LEGAL & POLICY
Cookie Policy (UK)
Applies to: Website visitors
Cookies and similar storage and access technologies used by the Nifty Fixes North East website
This policy explains how Nifty Fixes NE Ltd T/A Nifty Fixes North East uses cookies and similar technologies, which technologies are currently configured, why they are used, when consent is requested and how visitors can manage their choices.
Nifty Fixes NE Ltd T/A Nifty Fixes North East
Last updated: 24 July 2026
Version: v1.7 | Issued: 2026-07-24
1. Who we are
Expand
This website is operated by Nifty Fixes NE Ltd, trading as Nifty Fixes North East.
Company number: 16397211 (England and Wales)
Registered and trading address: Collingwood Buildings, 38 Collingwood Street, Newcastle upon Tyne, NE1 1JF
Email: hello@niftyfixesne.co.uk
Landline: 0191 810 8301
Mobile: 07956 011 072
2. Scope and current inventory
Expand
This policy covers niftyfixesne.co.uk and the website services that we control. It should be read together with our Privacy Policy.
The inventory below was revalidated on 24 July 2026 against the current managed website source, active WordPress plugins, recorded website settings and current provider documentation. It distinguishes technologies confirmed in the current configuration from technologies that are conditional on a visitor using a payment service, signing in, accepting optional external content or triggering a hosting security feature.
Some third-party and infrastructure technologies are generated dynamically and may change when a provider updates its service. A conditional entry does not mean that the cookie is set on every visit. We review the inventory when the website, payment services, hosting controls or approved integrations materially change.
3. What storage and access technologies are
Expand
A cookie is a small text file stored on your device by a website. Some cookies last only for the browser session. Others remain for a set period so that a website or service can recognise the browser when it returns.
UK rules also apply to other technologies that store information on, or access information from, a device. These can include local storage, session storage, scripts, tags, pixels, link decoration and device or browser signals used for security and fraud prevention. In this policy, “cookies” is used as a convenient collective term unless a particular technology is identified separately.
4. PECR, UK GDPR and consent
Expand
The Privacy and Electronic Communications Regulations 2003, as amended (PECR), govern storing information on and accessing information from a user’s device. The UK GDPR and Data Protection Act 2018 also apply where personal data is processed.
We provide clear information about the technologies we use. We obtain prior consent where no PECR exception applies. Technologies used solely to transmit communications, provide a service expressly requested by the user, remember the user’s cookie choice, protect the website or apply a user-requested appearance or functionality preference may be used without a separate optional-cookie opt-in where the relevant exception applies.
The NFNE consent tool keeps optional categories off by default and provides equally prominent choices to accept or reject them. Silence, continued browsing and pre-selected controls are not treated as consent. The persistent “Cookie settings” control lets you review, change or withdraw your optional choices.
WooCommerce order-attribution storage is placed in the optional “Analytics and attribution” category. It is blocked until that category is allowed and is cleared when the category is refused or withdrawn. We do not rely on the PECR statistical-purposes exception for this attribution activity. The optional MyJobQuote live-review panel and Environment Agency waste-registration panel are separately withheld until the visitor permits “Optional external content”.
