1. Introduction
This Cookie Policy explains how Ghulam Mustafa Mahmood trading as Auctaris uses cookies, local storage, session storage and similar technologies on the Auctaris website and through connected online services.
In this Policy, these tools are referred to collectively as storage and access technologies. The Privacy and Electronic Communications Regulations 2003 (PECR), as amended, apply to cookies and to other technologies that store information on or access information from a user’s device, including browser storage.
Some storage and access technologies may be used without consent where a specific PECR exception applies. Other technologies require valid consent before they are used. Auctaris aims to give clear information about each technology, its purpose, the relevant provider and its duration or control.
2. Contact details
- Business
- Ghulam Mustafa Mahmood trading as Auctaris
- Address
- 9 Rydall Terrace, Leeds, West Yorkshire, England, LS11 9LD
- info@auctaris.co.uk
Further information about Auctaris’s handling of personal data is available in the Auctaris Privacy Notice: auctaris.co.uk/privacy
4. Categories of technologies used
4.1 Strictly necessary and security technologies
These technologies are used where essential to transmit a communication, provide a service specifically requested by a visitor, protect the service against abuse, maintain security or authenticate authorised access. Where the relevant PECR exception applies, prior consent is not required.
4.2 Functionality and appearance technologies
These technologies remember a choice or interface state, such as whether a chat widget is open or which appearance setting is selected. Their consent position depends on their purpose and whether a specific PECR exception applies.
4.3 Analytics technologies
Analytics technologies collect information about how an online service is used. HubSpot classifies certain browser-storage items used on its hosted pages as non-essential analytics technologies. Where no PECR exception applies, these technologies require an appropriate consent or preference control before use.
4.4 Advertising technologies
Auctaris does not currently use advertising, behavioural-profiling or social-media tracking cookies on the main Auctaris website. If such technologies are introduced in the future, Auctaris will provide the required information and controls before enabling them.
5. Technologies used on the main Auctaris website
The following browser-storage item was identified on the main Auctaris website during the August 2026 audit:
| Name | Provider and type | Purpose | Duration and control |
|---|---|---|---|
auctaris_chat_session_v3 | Auctaris - local storage | Maintains the visitor’s chatbot session and enables the requested chatbot service to continue across page refreshes. It is created only after the visitor opens the chatbot. It is not used for advertising, cross-site tracking or behavioural profiling. | Treated as expired after 30 days of inactivity and removed when the chatbot is next opened, or earlier if the visitor clears website data or the chatbot removes or replaces the stored session. Treated as requested-service storage where it is essential to provide the chatbot feature. |
Restricted administrative authentication storage may be created when an authorised Auctaris administrator accesses protected administrative functions. It is not created for ordinary website visitors and is used for access control and security.
6. Enquiry form
The enquiry form on the Auctaris website currently opens the visitor’s own email application using a prepared email message. During the website audit, the form did not set a separate cookie or browser-storage item and did not transmit the entered information to an Auctaris website database before the visitor chose to send the email.
Personal data contained in a sent enquiry is handled as explained in the Auctaris Privacy Notice.
7. Website hosting and fonts
7.1 Netlify
The Auctaris website is hosted using Netlify. Netlify may process technical request information needed to deliver and secure the website, including IP addresses, request details and server logs. This server-side processing does not necessarily involve storing or accessing information on the visitor’s device.
7.2 Google Fonts
The website may request font resources supplied by Google Fonts. No Google Fonts cookie was identified on the main Auctaris website during the audit. A browser request for a font may nevertheless disclose technical information, such as the IP address and browser request information, to the provider. Further details are provided in the Auctaris Privacy Notice.
8. HubSpot-hosted consultation page
The Book a consultation link directs visitors to the HubSpot-hosted scheduling page at meetings.auctaris.co.uk. When a visitor follows that link, they leave the main Auctaris website and use a HubSpot-hosted service. HubSpot and its infrastructure providers may use their own cookies and browser storage to provide, protect, operate and measure that service.
