Introduction
Effective Date: 28/07/2026
Version: 1.0
This Cookie Policy explains how HackYourWay.com (“we”, “us”, “our”) uses cookies, localStorage and similar tracking technologies when you visit our website at https://hackyourway.com. It tells you what these technologies are, why we use them, and how you can control them.
This policy is separate from our Privacy Policy. It applies to all visitors, including those from the United Kingdom, the European Union/European Economic Area and the United States.
1. What are cookies?
A cookie is a small text file that a website places on your device (computer, phone or tablet) when you visit. Cookies are widely used to make websites work, remember your choices, and provide information to the site owner.
First‑party cookies are set by the website you are visiting. Only that website can read them.
Third‑party cookies are set by a domain other than the website you are visiting, usually by a service provider that the website has embedded (such as an advertising network or analytics service). These cookies can be read by the third party on different sites that use the same service.
localStorage is a technical feature of modern browsers that allows a website to store data locally on your device, similar to a cookie. The data remains in your browser and is not automatically sent to a server with every request. On our site, we use localStorage solely to save your course progress (see section 3.5).
Similar tracking technologies include pixels, web beacons and scripts. For example, Google Analytics uses a JavaScript tag that may set cookies or use first‑party identifiers. These technologies perform functions similar to cookies and are covered by this policy.
2. Why we use cookies
We use cookies and similar technologies to:
- make our website function correctly and securely;
- understand how you use our site so we can improve it;
- display advertisements, including personalised ads, through Google AdSense;
- remember the consent choices you make about cookies;
- support our course‑progress feature (via localStorage).
We do not use cookies to collect personal information that directly identifies you (such as your name or email address), and we do not maintain a database of personal data derived from cookies.
3. Types of cookies used on this website
Below we explain the categories of cookies and similar technologies we use, their purpose, legal basis, whether we need your consent, and how long they typically stay on your device.
3.1 Strictly necessary cookies
Purpose: These cookies are essential for the website to work. They enable core functions such as page navigation, maintaining your browsing session during a single visit, and keeping the site secure. Without them the site cannot operate properly.
Legal basis (UK/EU): These cookies are set under the exception in UK PECR and the EU ePrivacy Directive for strictly necessary storage, and on the basis of our legitimate interest in providing a functioning website (Article 6(1)(f) UK GDPR/EU GDPR). For US visitors they are required for the service you request.
Consent required: No. You cannot disable strictly necessary cookies through our consent management platform because the site would not work without them.
Typical retention: Most strictly necessary cookies are session cookies and are deleted when you close your browser. Any persistent strictly necessary cookie that is set for security or load‑balancing reasons will have a short lifetime (usually no more than a few hours or days).
Cookies used: Our website and hosting provider may set temporary session cookies where necessary. The exact cookie names depend on our hosting environment and website configuration.
3.2 Consent management cookies
Purpose: These cookies are set by our certified Consent Management Platform (CMP) to record the consent choices you make on the cookie banner. They remember whether you accepted, rejected or customised your preferences, so we can apply the right consent signals and respect your choices across visits.
Legal basis (UK/EU): The storage of your consent choice is necessary for compliance with legal obligations (Article 6(1)(c) UK GDPR/EU GDPR) and is strictly necessary under ePrivacy law.
Consent required: No. These cookies are set as soon as you interact with the consent banner, regardless of the choices you make. They do not track your browsing or identify you beyond recording your preferences.
Typical retention: The CMP’s consent cookie is typically stored for 13 months (reflecting IAB TCF policies) but the exact period is determined by our CMP provider and may vary. After expiry you will be asked to make your choices again.
3.3 Analytics cookies
Purpose: We use Google Analytics 4 to understand how visitors interact with our site—for example which pages are viewed, how much time is spent on the site, and whether visitors encounter errors. This information is aggregated and anonymised where possible. It helps us improve the website.
Legal basis (UK/EU): We only set analytics cookies when you give your explicit consent (Article 6(1)(a) UK GDPR/EU GDPR and the consent requirement of UK PECR/ePrivacy Directive). You may withdraw consent at any time.