5. Current categories
Expand
| Category | Current use | When it operates | Choice position |
|---|---|---|---|
| Strictly necessary | Consent preferences, core security, logged-in authentication, requested cart or payment sessions, payment fraud prevention and conditional hosting security. | Only where needed for the website or a service the user requests. | Not switchable through the optional-consent tool where a PECR exception applies. |
| Preferences and functionality | WordPress language and interface preferences for authorised logged-in users. | After sign-in or an explicit interface choice. | Used only for the requested account interface or preference where the applicable exception applies. |
| Analytics and attribution | Short-session WooCommerce order attribution, including traffic source, referral or UTM information, device type and session page-view count. | Only after an affirmative analytics-and-attribution choice. | Off by default. It is not used for advertising, remarketing or cross-session visitor profiling. |
| Optional external content | MyJobQuote live reviews and the Environment Agency waste-registration panel. | Only after an affirmative optional-content choice. | Off by default. The website, direct MyJobQuote profile link and direct Environment Agency register link remain available if refused. |
| Administrator-only operational telemetry | WooCommerce dashboard usage tracking where enabled. | Only within the logged-in WordPress administration area. | Not set for ordinary public visitors and not controlled by the public optional-content choice. |
| Advertising and remarketing | No approved advertising, remarketing or social-media tracking pixel is currently registered as active. | Not currently used by the managed NFNE website source. | Any future integration requires approval, an updated inventory and the appropriate consent assessment before activation. |
6. First-party, WordPress and WooCommerce technologies
Expand
| Name or pattern | When used | Purpose and category | Typical duration |
|---|---|---|---|
nfne_cookie_consent | After a visitor records or changes a cookie choice. | Signed first-party value containing a random consent identifier, policy version, expiry and category choices. It contains no name, email address, job details, IP address or browsing history. Strictly necessary to remember and apply the choice. | 180 days, unless the configured period is changed. |
wordpress_test_cookie | WordPress sign-in page. | Checks whether the browser accepts cookies. Strictly necessary for account sign-in. | Session. |
wordpress_logged_in_*, wordpress_sec_* and wordpress_* | Authorised users who sign in to WordPress. | Authentication, account security and logged-in state. Strictly necessary for the requested account session. | Browser session normally; up to 14 days where “Remember Me” is selected. |
wp-settings-*, wp-settings-time-*, wp_lang and WP_PREFERENCES_USER_* | Authorised users who sign in or select a WordPress interface preference. | Remembers dashboard display, language and interface preferences. Preferences and functionality. | Commonly up to 1 year, depending on the WordPress preference. |
woocommerce_cart_hash and woocommerce_items_in_cart | When a visitor uses a WooCommerce cart or payment pathway. | Detects cart changes and keeps the requested cart or payment process consistent. Strictly necessary for that requested process. | Session. |
wp_woocommerce_session_* | When WooCommerce creates a customer session for a requested cart or payment process. | Provides the code used to locate the customer’s cart or payment-session data in the database. Strictly necessary for that requested process. | 2 days. |
sbjs_session | Only after “Analytics and attribution” is allowed. | Records the number of page views in the current visit and the current page path for WooCommerce order attribution. | 30 minutes. |
sbjs_udata | Only after “Analytics and attribution” is allowed. | Records browser or device information used to describe the source and device associated with an order. Optional analytics and attribution. | Session. |
sbjs_first, sbjs_current, sbjs_first_add, sbjs_current_add and sbjs_migrations | Only after “Analytics and attribution” is allowed. | Temporarily records first and current traffic-source details, referring and entry pages, timestamps and technical migration information. The values are read and saved with the order only if an order or invoice payment is completed during the session. | Session. |
wc_stripe_express_checkout_redirect_url | Only if a Stripe express-checkout user is redirected through account sign-in. | Returns the user to the requested payment page after authentication. Strictly necessary for that express-checkout route. | 10 minutes. |
tk_ai | Logged-in WooCommerce dashboard only, where WooCommerce usage tracking is enabled. | Stores a randomly generated anonymous identifier for administrator-side operational usage tracking. It is not an ordinary public-visitor cookie. | Session. |
WooCommerce order attribution is enabled in the current website configuration, but the NFNE consent control prevents the attribution scripts and sbjs_* cookies from operating before permission. Refusing or withdrawing “Analytics and attribution” removes the registered first-party attribution cookies and prevents future attribution loading.
Where WooCommerce usage-data sharing remains enabled, WooCommerce states that statistical order-attribution data may be shared with Automattic on a per-order basis. Billing, shipping and email data are not included in that attribution-sharing statement. This is separate from the short-session browser cookies listed above.
WordPress comment convenience cookies, the WooCommerce recently viewed-products cookie, the WooCommerce store-notice cookie and WooCommerce customer-geolocation cookie are not identified as active public features in the current managed configuration. They are not listed as current visitor technologies merely because the underlying software is capable of using them.
