Cookie policy

This notice covers information written to, and read from, your device by this website and by the booking widget embedded on contact; outreach email is covered by data collection.

Last updated 25 August 2026. Richport Media Inc., 1225 Ave Ponce De Leon, PH 2020, San Juan, PR 00907, United States.

Puerto Rico Act 39-2012, Article 7. A $50,000 penalty attaches to publishing a privacy policy that does not correspond to actual practice — to publishing one that is wrong, not to failing to publish one.

What consent covers

The regulated act is storing information on, or gaining access to information stored in, your device, whether or not that information is a cookie and whether or not it is personal data.

  • §25(1) TDDDG — GermanyStoring information on, or gaining access to information already stored in, a user’s terminal equipment requires consent, whether or not that information is personal data. It applies to a service offered to users in Germany regardless of where the server sits. A breach is punishable by a fine of up to €300,000.
  • Regulation 6, PECR — United KingdomThe same rule in UK law: consent for storage on, or access to, a user’s terminal equipment, independent of where the server sits. Since 5 February 2026 the penalty ceiling has been raised to UK GDPR levels. Which contraventions fall in which tier is not yet settled.
  • Article 5(3), Directive 2002/58/ECThe ePrivacy Directive provision both national rules implement. The requirement is broadly the same across the EEA; the penalties are not.
  • The strictly-necessary exemption§25(2) TDDDG and regulation 6(4) PECR exempt storage that is strictly necessary to provide the service requested. It is narrow. It covers a cross-site-request-forgery token on a booking form and the record of a refusal already given. It does not cover a measurement cookie.
  • GDPR Article 6(1)(a)Where consented storage then produces personal data, consent is also the lawful basis for processing it. Article 7(3) gives you the right to withdraw at any time, and requires that withdrawing be as easy as giving.
  • Quebec — Law 25Quebec is the one part of North America on the consent-first side of the line: the Act respecting the protection of personal information in the private sector, as amended by Law 25, requires consent before non-essential tracking. Visitors we place in Quebec are treated exactly like visitors in the EEA.
  • The United States and the rest of CanadaNo US state privacy law requires consent before analytics or advertising storage; all of them work by notice and opt-out, and outside Quebec Canada runs on implied consent with clear notice. So there is no banner for those visitors: the storage described below is written by default, and the ways to refuse it are one section down. Several US state laws — California, Colorado, Connecticut, Texas and others — additionally require the Global Privacy Control browser signal to be honoured as an automatic opt-out, and it is, as described below.

Cookies this site sets

Fourteen public pages and a 404, served as static files by Cloudflare Pages, plus one small edge function the consent logic asks where you are. There is no account, no login and no server-side session.

  • Your banner choiceYour answer to the banner is stored on your device. It records what you chose and nothing else — no identifier, no profile, nothing that follows you off this domain. It is strictly necessary storage, and you are not asked to consent to it.
  • A session counter, only after analytics is permittedWhere analytics runs — by your consent in the prior-consent regions, by refusable default elsewhere — the tag manager keeps one sessionStorage record on your device: how many distinct pages you have opened this visit, how long the tab has actually been in the foreground, and which engagement thresholds have already been counted, so none is counted twice. It measures interest in hiring us — four active minutes, four pages, six pages — and vanishes when the browsing session ends. Refuse analytics and it is never written.
  • Ad-click identifiers, carried in the address barArrive from an advertisement and the click identifiers in the landing URL — Google’s gclid, gbraid and wbraid, Microsoft’s msclkid, Meta’s fbclid, X’s twclid, LinkedIn’s li_fat_id, Outbrain’s ob_click_id, Taboola’s tblci, and utm parameters, plus the landing path and referring host — are kept with you by rewriting the links you click to include them — they travel in the address bar, visibly, from page to page. Deliberately so: carrying them in a cookie would be consent-requiring device storage, and this way is not — nothing is written to or read from your device for it. Arrive without an ad click and links stay clean. What happens to those identifiers if you book a call is on the booking privacy page.
  • Where you are, looked up but never storedTo decide whether to show the banner, the page asks this domain which country — and, for Canada, which province — Cloudflare places your connection in. The answer is two codes, it is not cached or shared between visitors, and nothing about it is written to your device or to any log of ours. If the lookup fails, the site assumes you are somewhere consent is required and shows the banner.
  • Nothing else, from usApart from the choice record our code writes to no storage: no cookie, no localStorage, no sessionStorage, no IndexedDB. It reads exactly one thing beyond that record: on the contact page, the _ga cookie — if analytics consent has put it there — to pass the analytics client identifier to the booking widget, as described under the booking section below. The hosting sets nothing either — there is no Set-Cookie header on the home page, on the contact page or on the font stylesheet.
  • Self-hosted fontsThirteen .woff2 files under /assets/fonts, served from this domain. The font stylesheet contains no external URL. No Google Fonts and no font CDN.
  • No formsThere is no form, input, textarea or select element anywhere in the site’s markup. The site collects nothing from you directly. The only place on this property that accepts typed input is the booking widget, a separate application described below.
  • No third-party images, no preconnect hintsEvery image is served from this domain, and the pages carry no preconnect, dns-prefetch or preload directives pointing anywhere else.
  • The copy buttonThe contact page has a button that copies our email address to your clipboard. It writes only when clicked, and writes only that address.
  • Permissions-PolicyEvery response carries Permissions-Policy: geolocation=(), microphone=(), camera=(). No script on any page can ask your browser for your location, your microphone or your camera.
  • HSTS, which your browser also storesStrict-Transport-Security with max-age 31536000, includeSubDomains and preload. Your browser remembers for a year that this domain must be reached over HTTPS. It identifies nobody and is treated as strictly necessary.