Consent required: Yes. If you do not consent, Google Analytics 4 will not place cookies, and we will use only cookieless aggregated data signals (via Google Consent Mode v2) where available.
Typical retention: Google Analytics 4 cookies have the following default lifetimes:
- _ga – 2 years
- _ga_<container-id> – 2 years
The exact names and durations are managed by Google and may be updated from time to time. For more details, visit Google Analytics Cookie Usage.
3.4 Advertising cookies
Purpose: We display advertisements through Google AdSense. Advertising cookies help Google and its partners:
- select ads that are more relevant to you (personalisation);
- limit the number of times you see the same ad (frequency capping);
- measure ad performance and detect click fraud;
- create reports for advertisers.
Some of these cookies are set by Google; others may be set by third‑party ad providers that appear through our site.
Legal basis (UK/EU): We only use advertising cookies with your explicit consent (Article 6(1)(a) UK GDPR/EU GDPR and UK PECR/ePrivacy Directive). You can reject non‑essential cookies or customise your preferences.
Consent required: Yes. If you do not consent, AdSense will serve only non‑personalised ads that do not rely on cookies, or contextual ads, depending on your consent signals and Google Consent Mode v2.
Typical retention: Google AdSense cookies have varying lifetimes. Common examples include:
- __gads – up to 13 months in the EEA/UK
- _gac_<property-id> – 90 days
- FPAU – 90 days
Exact cookie names and retention periods are controlled by Google and may change. For more information see Google’s Advertising Cookie Policy.
3.5 localStorage (Course Progress)
Purpose: We use the browser’s localStorage to save your progress when you work through a course on the website. This allows you to resume where you left off. The data is stored only on your device; it is never transmitted to our servers or shared with any third party.
Legal basis (UK/EU): This storage is strictly necessary to provide a feature you have explicitly requested (the course progress function). It falls within the exception under UK PECR and the EU ePrivacy Directive. The processing is also based on our legitimate interest in delivering the service you asked for (Article 6(1)(f)).
Consent required: No. The feature is required for saving course progress. You may disable or clear localStorage using your browser settings, although doing so will reset your saved progress.
Retention: Data remains in localStorage until you actively clear it or your browser deletes it. There is no automatic expiry set by us.
4. Cookies and technologies used by third parties
Some of the technologies on our site are provided by third parties. They may process information they collect for their own purposes, in accordance with their own privacy policies. We do not control those third‑party cookies directly.
4.1 Google Analytics 4
Google Analytics 4 uses first‑party cookies (_ga, _ga_<container-id>) and JavaScript to collect information about your visit. Google may process the data on our behalf and, depending on the service and applicable law, may also process certain information as an independent controller. Google may also use the data for its own purposes, such as improving its services. For details, see the Google Analytics Privacy & Terms.
4.2 Google AdSense
Google AdSense uses third‑party cookies (such as __gads) and similar identifiers to serve ads, personalise them and measure performance. Google may combine this data with information from other sources. The use of AdSense cookies is subject to Google’s Privacy Policy and the Google Advertising Cookie Policy.
4.3 Google Consent Mode v2
Google Consent Mode is not a cookie but a mechanism that communicates your consent choices to Google services (see section 6). It adjusts how Google Analytics and Google AdSense behave based on the consents you grant.
4.4 Google Fonts (if remotely hosted)
We may serve fonts from Google Fonts to ensure a consistent visual presentation. When you load a page, your browser requests the font files from Google’s servers. This request includes your IP address. Google may process this data according to its Privacy Policy. No cookie is placed by Google Fonts, but the data transfer functions as a similar technology. Where applicable under local law, Google Fonts will only be loaded after obtaining any required consent. Otherwise they are loaded based on our legitimate interests in providing a consistent website experience.
4.5 Certified Consent Management Platform (CMP)
We use a CMP that is integrated with the IAB Transparency & Consent Framework (TCF) v2.2. The CMP sets a consent cookie (often named eupubconsent-v2, euconsent-v2 or a vendor‑specific name) that encodes your preferences in a standardised “TC string”. This string is shared with Google and other IAB TCF participants so they can respect your choices. The CMP provider processes your consent data for compliance purposes. Please review the CMP’s own privacy notice, accessible from the consent banner, for details.