6A. Job Assistant and optional AI guidance
Expand
The guided Job Assistant may use browser session storage to retain unfinished ordinary form answers in the current browser tab. This helps a visitor move between guided steps without losing entries. The saved draft excludes uploaded files, hidden security values, any signed estimate token and required acknowledgements, and is removed when the form is submitted or the visitor uses the clear control. Closing the tab or browser normally clears session storage in accordance with the browser’s behaviour. A separate non-content session marker may record that the assistant bubble has already opened automatically in the tab.
If optional AI guidance is enabled and used, the website creates a short-lived server-side session and places its random session reference in the active page form. The AI chat history, session nonce, contact/detail conversation state and estimate state are held in page memory for the current visit and are not written to browser draft storage, a marketing cookie or an analytics cookie. Reloading or leaving the page starts a new visible conversation. The server-side session is strictly necessary to deliver the visitor-requested AI interaction, enforce limits and prevent misuse. It expires automatically and the guided enquiry form works without AI.
Where a visitor requests an instant estimate check, the website may create a short-lived signed estimate token in the active form after a qualifying rule matches. The token verifies the result shown against the current non-contact form inputs. It is not a cookie, is not placed in browser draft storage, expires automatically and is retained only if the visitor submits the enquiry.
The Job Assistant does not use AI guidance or estimate checks to add advertising, remarketing or general visitor analytics cookies. Any material change to the storage technologies used by this feature will be reflected in this policy and, where required, the consent controls before activation.
7. Payment and fraud-prevention technologies
Expand
Payment technologies are loaded only within the approved payment, order-pay, cart or checkout pathways where the visitor has chosen to use an online payment service. Payment providers may use cookies, browser storage, scripts and device signals for payment processing, authentication, fraud detection, loss prevention and security.
| Provider and examples | When used | Purpose and category | Duration or control |
|---|---|---|---|
Stripe: __stripe_mid, __stripe_sid, m; and, where Link is used, values such as pay_sid, __Host-LinkSession and link.auth_session_client_secret | When Stripe.js, Stripe payment fields, express checkout or Link is used on an approved payment pathway. | Fraud prevention, payment security and payment authentication. Treated as necessary for the payment service expressly requested by the user. Stripe controls the provider-side technology. | __stripe_mid is commonly up to 1 year and __stripe_sid around 30 minutes. Other Stripe values are session or provider-controlled and may change with the selected Stripe product. |
| PayPal, PayPal Google Pay and PayPal Apple Pay provider cookies and similar technologies | When the PayPal payment SDK or a PayPal-supported wallet is loaded in an approved payment pathway. | Payment processing, authentication, security, risk management and fraud prevention. Only provider technologies required for the requested payment, authentication or security process are treated as strictly necessary by NFNE. | PayPal uses both session and persistent technologies and also describes performance, functionality and advertising categories under its own controls. Names and durations are controlled by PayPal and may change. |
Google reCAPTCHA: _GRECAPTCHA | When the enabled PayPal fraud-protection process executes reCAPTCHA. | Risk analysis, bot detection and payment fraud prevention. Necessary for the protected payment process when executed. | Controlled by Google. Google states that its normal google.com domain may also set other Google cookies. |
Provider-controlled technologies can change. Current provider information is available from Stripe’s Privacy Center, Stripe’s cookie settings, PayPal’s cookie statement and Google’s reCAPTCHA information.
8. Hosting, content delivery and security
Expand
The website is delivered through managed hosting and Cloudflare content-delivery and security services. Infrastructure cookies are conditional: they are set only if the corresponding security, challenge, rate-limiting or load-balancing feature is active or triggered.