The contact page has no mailto: link; the address is plain text next to the copy button. With JavaScript switched off, that page shows “[email protected]” and no address at all.

Google Analytics

Measurement ID G-J5QWW3XMFW, loaded from www.googletagmanager.com on the thirteen public pages through Google Tag Manager container GTM-NXQHWBFT, which also carries the advertising tags described below. The gate is geographic, because the law is. For visitors in the EEA, Iceland, Liechtenstein, Norway, the United Kingdom, Switzerland and Quebec, the script is never requested until you allow it: nothing is fetched from Google, no cookie is written, no measurement request is sent and no advertising request is sent. For everyone else the tag loads by default with measurement and advertising signals on, and switching either off — from the banner, reopened by the footer links — is honoured on the spot and remembered. A stored refusal is honoured everywhere, whichever regime you made it under.

  • _gaFirst-party cookie written by the Google tag, in the form GA1.1 followed by a client identifier and a timestamp. It ties your page views into one session and recognises the same browser on a later visit.
  • _ga_J5QWW3XMFWThe companion cookie for this property — its name is the measurement ID with the G- removed. It carries session state: a session identifier, counters and timestamps.
  • How long they lastTwo years. The tag is configured with a bare config call and no cookie expiry parameter, so Google’s documented default applies.
  • Nothing else in this domain’s cookie jarNo _gid, no _gat, no other cookie for richportmedia.ai. What Google sets on Google’s own domains when your browser talks to them sits on Google’s side and is not visible to us.
  • What is transmittedOn a measured page view the tag sends to analytics.google.com: the full page URL, the page title, your screen resolution, your language, and user-agent client hints — platform, platform version, CPU architecture, bitness and browser version list. Your IP address is visible to Google as a property of the request. The tag sends aip=1, which asks Google to anonymise it; whether that happens is on Google’s side.
  • The advertising requestThe same tag also sends a request to Google’s advertising path, /ads/ga-audiences, on the Google Ads domain localised to the visitor — from Puerto Rico that is www.google.com.pr, elsewhere the local equivalent. It carries the measurement ID and your _ga client identifier, and it goes with npa=0, meaning non-personalised advertising is not set, so personalised advertising signals are permitted.
  • If you allow one and not the otherMeasurement and advertising ride on the same tag, separated by Google’s Consent Mode signals. Allow measurement and refuse advertising and the tag runs with ad_storage, ad_user_data and ad_personalization denied, so no advertising identifier is stored and Google is told to redact ad data on what is sent.
  • Global Privacy ControlIf your browser sends the GPC signal, the advertising signals are set to denied automatically on every page load, before anything else runs, and the advertising option in the banner is disabled. This happens for every visitor, not only in the US states whose laws require it. GPC is a browser setting, not a stored choice, so it applies for exactly as long as your browser sends it.
Scope of the third-party-cookie statement made elsewhere on this site. Statements that our attribution method was built without reliance on third-party cookies describe how media is bought for clients. They are not statements about this website, which fires a Google advertising request on the same tag as the measurement.