4.6 IAB Transparency & Consent Framework (TCF)
Our site acts as a publisher within the IAB TCF v2.2. When you make your cookie choices, the CMP creates a digital signal (the TC string) that tells participating advertising technology companies what permissions they have. This helps ensure that your preferences are honoured across the advertising ecosystem. You can find more information about the TCF on the IAB Europe website.
5. Cookie consent
When you first visit our website, a cookie banner appears. The banner tells you that we use cookies and similar technologies and asks for your choices. It is operated by our certified CMP.
You can:
- Accept all cookies – give consent for analytics, advertising and any other non‑essential purposes;
- Reject all non‑essential cookies – refuse consent for analytics and advertising. Only strictly necessary cookies and localStorage will be used;
- Customise your preferences – open the “Cookie Settings” panel to choose which categories of cookies you allow (analytics, advertising). You can grant or deny consent for specific purposes.
The banner gives you genuine, granular control. Rejecting non‑essential cookies is as easy as accepting them.
Changing your choices later: You can withdraw or change your consent at any time by clicking the “Cookie Settings” link, which is displayed in the website footer or within this policy. Open the panel, adjust your preferences and save. The new choices take effect immediately for subsequent page loads.
Withdrawing consent: Withdrawing consent is just as straightforward. Simply open the Cookie Settings panel and toggle off any category you no longer agree to. It does not affect the lawfulness of processing based on consent before its withdrawal.
How consent is recorded: The CMP stores your preferences in a consent cookie on your device. Depending on the CMP provider, consent records may be stored to demonstrate compliance with applicable legal requirements. The TC string is sent to Google and other IAB TCF vendors so they know which purposes you have consented to.
Google Consent Mode integration: When you give or refuse consent, Google Consent Mode v2 translates your choices into specific signals (ad_storage, analytics_storage, ad_user_data, ad_personalization). Google then adjusts its behaviour accordingly (see section 6).
6. Google Consent Mode v2
Google Consent Mode v2 is a framework that allows Google tags (for analytics and ads) to behave differently depending on your consent choices. It does not place additional cookies; instead it uses the consent signals your browser sends after you interact with our cookie banner.
The four main consent types are:
- ad_storage – enables the storage of advertising‑related cookies (e.g. for ad measurement or remarketing). If consent is denied, Google will not read or write advertising cookies and will rely on conversion modelling.
- analytics_storage – controls whether Google Analytics 4 cookies are set. If denied, GA4 will not place cookies and will use cookieless signals for aggregated, modelled data.
- ad_user_data – controls whether data collected on our site can be used by Google to build user profiles for advertising purposes. When denied, user data will not be used for this purpose.
- ad_personalization – controls whether your data may be used to personalise the ads you see (remarketing, interest‑based advertising). When denied, Google will not use your data for personalised advertising on our site or elsewhere.
How it affects you:
- If you grant full consent, Google services operate with cookies and all advertising features.
- If you deny consent for advertising, ads will still be shown but they will be non‑personalised (contextual) and advertising cookies will not be set.
- If you deny consent for analytics, Google Analytics will not use cookies but will still provide aggregated reports using cookieless pings.
Consent Mode ensures that your choices are respected at a granular level, without breaking the basic functionality of Google services.
7. How to manage cookies
You have several ways to control and delete cookies and similar technologies.
7.1 Use our Cookie Settings
Click the “Cookie Settings” link in the website footer at any time to open the CMP panel and change your preferences.
7.2 Delete cookies
You can delete all cookies stored by your browser. In most browsers, go to Settings → Privacy & Security → Cookies and site data → See all site data and search for “hackyourway.com”. Remove the entries.
7.3 Clear localStorage
Your course progress is kept in localStorage. To delete it, open your browser’s developer tools (usually F12), go to the Application or Storage tab, find “Local Storage” under “hackyourway.com”, and clear the relevant key. Alternatively, you can clear all site data, which will also delete localStorage.