The following technologies were observed during the audit or are documented by the relevant provider as potentially used when the corresponding feature is executed:
| Name | Provider and type | Purpose | Duration and control |
|---|---|---|---|
__cf_bm | Cloudflare - cookie | Supports bot detection and security on the HubSpot-hosted service. Cloudflare states that it does not track users from site to site or session to session through this cookie. | Expires after 30 minutes of continuous inactivity. Necessary security technology. |
hubspot-modern-theme | HubSpot - local storage | Applies or remembers the appearance or theme of the HubSpot-hosted page. | Until the choice is changed or the visitor clears website data. Appearance-preference technology. |
hs-messages-is-open | HubSpot - cookie | Remembers whether the HubSpot chat widget is open. | 30 minutes after inactivity. |
hs-messages-hide-welcome-message | HubSpot - cookie | Prevents the HubSpot chat welcome message from reappearing immediately after it is dismissed. | One day. |
__hmpl | HubSpot - session or local storage | Contains metadata about product tracking events collected by HubSpot during use of its hosted service. HubSpot states that it does not contain personally identifiable information or information identifying the visitor’s device or hardware. | HubSpot controls the storage location and lifecycle. HubSpot classifies this as non-essential analytics storage. It requires consent unless a specific PECR exception applies and all conditions of that exception, including any objection requirement, are satisfied. |
hublytics_events_53 | HubSpot - session or local storage | Temporarily stores HubSpot product tracking events until they are transmitted over the network. | HubSpot controls the storage location and lifecycle. HubSpot classifies this as non-essential analytics storage. It requires consent unless a specific PECR exception applies and all conditions of that exception, including any objection requirement, are satisfied. |
messagesUtk | HubSpot - cookie; may be set after chat consent and use | Recognises a chat visitor and can restore HubSpot chat history. | Six months where set. HubSpot functionality cookie used to recognise a chat visitor and restore chat history. Under the current configuration, HubSpot asks the visitor to agree before the cookie is used. |
_GRECAPTCHA | Google reCAPTCHA - cookie; may be set when reCAPTCHA executes | Provides risk analysis used to distinguish legitimate users from automated activity and protect the scheduling form from spam and abuse. | Provider-controlled duration. Google describes it as a necessary security cookie. |
The exact technologies present may vary according to the visitor’s browser, privacy settings, whether the booking or chat feature is used, the choices made through any available consent control, and changes made by HubSpot, Cloudflare or Google.
Auctaris does not use HubSpot’s analytics storage for independent advertising or cross-site behavioural profiling. HubSpot classifies __hmpl and hublytics_events_53 as non-essential analytics storage. They require consent unless a specific PECR exception applies and all conditions of that exception are satisfied.
9. HubSpot chat and consent choices
The optional HubSpot chat feature displays a consent message before allowing the visitor to begin the chat where the relevant chat-history setting applies.
- The visitor must actively choose to agree before the optional chat begins.
- The chat-history technology should not be used before the required choice is made.
- If the visitor does not agree, the optional chat feature may be unavailable.
- Visitors may change or withdraw their choice through any cookie-preference control made available on the HubSpot page and may also delete the relevant website data through their browser.
Auctaris will keep the HubSpot page configuration under review so that consent-based technologies provide an accessible means of revisiting the visitor’s choice.
10. Google reCAPTCHA
The HubSpot consultation form uses Google reCAPTCHA to help protect the service against spam, automated submissions and abuse. Google states that reCAPTCHA sets the necessary _GRECAPTCHA cookie when executed to provide its risk analysis.
reCAPTCHA may process technical and device information when assessing whether activity is likely to originate from a person or an automated system. Visitors using the HubSpot scheduling page may also be subject to Google’s applicable privacy and service terms.
12. Consent and other controls
Where no PECR exception applies, Auctaris will ensure that the relevant technology remains disabled until the user has provided valid consent.
- A consent request will explain the relevant purpose clearly.
- Consent will require a clear positive action.
- Rejecting non-essential technologies will be presented as an accessible option.
- Visitors will be able to revisit their choice.
- Withdrawing consent will be as easy as giving it.
- Withdrawal will not affect processing carried out lawfully before the withdrawal.
Where Auctaris relies on a statutory PECR exception instead of consent, it will assess and document the conditions of that exception and provide any required information or objection mechanism.
13. Retention and review
Auctaris will not keep storage and access technologies for longer than is reasonably necessary for their stated purpose. The durations in this Policy reflect the August 2026 audit and current provider information.
The Auctaris chatbot session is treated as expired after 30 days of inactivity and is removed when the chatbot is next opened, or earlier if the visitor clears website data or the system removes or replaces the stored session.
Auctaris will review its cookie and browser-storage audit periodically and whenever it changes the website, chatbot, booking service or third-party providers.
14. Third-party information
The following official provider information may assist visitors who want further details: