Last updated: 21 July 2025

Contents

  1. Introduction
  2. What Are Cookies?
  3. Why We Use Cookies
  4. Types of Cookies We Use
  5. Managing Your Cookie Preferences
  6. Detailed List of Cookies Used
     A. WordPress
     B. Cloudflare (including Turnstile)
     C. Stripe
     D. Sentry
     E. Google Analytics & reCAPTCHA
     F. Getscreen.me
     G. Essential Site Cookies
     H. Other Third-Party/Plugin Cookies
  7. Legal Basis for Cookies
  8. Changes to This Policy
  9. Contact Us

1. Introduction

This Cookie Policy explains how Avefinity (“we”, “us”, “our”), operated by Avery Mainstone (trading as Avefinity), uses cookies and similar technologies on our websites and online services. This policy meets the requirements of the UK GDPR, Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), the EU GDPR, and guidance from the Information Commissioner’s Office (ICO).

2. What Are Cookies?

Cookies are small text files placed on your device by websites you visit. They allow sites to remember your actions and preferences (such as login, language, or privacy choices) over a period of time. Other similar technologies (such as web beacons, pixels, HTML5 local storage, and scripts) are also used and, for simplicity, are referred to as “cookies” in this policy.

3. Why We Use Cookies

We use cookies to:

  • Enable essential features and security of our sites and services
  • Recognise your device and preferences
  • Analyse site usage and performance to improve services
  • Facilitate secure payments and remote support
  • Protect against fraud, spam, and abuse
  • Support logins and forms
  • Enable certain third-party integrations

We do not use cookies for advertising or profiling.

4. Types of Cookies We Use

a. Strictly Necessary (Essential) Cookies

These are required for our sites and services to function and cannot be switched off. They are typically set only in response to actions you take (such as logging in or filling out forms). Consent is not required for these cookies.

b. Performance & Analytics Cookies

These help us count visits and sources, see how visitors move around the site, and identify performance issues. These are only set with your consent.

c. Functional Cookies

These enable our websites to remember choices you make (such as your username, language, or region). Some are set by third-party providers.

d. Security & Anti-Abuse Cookies

Used to authenticate users, protect against fraud and abuse (e.g. Cloudflare Turnstile, Stripe anti-fraud).

e. Third-Party Cookies

Some site features rely on trusted third-party providers who may set their own cookies (see section 6).


5. Managing Your Cookie Preferences

  • On your first visit, our cookie banner allows you to accept, reject, or customise cookie preferences.
  • You can change your choices at any time using the link in our website footer or by contacting us.
  • You may also block or delete cookies via your browser settings. Note: Disabling some cookies may affect website functionality.
  • For more information, visit AboutCookies.org or ICO Cookies Guidance.

6. Detailed List of Cookies Used

While we aim to provide an accurate and current list of cookies, the actual cookies set may change depending on site updates, features, and third-party services. You may request an up-to-date list at any time by contacting us.

A. WordPress Cookies

Cookie NamePurposeTypeRetentionWhen Set
wordpress_[hash]Authentication for logged-in usersEssentialSessionWhen logged in
wordpress_logged_in_[hash]Logged-in statusEssentialSessionWhen logged in
wordpress_sec_[hash]Security/authenticationEssentialSessionWhen logged in
wp-settings-{user_id}User dashboard/settingsFunctional1 yearWhen logged in
wp-settings-time-{user_id}Timestamp of WP settingsFunctional1 yearWhen logged in
wp-saving-postPost autosave/editingFunctional1 dayWhen editing
wordpress_test_cookieTests if browser supports cookiesEssentialSessionAll users
comment_author_[hash]Remembers comment author nameFunctional347 daysWhen commenting
comment_author_email_[hash]Remembers comment author emailFunctional347 daysWhen commenting
comment_author_url_[hash]Remembers comment author websiteFunctional347 daysWhen commenting
wfwaf-authcookie-[hash]Wordfence firewall/security (if active)Security1 dayIf plugin enabled

B. Cloudflare Cookies (including Turnstile)

Cookie NamePurposeTypeRetention
__cfduid*Legacy security, identifies trusted web trafficEssential30 days
__cfruidRate limiting, DDoS protectionEssentialSession
cf_clearanceAccess granted after challenge or TurnstileEssential30 mins – 24 hrs
__cf_bmBot management, abuse preventionEssential30 mins
cf_chl_*Cloudflare challenge and anti-botEssentialVaries
cf_use_ob, cf_ob_infoAlways Online/obfuscationFunctionalSession
cf_turnstile_*Turnstile (CAPTCHA/anti-spam) sessionEssential30 mins

Cloudflare never uses cookies for marketing. See Cloudflare Cookie Policy.


C. Stripe Cookies (Payments & Identity)

Cookie NamePurposeTypeRetention
__stripe_midPayment fraud preventionEssential1 year
__stripe_sidPayment session managementEssential30 mins
mStripe device/fraud preventionEssential2 years

Set when making payments or using Stripe Identity. See Stripe Cookies Policy.


D. Sentry Cookies (Error/Performance Monitoring)

Cookie NamePurposeTypeRetention
sentryReplaySessionError tracing sessionAnalyticsSession
sentryReplayIDError report sessionAnalyticsSession

E. Google Analytics & reCAPTCHA

Cookie NamePurposeTypeRetention
_gaUnique visitor IDAnalytics2 years
_gidSession analyticsAnalytics24 hours
_gatThrottling requestsAnalytics1 minute
gac*Stores campaign informationAnalytics90 days
NIDGoogle reCAPTCHA/Maps functionalitySecurity6 months
_GRECAPTCHAGoogle reCAPTCHA securitySecurity6 months

Google cookies set only with your consent or if you use forms protected by reCAPTCHA. See Google Cookie Policy.


F. Getscreen.me (Remote Support)

Cookie NamePurposeTypeRetention
gsme_sessionidRemote support session IDEssentialSession
gsme_deviceDevice identificationEssentialSession

Only set if you use remote support. See Getscreen.me Privacy Policy.


G. Essential Site Cookies

Cookie NamePurposeTypeRetention
PHPSESSIDUser session managementEssentialSession
cookieConsent/privacyRecords your cookie choicesEssential1 year
[site]_csrfCSRF (security) protectionEssentialSession

H. Other Third-Party/Plugin Cookies (if present)

  • Google Fonts: No cookies; may log IP for delivery
  • WooCommerce (e-commerce):
    • woocommerce_cart_hash, woocommerce_items_in_cart (cart)
    • wp_woocommerce_session_* (user session)
  • Live chat/feedback tools: If enabled, may set cookies (see tool policy)

7. Legal Basis for Cookies

  • Strictly necessary cookies: Used on the basis of our legitimate interests and/or to perform a contract with you (e.g. to provide secure access, process logins, or enable payments).
  • Non-essential cookies: Used only with your consent (analytics, functional, some third-party integrations). You may withdraw consent at any time via our cookie controls or your browser.

8. Changes to This Policy

We may update this policy to reflect changes in the law, technology, or our practices. The latest version is always available on our website with the date above. Significant changes will be notified where appropriate.


9. Contact Us

If you have questions about our Cookie Policy or require a full up-to-date list of cookies in use, please contact:
Avery Mainstone (Avefinity)
Email: [email protected]
Correspondence address: 86–90 Paul Street, London EC2A 4NE, United Kingdom


For further details, see our full Privacy Policy