7.4 Browser settings
You can set your browser to block all cookies, block third‑party cookies, or warn you before a cookie is placed. Common settings paths:
- Chrome: Settings → Privacy and security → Cookies and other site data
- Firefox: Options → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy → Cookies and website data
- Edge: Settings → Cookies and site permissions
Please note that blocking all cookies may affect the functionality of the site.
7.5 Google Analytics opt‑out
Google provides a browser add‑on that prevents Google Analytics from using your data. You can download it at: Google Analytics Opt‑out Browser Add‑on.
7.6 Google Ad Settings
You can manage the ads you see and control some of the data Google uses for personalisation by visiting Google Ad Settings. This lets you turn off ad personalisation even if you have previously consented on individual sites.
7.7 Browser privacy settings
Many browsers include built‑in tracking protection and the ability to send “Do Not Track” signals. While we do not respond to the Do Not Track header directly (see section 9), we respect your explicit consent choices made through our CMP.
8. Global Privacy Control (GPC)
The Global Privacy Control (GPC) is a browser signal that communicates your preference to opt out of the sale or sharing of personal data. Where supported by our CMP and required by applicable law, we recognise the Global Privacy Control (GPC) signal as a valid opt‑out request for visitors covered by the California Consumer Privacy Act (CCPA/CPRA), Colorado Privacy Act, Virginia CDPA, Connecticut Data Privacy Act and Utah Consumer Privacy Act.
When a GPC signal is detected, we automatically set your advertising consent preferences to “denied” (ad_storage, ad_user_data, ad_personalization set to denied), treating it as a full opt‑out of targeted advertising and the “sale” or “sharing” of personal data. You do not need to provide additional consent through the banner for this effect to take place. Our CMP will reflect this in the consent record.
9. Do Not Track (DNT)
Some browsers offer a “Do Not Track” setting. At present there is no consistent industry or legal standard for responding to DNT signals. Because of that, our website does not alter its behaviour based solely on the DNT header. Instead, we rely on the explicit, granular consent mechanism provided by our cookie banner and CMP to honour your choices. This approach gives you clearer and more reliable control.
10. Cookie retention
The lifespan of a cookie depends on its type and who sets it.
- Session cookies (e.g. our strictly necessary session cookie) are deleted when you close your browser.
- Persistent cookies remain on your device for a fixed period. Common durations include:
- Consent management cookies: typically 13 months (or as configured by the CMP).
- Google Analytics cookies: up to 2 years.
- Google AdSense cookies: up to 13 months (EEA/UK), though some may persist longer outside those regions.
- localStorage data remains until you actively delete it or your browser clears the storage. No automatic expiry applies.
Please refer to the third‑party providers’ own documentation for the most current retention details. We do not extend retention beyond the period set by the cookie setter.
11. International data transfers
Some of the third parties we use, particularly Google, may process information collected through cookies and similar technologies in the United States and other countries outside the UK, EU/EEA.
Where such transfers occur, safeguards are in place to ensure an adequate level of protection for your data. Google relies on:
- the EU–US Data Privacy Framework (DPF) and the UK Extension to the DPF for transfers from the EU/EEA and the UK to certified US entities;
- Standard Contractual Clauses (SCCs) approved by the European Commission and the UK Government, together with supplementary measures where required.
You can read more about Google’s transfer mechanisms in its Privacy Policy and its Data Processing Amendment documentation. Our certified CMP may also transfer consent logs; the CMP provider’s privacy notice will detail any international transfers and the applicable safeguards.
12. Changes to this Cookie Policy
We may update this Cookie Policy from time to time to reflect changes in the cookies and technologies we use, or to stay compliant with legal requirements. When we make material changes, we will inform you by updating the “Effective Date” at the top of this page and, where necessary, asking for fresh consent through the cookie banner.
We encourage you to review this policy periodically to stay informed about how we use cookies and protect your privacy.
13. Contact
If you have questions about this Cookie Policy or your cookie choices, you can contact us at:
Krzysztof Sajdak
Email: HackYourWayStudio@gmail.com
