Home / Cookies & Consent
Four consent switches decide whether Google, Microsoft or Meta get anything from your visit, and every one starts turned off.
This page explains the banner you saw when you arrived, the identifiers that ride in on a paid click, and exactly what happens the moment you press decline.
The banner and what it controls
Google Ads and Microsoft Advertising send paid traffic to this site, and Meta Ads does on some campaigns. That means an advertising tag can sit on this domain, and the banner you saw on arrival is the switch for it. It is not decoration and it does not block the page — you can read every word here, book nothing, and never touch it, and the site still works.
The banner offers two buttons: allow storage, or decline. Nothing else on the page depends on your choice. The inquiry form still posts to our office whether you allow or decline. The chat widget still works either way. What changes is whether the four signals below get set to granted or stay at denied, and whether an identifier that arrived with your click gets attached to anything in our advertising accounts.
You can reopen this banner at any time from the Cookie Settings link in the footer of every page, including this one.
The four Consent Mode v2 signals
Google's Consent Mode v2 is a small set of named signals that our advertising and analytics tags read before they do anything. On page load, before you have made a choice, all four start at denied. They do not sit at a default of granted while we wait for you to notice the banner. Decline, and they get set back to denied explicitly, even if you had allowed them on an earlier visit and changed your mind on this one.
| Signal | Default | What it gates |
|---|---|---|
| ad_storage | Denied | Cookies or similar storage tied to serving or measuring an ad, including any value read back from a click identifier. |
| ad_user_data | Denied | Whether data about your visit can be sent to Google for advertising purposes at all. |
| ad_personalization | Denied | Whether that data can be used to build or refine an advertising audience. |
| analytics_storage | Denied | Cookies or storage used to measure how you moved through the site, apart from advertising. |
Two storage categories outside Consent Mode are treated as always on because the site cannot function without them: functionality_storage (holds your consent choice and the chat token) and security_storage (basic abuse protection on form posts). Neither is used for advertising and neither is a signal you can turn off, because turning it off would mean re-showing the banner on every single page load.
gclid, msclkid and fbclid
When you click a paid ad and land here, the advertising platform appends a short parameter to the web address. We do not add these ourselves — the platform does, and they show up in the address bar the moment the page loads, before you have touched the banner.
| Parameter | Source | Held under |
|---|---|---|
| gclid | Google Ads | ad_storage / ad_user_data |
| msclkid | Microsoft Advertising | ad_storage / ad_user_data |
| fbclid | Meta Ads | ad_storage / ad_user_data |
Because ad_storage and ad_user_data both start denied, a click identifier that arrives on your first pageview is not written to a durable cookie and is not sent back to the issuing platform until you allow storage. If you decline, or you never touch the banner, the parameter sits in the address bar for that one page load and nothing captures it into ad tooling. Allow storage, and the identifier is passed to the matching platform so it can credit the click that brought you here — that is the entire purpose of the parameter, and it is why the platform attached it to the link in the first place.
Google Ads, Microsoft Advertising and Meta Ads
All three platforms operate under their own privacy terms, not ours. What we control is the consent gate on our side of the connection: whether their tag, running on this domain, is allowed to store anything or send anything back.
Google Ads reads ad_storage, ad_user_data and ad_personalization. With all three denied, Google's own systems still receive a conversion ping in a reduced, cookieless form for basic measurement, per Google's documented behavior under Consent Mode — no advertising cookie is set and no personalization occurs. Allow storage and the full signal, including gclid, flows through.
Microsoft Advertising reads the same class of signal for the Microsoft Ads (UET) tag and for msclkid specifically. Microsoft's own account of what it collects and how it is used sits in the Microsoft privacy statement, which we link here because Microsoft, not this bakery, is the party that can tell you what happens to data once it reaches their systems.
Meta Ads, on the campaigns where it runs, reads the same ad_storage and ad_user_data gate for the Meta pixel and for fbclid. Meta's handling of that data is set out in Meta's own data policy, which governs once information reaches Meta's systems, the same way Microsoft's statement governs its own.
None of the three platforms has reviewed, certified or approved this website. Running their advertising tag on our domain is not an endorsement from Google, Microsoft or Meta of the bakery, the recipes, or anything else on this site — it is a paid arrangement to place ads, gated by the consent signals above.
Declining, or changing your mind
Press decline and all four signals — ad_storage, ad_user_data, ad_personalization, analytics_storage — are set to denied immediately, as an explicit update, not a silent no-op. If any of them had previously been granted on this browser, that grant is revoked the same way. Your choice is written to this browser's local storage so the banner does not reappear on your next page, but nothing about the choice itself is sent to us; we do not maintain a server-side log of who accepted and who declined.
To change a decision you made earlier, open Cookie Settings in the footer. The banner reappears with both buttons live, and whichever one you press this time overwrites the last choice on this browser.
Global Privacy Control
If your browser or a browser extension sends a Global Privacy Control signal, this site reads that as a decline before you ever see the banner. All four Consent Mode v2 signals are set to denied on that basis, and they stay denied on that device regardless of any earlier choice, unless you separately press allow. A note confirming this appears in the banner itself when the signal is detected.
What we store ourselves
Outside the advertising signals, the site keeps a short list of things in your browser's local storage, not as cookies in the classic sense:
- Your consent choice (granted or denied) and the date you made it, so the banner is not shown again on every page.
- A chat session token, created only if you open the chat widget and send a first message, so the conversation continues if you navigate to another page.
Neither of those is shared with an advertising platform. The chat token is meaningless outside our own chat system; it does not carry your name, phone number or email in the token itself, only a reference to the thread you started.
Where the rest of this lives
This page covers storage and the advertising signal gate specifically. What we do with the information you type into an inquiry form — your name, phone, address, and the details of an order — is covered in the privacy policy, including the Accessibility Statement and the Data Request procedure folded into that same page. The booking, deposit and cancellation terms for custom cake and standing wholesale orders are in the terms of service. If something in this policy is unclear, call the shop or write to office@oakemberbakery.com and ask for it in plain language; someone will answer.