Cookie policy
This notice covers information written to, and read from, your device by this website and by the booking widget embedded on contact; outreach email is covered by data collection.
Last updated 12 August 2026. Richport Media Inc., 1225 Ave Ponce De Leon, PH 2020, San Juan, PR 00907, United States.
What consent covers
The regulated act is storing information on, or gaining access to information stored in, your device, whether or not that information is a cookie and whether or not it is personal data.
- §25(1) TDDDG — GermanyStoring information on, or gaining access to information already stored in, a user’s terminal equipment requires consent, whether or not that information is personal data. It applies to a service offered to users in Germany regardless of where the server sits. A breach is punishable by a fine of up to €300,000.
- Regulation 6, PECR — United KingdomThe same rule in UK law: consent for storage on, or access to, a user’s terminal equipment, independent of where the server sits. Since 5 February 2026 the penalty ceiling has been raised to UK GDPR levels. Which contraventions fall in which tier is not yet settled.
- Article 5(3), Directive 2002/58/ECThe ePrivacy Directive provision both national rules implement. The requirement is broadly the same across the EEA; the penalties are not.
- The strictly-necessary exemption§25(2) TDDDG and regulation 6(4) PECR exempt storage that is strictly necessary to provide the service requested. It is narrow. It covers a cross-site-request-forgery token on a booking form and the record of a refusal already given. It does not cover a measurement cookie.
- GDPR Article 6(1)(a)Where consented storage then produces personal data, consent is also the lawful basis for processing it. Article 7(3) gives you the right to withdraw at any time, and requires that withdrawing be as easy as giving.
Cookies this site sets
Fourteen public pages and a 404, served as static files by Cloudflare Pages. There is no account, no login and no server-side session.
- Your banner choiceYour answer to the banner is stored on your device. It records what you chose and nothing else — no identifier, no profile, nothing that follows you off this domain. It is strictly necessary storage, and you are not asked to consent to it.
- Nothing else, from usApart from that record our code neither writes to nor reads from any storage: no cookie, no localStorage, no sessionStorage, no IndexedDB. Our scripts do not call any of those APIs. The hosting sets nothing either — there is no Set-Cookie header on the home page, on the contact page or on the font stylesheet.
- Self-hosted fontsThirteen .woff2 files under /assets/fonts, served from this domain. The font stylesheet contains no external URL. No Google Fonts and no font CDN.
- No formsThere is no form, input, textarea or select element anywhere in the site’s markup. The site collects nothing from you directly. The only place on this property that accepts typed input is the booking widget, a separate application described below.
- No third-party images, no preconnect hintsEvery image is served from this domain, and the pages carry no preconnect, dns-prefetch or preload directives pointing anywhere else.
- The copy buttonThe contact page has a button that copies our email address to your clipboard. It writes only when clicked, and writes only that address.
- Permissions-PolicyEvery response carries Permissions-Policy: geolocation=(), microphone=(), camera=(). No script on any page can ask your browser for your location, your microphone or your camera.
- HSTS, which your browser also storesStrict-Transport-Security with max-age 31536000, includeSubDomains and preload. Your browser remembers for a year that this domain must be reached over HTTPS. It identifies nobody and is treated as strictly necessary.
The contact page has no mailto: link; the address is plain text next to the copy button. With JavaScript switched off, that page shows “[email protected]” and no address at all.
Google Analytics
Measurement ID G-J5QWW3XMFW, loaded as gtag.js from www.googletagmanager.com on the fourteen public pages. Until you allow it, the script is never requested: nothing is fetched from Google, no cookie is written, no measurement request is sent and no advertising request is sent. The gate is not geographic and applies to every visitor.
- _gaFirst-party cookie written by the Google tag, in the form GA1.1 followed by a client identifier and a timestamp. It ties your page views into one session and recognises the same browser on a later visit.
- _ga_J5QWW3XMFWThe companion cookie for this property — its name is the measurement ID with the G- removed. It carries session state: a session identifier, counters and timestamps.
- How long they lastTwo years. The tag is configured with a bare config call and no cookie expiry parameter, so Google’s documented default applies.
