Legal
Cookies & website storage
talltree.tech sets no cookies. None — not for analytics, not for advertising, not for preferences. That is why there is no cookie banner: there are no non-essential cookies to ask consent for.
What follows is the complete inventory of what the site does use in your browser.
PostHog analytics — cookieless
We measure how the site is used (page views, clicks on key buttons and forms) with PostHog running in cookieless mode. No cookies are set, nothing tracks you across sites, and there is no fingerprinting. Events travel first-party via ketchup.talltree.tech (a PostHog-managed proxy on our domain) to PostHog’s EU cloud.
Google tag — cookieless, consent permanently denied
We run Google’s measurement tag (Google Analytics 4, linked to our Google Ads account) in a deliberately restricted mode: its consent state is set to denied for every signal and is never granted. In that mode it sets no cookies and uses no storage in your browser at all — it appears on this page to be disclosed, not because it stores anything. What Google receives are anonymous, consent-flagged pings used for aggregate and statistically modelled campaign measurement (which pages were visited after an ad click — never a profile of you).
Two further reductions: the tag and all of its pings stay on our own domain (relish.talltree.tech, a proxy we run on Cloudflare) — your browser never connects to a Google server — and our proxy strips your IP address before relaying, so Google does not receive it. There is no remarketing, no ad personalisation, and no cross-site tracking.
Cloudflare Turnstile — the forms bot-check, no cookies
The contact form carries a small Cloudflare Turnstile widget (an embedded frame from challenges.cloudflare.com) that tells humans and bots apart without puzzles. In the mode we use, passing the check issues a one-time token inside the form itself — not a cookie. Turnstile transiently inspects connection signals (your IP address, TLS fingerprint and browser user-agent) strictly to detect bots; Cloudflare publishes the details in its Turnstile privacy addendum. We do not use Turnstile’s optional “pre-clearance” mode, which is the variant that would set a cookie.
One sessionStorage entry: tt_attribution
The site keeps one entry in sessionStorage under the key tt_attribution: a random session marker (a UUID minted fresh each browser session, meaningless outside it), the path of the page you landed on, and — if you arrived through a campaign link — the utm_*, gclid, or ref query parameters you arrived with.
- What it is for. When you submit a form or click a key button, this entry is attached so we know which campaign brought the enquiry, and the session marker lets us connect that submission to the pages viewed in the same visit. It identifies the session, not you: it cannot recognise you tomorrow, on another device, or on another site.
- Lifetime. Your current browser session only. sessionStorage is cleared automatically when the session ends. It is not a cookie, it stays first-party, and it is never shared across sites.
- How to clear it sooner. Close the tab or browser, or clear site data for talltree.tech in your browser settings. Every form works exactly the same without it.
Cloudflare Turnstile — bot check on forms
The contact form includes a Cloudflare Turnstile check to keep automated spam out. The widget loads from challenges.cloudflare.com and may use storage inside its own widget to run the bot check. The mailing-list signup uses no Turnstile, and the sample report has no form at all — it is published openly, so nothing is checked and nothing is collected when you read it.
Pages you choose to visit elsewhere
Buying a Readiness Snapshot happens on Stripe’s checkout pages; booking a call happens on Cal.com’s booking pages. Stripe and Cal.com set their own cookies there, under their own policies. Nothing those pages set is readable by talltree.tech.
Questions
Write to info@talltree.tech. For what happens to data once it reaches us, see the privacy notice.
Last updated: .