Google is the processor for both the measurement and the advertising request; which Google company, on what terms, and where the data ends up is in the privacy notice. Google Analytics does not run on the 404 page.

Microsoft Advertising

The same container carries Microsoft’s UET tag, for measuring Microsoft Advertising campaigns. It is behind the advertising choice, not the analytics one: it loads only when advertising storage is permitted — never in the prior-consent regions without your allow, never while your browser sends Global Privacy Control, and never after a refusal anywhere.

  • What loadsbat.js from bat.bing.com, which then reports page views and booking conversions to Microsoft. Refuse advertising and it is never fetched.
  • _uetsid and _uetvidFirst-party cookies set by the tag when it runs: a session identifier lasting about a day, and a visitor identifier lasting about thirteen months. What Microsoft sets on its own domains when your browser talks to bat.bing.com sits on Microsoft’s side.
  • RecipientMicrosoft Corporation, United States. It receives the page URL, the referrer and, on a booking, the booking identifier — no name, no email address, no meeting details.

X (Twitter) advertising

The same container carries X’s pixel, for measuring X advertising campaigns and building advertising audiences there. It sits behind the same advertising choice as the Microsoft tag: it loads only when advertising storage is permitted — never in the prior-consent regions without your allow, never while your browser sends Global Privacy Control, and never after a refusal anywhere.

  • What loadsuwt.js from static.ads-twitter.com, which then reports page views and campaign events to X. Refuse advertising and the script is never fetched.
  • CookiesWhen you arrive from an X advertisement the pixel keeps the click identifier from the address bar in a first-party cookie so the visit can be attributed to that advertisement. What X sets on its own domains when your browser talks to its servers sits on X’s side, under X’s policies.
  • RecipientX Corp., United States (for visitors in the EEA and the United Kingdom, Twitter International Unlimited Company, Ireland, is X’s stated counterpart). It receives the page URL, the referrer and campaign measurement events — no name, no email address, no meeting details.

LinkedIn advertising

For LinkedIn there is no LinkedIn script on this site. Instead, when advertising storage is permitted, our own measurement server instructs your browser to fetch a single tracking pixel from px.ads.linkedin.com as pages are viewed — the same signal LinkedIn’s Insight Tag would send, without LinkedIn code running here. It is behind the advertising choice, with the same regional rules as the tags above.

  • What it carriesThe page URL and our LinkedIn advertising account identifier. Because the request goes to LinkedIn’s domain, your browser attaches whatever LinkedIn cookies it already holds — that is how LinkedIn recognises its own members and how advertising audiences are built there. Browsers that block third-party cookies send none, and the request then identifies nobody.
  • ConversionsCampaign conversion events are reported to LinkedIn server-to-server, from our measurement server rather than your browser, keyed to LinkedIn’s advertisement click identifier when one arrived in the address bar.
  • RecipientLinkedIn Corporation, United States (for visitors in the EEA and the United Kingdom, LinkedIn Ireland Unlimited Company). It receives page URLs, the click identifier when present and campaign measurement events — no name, no email address, no meeting details.

Scripts added by Cloudflare

Cloudflare serves this site and modifies the response on its way to you. None of the following appears in the site’s source files, and the consent banner does not control any of it.

  • Cloudflare Web Analyticsbeacon.min.js from static.cloudflareinsights.com, followed by a POST to /cdn-cgi/rum on this domain. It measures real-user performance and traffic. Cloudflare injects it server-side and only for browser-like requests. It has been observed setting no cookie and writing nothing to local or session storage. It is a second analytics processor — Cloudflare, Inc., United States — and it is not behind the consent banner.
  • Bot detectionA script from /cdn-cgi/challenge-platform/, followed by a POST back to the same path. It collects browser and device signals to score whether the visitor is a person or an automated client. It runs on every page including the 404, where it is the only Cloudflare script present. It is bot scoring, not analytics.
  • Email address obfuscationOn the contact page only. Cloudflare rewrites our address into an encoded attribute and loads email-decode.min.js from /cdn-cgi/scripts/ to decode it in your browser. It is incomplete: the same address remains in cleartext once, inside the page’s copy-button script. It stops simple automated harvesting of the address and nothing more.
  • Network Error LoggingEvery response carries NEL and Report-To headers pointing at a.nel.cloudflare.com, with success_fraction 0.0 — your browser reports only requests that failed, never successful ones. Those reports carry your IP address, the URL and the error type, and they go to Cloudflare rather than to us.
Storage and access not behind the banner. The performance beacon and the bot-detection script both read information from your device, and neither is behind the consent banner. The bot check forms part of the site’s defences. The performance beacon is a Cloudflare account setting and could be switched off. Neither is claimed to fall within the strictly-necessary exemption. Blocking them is covered under your choices, below.

