2 Storage Mechanisms:
- Cookies: HTTP-only, Secure flag, SameSite attribute
- Local Storage: Session data and preferences, origin-restricted
- IndexedDB: Application state and preferences, origin-restricted
10.3 Security Measures:
- All cookies transmitted over HTTPS with Secure flag
- HTTP-only flag prevents JavaScript access to sensitive cookies
- SameSite attribute prevents CSRF attacks
- Content Security Policy (CSP) restricts third-party access
Document Information
Document Owner: Data Protection Officer, Steleo Publishing Limited
Review Frequency: Annually or upon material changes
Next Review Date: 17th June 2027
Approval Authority: Board of Directors, Steleo Publishing Limited
Version History:
- Version 1.0 - 1st February 2025 - Initial publication
- Version 1.1 - 17th June 2026 - Updated to disclose consent-based analytics and advertising cookies (Google Analytics 4, Google Ads, Microsoft Clarity) and cookieless Plausible Analytics, and to describe cookie-consent controls