- Nothing else in this domain’s cookie jarNo _gid, no _gat, no other cookie for richportmedia.ai. What Google sets on Google’s own domains when your browser talks to them sits on Google’s side and is not visible to us.
- What is transmittedOn a measured page view the tag sends to analytics.google.com: the full page URL, the page title, your screen resolution, your language, and user-agent client hints — platform, platform version, CPU architecture, bitness and browser version list. Your IP address is visible to Google as a property of the request. The tag sends aip=1, which asks Google to anonymise it; whether that happens is on Google’s side.
- The advertising requestThe same tag also sends a request to Google’s advertising path, /ads/ga-audiences, on the Google Ads domain localised to the visitor — from Puerto Rico that is www.google.com.pr, elsewhere the local equivalent. It carries the measurement ID and your _ga client identifier, and it goes with npa=0, meaning non-personalised advertising is not set, so personalised advertising signals are permitted.
- If you allow one and not the otherMeasurement and advertising ride on the same tag. Allow measurement and refuse advertising and the tag runs with the advertising signals off, so no /ads/ga-audiences request is made. If that separation fails to hold, the tag does not load at all.
Google is the processor for both the measurement and the advertising request; which Google company, on what terms, and where the data ends up is in the privacy notice. Google Analytics does not run on the 404 page.
Scripts added by Cloudflare
Cloudflare serves this site and modifies the response on its way to you. None of the following appears in the site’s source files, and the consent banner does not control any of it.
- Cloudflare Web Analyticsbeacon.min.js from static.cloudflareinsights.com, followed by a POST to /cdn-cgi/rum on this domain. It measures real-user performance and traffic. Cloudflare injects it server-side and only for browser-like requests. It has been observed setting no cookie and writing nothing to local or session storage. It is a second analytics processor — Cloudflare, Inc., United States — and it is not behind the consent banner.
- Bot detectionA script from /cdn-cgi/challenge-platform/, followed by a POST back to the same path. It collects browser and device signals to score whether the visitor is a person or an automated client. It runs on every page including the 404, where it is the only Cloudflare script present. It is bot scoring, not analytics.
- Email address obfuscationOn the contact page only. Cloudflare rewrites our address into an encoded attribute and loads email-decode.min.js from /cdn-cgi/scripts/ to decode it in your browser. It is incomplete: the same address remains in cleartext once, inside the page’s copy-button script. It stops simple automated harvesting of the address and nothing more.
- Network Error LoggingEvery response carries NEL and Report-To headers pointing at a.nel.cloudflare.com, with success_fraction 0.0 — your browser reports only requests that failed, never successful ones. Those reports carry your IP address, the URL and the error type, and they go to Cloudflare rather than to us.
No Cloudflare cookie has been observed on this site. Every response also carries HSTS, X-Content-Type-Options nosniff, X-Frame-Options DENY, Referrer-Policy strict-origin-when-cross-origin, and the Permissions-Policy above. There is no Content-Security-Policy. Referrer-Policy limits the Referer header sent to a third party to the bare origin; it does not limit the full page URL that the Google tag itself transmits.
The booking widget
The scheduler on the contact page is Tymeslot, open-source, running at cal.richportmedia.ai on a machine we rent and administer ourselves.
- How it is embeddedembed.js from cal.richportmedia.ai injects an iframe pointing at cal.richportmedia.ai/vincent. The script appends parent-origin=https://richportmedia.ai to that URL, so the booking server is told which page the widget is sitting on. The iframe communicates back to the page only by postMessage, with an origin check, and only to resize itself.
- _tymeslot_keySet by the booking app the moment the widget loads — when you open the contact page, before you click or type anything. Attributes: path=/; Secure; HttpOnly; SameSite=Lax; no expiry set, so it is a session cookie and your browser drops it at the end of the browsing session. Decoded, it carries a cross-site-request-forgery token and a locale — nothing else, and no identifier for you. It is the only cookie the app sets on load, it is strictly necessary under §25(2) TDDDG and regulation 6(4) PECR, and it is not behind the banner.