No Cloudflare cookie has been observed on this site. Every response also carries HSTS, X-Content-Type-Options nosniff, X-Frame-Options DENY, Referrer-Policy strict-origin-when-cross-origin, and the Permissions-Policy above. There is no Content-Security-Policy. Referrer-Policy limits the Referer header sent to a third party to the bare origin; it does not limit the full page URL that the Google tag itself transmits.

The booking widget

The scheduler on the contact page is Tymeslot, open-source, running at cal.richportmedia.ai on a machine we rent and administer ourselves.

  • How it is embeddedembed.js from cal.richportmedia.ai injects an iframe pointing at cal.richportmedia.ai/vincent. The script appends parent-origin=https://richportmedia.ai to that URL, so the booking server is told which page the widget is sitting on; our own page code then appends the advertising attribution fields — the ad-click identifiers carried in the address bar, the landing page, the referring host and, if analytics is running, the _ga client identifier — so a booking can be attributed to the advertisement that produced it. The iframe communicates back to the page by postMessage, with an origin check, to resize itself and to report booking progress (a slot picked, a booking confirmed) so a conversion can be counted.
  • _tymeslot_keySet by the booking app the moment the widget loads — when you open the contact page, before you click or type anything. Attributes: path=/; Secure; HttpOnly; SameSite=Lax; no expiry set, so it is a session cookie and your browser drops it at the end of the browsing session. Decoded, it carries a cross-site-request-forgery token and a locale — nothing else, and no identifier for you. It is the only cookie the app sets on load, it is strictly necessary under §25(2) TDDDG and regulation 6(4) PECR, and it is not behind the banner.
  • Your timezoneThe booking page reads your timezone from your browser and shows it back to you so that slots appear in your local time. It is worked out on your device rather than from your IP address, and nothing is stored to do it.
  • Where the request goescal.richportmedia.ai is not proxied through Cloudflare. Its DNS record points straight at the origin — a Hetzner CPX11 in Ashburn, Virginia, contracted through Hetzner Online GmbH in Germany. Your IP address reaches that server directly, and Cloudflare is not in the path for anything you do inside the widget.
  • More permissions than it usesThe booking app’s Content-Security-Policy whitelists Google and Stripe origins. The page as served loads none of them: every asset comes from cal.richportmedia.ai. No payment is taken on that page.

Inside the iframe you are on a different origin running a different application. What you type into it, who receives it and what happens to it afterwards is a separate notice under GDPR Article 13: booking privacy.

Analytics and the booking server

Google sets _ga and _ga_J5QWW3XMFW on the registrable domain — .richportmedia.ai — rather than on a single host. Your browser therefore sends them to every host under that domain, and cal.richportmedia.ai is one of them.

What that means in practice. If analytics is running and you open the booking widget, the booking server receives your Google Analytics client identifier twice over: incidentally, in the request headers, because of the cookie’s domain scope; and deliberately, because the contact page passes it in the widget address as one of the attribution fields, and the scheduler stores it on the booking record. The identifier is the key to an otherwise pseudonymous analytics record, and a booking is not pseudonymous — it carries the details you type in, including the corporation name the form requires. So the join is no longer hypothetical: it exists on the booking record, on purpose, to attribute the booking to its session and its advertisement. It happens only when analytics is permitted under the regional rules above — refuse analytics and there is no _ga identifier to pass. The booking privacy page states what is done with it and what leaves the booking system.

Refusing and withdrawing consent

Consent can be refused or withdrawn at any time, at no cost and without writing to us.