| Possible conditional value | When it may be set | Purpose and category | Typical duration |
|---|---|---|---|
__cf_bm | If Cloudflare bot-management features are active. | Bot detection and website security. Strictly necessary when the security feature operates. | Expires after about 30 minutes of continuous inactivity. |
cf_clearance | After a visitor successfully passes a Cloudflare challenge. | Stores proof that the challenge was passed so the visitor can reach the site. Strictly necessary when challenged. | The configured challenge-passage period; Cloudflare’s default is generally 30 minutes. |
_cfuvid | Only if the corresponding Cloudflare rate-limiting unique-visitor option is used. | Distinguishes visitors who share an IP address so rate limits can operate fairly. Strictly necessary when that rule is configured. | Controlled by the Cloudflare configuration. |
__cflb | Only if Cloudflare load-balancer session affinity is used. | Keeps a visitor routed to the appropriate server for service continuity. Strictly necessary when that feature is configured. | Controlled by the load-balancer configuration. |
Cloudflare’s current infrastructure-cookie descriptions are available in its Cloudflare Cookies documentation.
9. Optional external content
Expand
The Reviews page can display a live panel supplied by MyJobQuote. The external MyJobQuote script is not loaded by the NFNE website until the consent tool verifies that the visitor has allowed the “Optional external content” category.
After permission is granted, MyJobQuote may use provider-controlled cookies, browser storage, scripts or network identifiers to deliver and secure the panel. MyJobQuote controls the names and durations of those technologies and may change them. The current MyJobQuote information is available in its Privacy Policy.
If permission is refused, the live MyJobQuote panel is not loaded by the NFNE integration. The rest of the website remains available, and a direct link to the NFNE profile on MyJobQuote is provided instead.
The About page can also display the official Environment Agency Waste Carriers, Brokers and Dealers widget for registration CBDU585506. The iframe is not connected until the same “Optional external content” category is allowed. Once loaded, the visitor’s browser connects directly to the Environment Agency service, which may use its own cookies, storage or network identifiers under its published controls.
If permission is refused, a normal link remains available so visitors can check the registration directly in the Environment Agency public register without loading the embedded panel.
10. Technologies not currently registered as active
Expand
Other than the consent-controlled WooCommerce order-attribution feature described above, the current managed NFNE website source does not register general public visitor analytics, advertising, remarketing, social-media tracking pixels or marketing cookies as active. No such technology should be treated as approved merely because the underlying WordPress or payment software is capable of supporting it.
Before any additional analytics, advertising or marketing service is enabled, it must be approved, technically assessed, added to the inventory, reflected in the privacy and cookie information, and assigned the correct consent or PECR-exception treatment.
11. Managing or withdrawing choices
Expand
- Use the website’s “Cookie settings” control to review, accept, reject or withdraw permission for “Analytics and attribution” and “Optional external content” independently.
- Use your browser settings to inspect, block or delete cookies and browser storage.
- Do not load optional MyJobQuote or Environment Agency panels, or use an optional online payment service, if you do not wish to connect to the relevant provider.
- Where a third-party service provides its own privacy or cookie controls, use those controls for provider-domain technologies that the NFNE website cannot directly remove.
Saving a changed choice reloads the page so the revised controls take effect. Withdrawing “Analytics and attribution” removes the registered first-party WooCommerce attribution cookies and blocks the attribution scripts. Withdrawing “Optional external content” prevents future loading of the MyJobQuote and Environment Agency panels. A cookie stored solely on a third party’s domain may need to be removed through that provider’s controls or the browser. Blocking strictly necessary technologies may prevent sign-in, security checks, cart operation or online payment from working.
12. Consent records and retention
Expand
The nfne_cookie_consent preference cookie normally lasts for 180 days. The website also keeps a minimised backend consent event record for accountability and administration. It contains a random consent identifier, action, category choices, policy version and timestamps. It intentionally excludes IP addresses, full page URLs and browsing history.
Consent event records are normally retained for 365 days and then deleted automatically, subject to the configured settings and any justified legal need to preserve a particular record.
13. Changes to this policy
Expand
We may update this policy when the website, hosting, payment providers, consent controls, third-party integrations or legal requirements change. A material change to the optional technology inventory or purpose may cause the consent tool to ask visitors to make a new choice.
14. Contact
Expand
Questions about this policy or the website’s use of cookies and similar technologies can be sent to hello@niftyfixesne.co.uk.