- Your timezoneThe booking page reads your timezone from your browser and shows it back to you so that slots appear in your local time. It is worked out on your device rather than from your IP address, and nothing is stored to do it.
- Where the request goescal.richportmedia.ai is not proxied through Cloudflare. Its DNS record points straight at the origin — a Hetzner CPX11 in Ashburn, Virginia, contracted through Hetzner Online GmbH in Germany. Your IP address reaches that server directly, and Cloudflare is not in the path for anything you do inside the widget.
- More permissions than it usesThe booking app’s Content-Security-Policy whitelists Google and Stripe origins. The page as served loads none of them: every asset comes from cal.richportmedia.ai. No payment is taken on that page.
Inside the iframe you are on a different origin running a different application. What you type into it, who receives it and what happens to it afterwards is a separate notice under GDPR Article 13: booking privacy.
Analytics and the booking server
Google sets _ga and _ga_J5QWW3XMFW on the registrable domain — .richportmedia.ai — rather than on a single host. Your browser therefore sends them to every host under that domain, and cal.richportmedia.ai is one of them.
Refusing and withdrawing consent
Consent can be refused or withdrawn at any time, at no cost and without writing to us.
- On the bannerThree options: allow, refuse, or set the categories yourself. Refuse and no non-essential storage is written and the Google tag is never fetched. Your choice is stored on your device, as described above.
- Changing your mindThe banner can be reopened from every page, and whatever you choose then replaces what you chose before. Clearing this site’s cookies and site data also works: that deletes the stored choice along with _ga and _ga_J5QWW3XMFW, and the banner returns on your next visit. GDPR Article 7(3) entitles you to withdraw consent at any time and requires that it be as easy as giving it.
- At the browser levelBlock cookies for this domain, use your browser’s tracking protection, or use a content blocker to block www.googletagmanager.com, analytics.google.com and static.cloudflareinsights.com. Google also publishes a browser add-on that stops its measurement script from sending data. Whatever you block, we do not receive.
- What refusing on the banner does not stopThe Cloudflare code in the section above. It is injected at the edge and the banner does not control it. Only a browser-level or network-level block stops it.
- What refusing does not stop on the contact page_tymeslot_key, if the widget loads. It is the booking app’s strictly-necessary cookie and the form cannot be submitted safely without it. Blocking cookies for cal.richportmedia.ai stops it, and stops the widget working.
- What nothing stopsYour IP address reaching a server. Cloudflare terminates the connection for this site; the Hetzner machine in Ashburn terminates it for the booking widget. What is done with what those servers see is in the privacy notice.
- Do Not Track and Global Privacy ControlNeither signal is read. Nothing non-essential loads until you press allow.
Switching JavaScript off works: none of the Cloudflare scripts run either. Two consequences: the contact page will not display our email address, and the booking widget will not load. The scheduler is also reachable directly at cal.richportmedia.ai/vincent, which requires JavaScript as well.
Before the consent banner
The consent controls described above took effect on 12 August 2026.
On 12 August 2026 the consent banner went live and this page went up with it, alongside the privacy notice, the booking notice, the data collection notice, the disclosures and the terms. From that date the Google tag is fetched only after you allow it. The measurement data collected before that date is still in the Google Analytics property and has not been deleted.
What did not change on that date: Cloudflare’s edge code still runs outside the banner, and the booking cookie is still set when the widget loads.
Related notices
- Privacy noticeWho the controller is, what is processed, the companies that touch it, and where it sits.
- Booking privacyThe GDPR Article 13 notice for the scheduling widget: which fields are needed to make a booking, who receives them, and where the server is.
- Data collection and outreachWhere business contact data comes from, the GDPR Article 14 notice for people whose details we did not collect from them, and how to be removed and stay removed.
- DisclosuresPaid-article compensation disclosure under 15 U.S.C. 77q(b) and the labelling standards applied to that content.
- TermsThe terms on which this site is published.
The controller for the processing described on this page is Richport Media Inc. Requests and corrections: [email protected]. Corrections are made on the page rather than in a reply.