  • On the bannerThree options: allow, refuse, or set the categories yourself — analytics and advertising are separate checkboxes. Where the banner appears automatically (EEA, UK, Switzerland, Quebec), refusing means no non-essential storage is written and the Google tag is never fetched. Everywhere else the panel opens from the footer, shows the categories currently running, and refusing stops them and deletes nothing you did not agree to keep. Your choice is stored on your device, as described above, and a refusal travels with you across every regime.
  • The footer, on every pageTwo links open the same panel: “Consent settings” and, for visitors exercising a right under a US state law, “Do Not Sell or Share My Personal Information.” Rejecting all in that panel is the opt-out: advertising and analytics storage stop, and the refusal is remembered.
  • Changing your mindThe banner can be reopened from every page, and whatever you choose then replaces what you chose before. Clearing this site’s cookies and site data also works: that deletes the stored choice along with _ga and _ga_J5QWW3XMFW, and the banner returns on your next visit. GDPR Article 7(3) entitles you to withdraw consent at any time and requires that it be as easy as giving it.
  • At the browser levelBlock cookies for this domain, use your browser’s tracking protection, or use a content blocker to block www.googletagmanager.com, analytics.google.com and static.cloudflareinsights.com. Google also publishes a browser add-on that stops its measurement script from sending data. Whatever you block, we do not receive.
  • What refusing on the banner does not stopThe Cloudflare code in the section above. It is injected at the edge and the banner does not control it. Only a browser-level or network-level block stops it.
  • What refusing does not stop on the contact page_tymeslot_key, if the widget loads. It is the booking app’s strictly-necessary cookie and the form cannot be submitted safely without it. Blocking cookies for cal.richportmedia.ai stops it, and stops the widget working.
  • What nothing stopsYour IP address reaching a server. Cloudflare terminates the connection for this site; the Hetzner machine in Ashburn terminates it for the booking widget. What is done with what those servers see is in the privacy notice.
  • Do Not Track and Global Privacy ControlGlobal Privacy Control is read and honoured: the advertising signals are denied automatically while your browser sends it, for every visitor. Do Not Track, the older and legally weightless signal, is not read.

Switching JavaScript off works: none of the Cloudflare scripts run either. Two consequences: the contact page will not display our email address, and the booking widget will not load. The scheduler is also reachable directly at cal.richportmedia.ai/vincent, which requires JavaScript as well.

Before the consent banner

The consent controls described above took effect on 12 August 2026, and became region-based on 25 August 2026.

Before 12 August 2026. This site had no consent banner, no cookie notice, no privacy policy and no terms. Google Analytics 4 loaded on all eight public pages for every visitor, and _ga and _ga_J5QWW3XMFW were written before anyone had the chance to refuse them. The advertising request described above went with them. For visitors in Germany and the United Kingdom that was storage without consent under §25 TDDDG and regulation 6 PECR.

On 12 August 2026 the consent banner went live and this page went up with it, alongside the privacy notice, the booking notice, the data collection notice, the disclosures and the terms. From that date to 25 August 2026 the Google tag was fetched only after an explicit allow, for every visitor everywhere. The measurement data collected before 12 August is still in the Google Analytics property and has not been deleted.

On 25 August 2026 the gate became geographic, matching the consent rules to the law of the place the visit comes from. Visitors in the EEA, the UK, Switzerland and Quebec kept the prior-consent banner unchanged. Visitors everywhere else stopped seeing a banner; for them the tag now loads by default with measurement and advertising on, refusable at any time from the footer links. The Global Privacy Control signal has been honoured from the same date. A refusal stored under the old regime kept its effect; an old acceptance was discarded rather than widened, because it never covered the advertising category the panel now asks about separately.

What did not change on that date: Cloudflare’s edge code still runs outside the banner, and the booking cookie is still set when the widget loads.

Related notices

  • Privacy noticeWho the controller is, what is processed, the companies that touch it, and where it sits.
  • Booking privacyThe GDPR Article 13 notice for the scheduling widget: which fields are needed to make a booking, who receives them, and where the server is.
  • Data collection and outreachWhere business contact data comes from, the GDPR Article 14 notice for people whose details we did not collect from them, and how to be removed and stay removed.
  • DisclosuresPaid-article compensation disclosure under 15 U.S.C. 77q(b) and the labelling standards applied to that content.
  • TermsThe terms on which this site is published.

The controller for the processing described on this page is Richport Media Inc. Requests and corrections: [email protected]. Corrections are made on the page rather than in a reply.