PhotoCrew.co.uk — Cookie Policy
Effective date: 5 August 2026 Version: 1.0
This Cookie Policy explains how PhotoCrew.co.uk (“PhotoCrew”, “we”, “us” or “our”) uses cookies and similar storage or access technologies on photocrew.co.uk and related pages, profiles, listings, dashboards, forms, Account areas, messaging tools, review tools, Paid Plans and associated services (the “Platform”).
PhotoCrew.co.uk is operated as a sole trader business under the trading name PhotoCrew.co.uk.
Contact:
hello@photocrew.co.uk
This Policy should be read with the Privacy Policy and Terms and Conditions.
1. Important summary
The Platform may use cookies and similar technologies to operate, secure and improve the service.
Some technologies are necessary for login, security, fraud prevention, forms, payments, subscriptions, preferences, routing and other requested functionality.
Other technologies may support analytics, personalisation, embedded content, social features, advertising or marketing.
Where consent is legally required, optional technologies will not be intentionally activated until the required consent has been obtained.
UK law contains limited exceptions for certain low-risk storage or access purposes, including specified statistical and functionality purposes, where all legal conditions are satisfied.
Users can manage optional choices through the available consent or Cookie Settings tool.
Blocking or deleting technologies may reduce functionality.
The exact technologies may change because WordPress, plugins, hosting, security, payment, analytics and other providers change over time.
A current technical inventory must be maintained through the Platform’s consent-management and audit process.
No cookie policy can prevent independent third parties, browsers, devices or networks from using their own technologies outside PhotoCrew’s control.
2. What is a cookie?
A cookie is a small text file or data record placed on or read from a browser, device or application. Cookies can contain identifiers, preferences, security information, session information or other data.
Cookies may be:
session cookies, which usually expire after the browser session;
persistent cookies, which remain for a defined period or until deleted;
first-party cookies, set in the PhotoCrew domain context;
third-party cookies, set or read by an external provider.
3. Similar technologies
This Policy also covers technologies that store information on or access information from a device, including:
browser local storage;
session storage;
pixels;
web beacons;
scripts and tags;
SDKs;
device identifiers;
advertising identifiers;
link decoration and navigational tracking;
embedded-content identifiers;
fingerprinting techniques where used;
cache identifiers;
login and security tokens;
consent identifiers;
server-side identifiers linked to device or browser activity.
References to “cookies” include these technologies where appropriate.
4. Legal framework
In the United Kingdom, relevant rules may include:
the Privacy and Electronic Communications Regulations;
the UK GDPR;
the Data Protection Act 2018;
the Data (Use and Access) Act 2025;
applicable ICO guidance.
The exact requirement depends on the technology, purpose, information accessed, privacy impact and legal exception.
Where PECR requires consent, consent must satisfy the applicable UK data-protection standard.
5. Our approach to consent
We may display options to accept all, reject non-essential technologies, manage categories, save selected choices and change choices later.
Continuing to browse is not treated as consent where positive consent is required.
Optional categories should not be intentionally activated before the required choice.
The consent tool may store a necessary record of the choice.
A User may need to choose again when cookies are deleted, a different browser or device is used, private browsing is used, the consent version changes or the technology or legal basis materially changes.
Withdrawal does not make earlier consented processing unlawful.
Some third-party technologies may require a page reload before a changed preference fully takes effect.
6. Legal exceptions
A technology may be used without consent where an applicable exception is satisfied, which may include:
transmission of a communication;
strictly necessary provision of a service requested by the User;
certain security, authentication or fraud-prevention uses;
consent-choice storage;
specified statistical purposes under current law;
specified functionality or appearance purposes under current law;
another exception introduced by law.
An exception is applied only where the purpose and conditions are met. A technology is not “strictly necessary” merely because it is useful, commercially beneficial or convenient.
Where a statistical or functionality exception is relied upon, PhotoCrew may provide information and an objection or opt-out mechanism where required.
7. Categories of technologies
The Platform may use the categories below. A category description does not mean every listed example is active at all times.
7.1 Strictly necessary
May support:
page delivery;
network routing;
load balancing;
login;
authentication;
session management;
password reset;
Account security;
CSRF and form protection;
fraud prevention;
anti-spam;
shopping basket or checkout;
subscription status;
payment authentication;
consent choice;
preference required for a requested service;
feature access;
server stability;
abuse prevention.
These cannot normally be disabled through the consent tool where essential to a requested service.
7.2 Functionality and preferences
May remember:
language;
display;
interface;
location preference;
saved filters;
dashboard choices;
accessibility preference;
recently used settings;
form progress;
embedded-content choice.
Some may be necessary, exempt under current law or optional depending on purpose.
7.3 Analytics and performance
May measure:
page views;
sessions;
clicks;
navigation;
device and browser;
approximate region;
referrals;
sign-up;
checkout;
errors;
page speed;
profile and listing interaction;
feature use;
conversion.
Analytics may rely on consent or a specific statutory exception, depending on implementation and legal conditions.
7.4 Security and fraud
May detect:
bots;
credential attacks;
spam;
scraping;
suspicious Account creation;
unusual payment or login activity;
fake reviews;
malicious traffic;
denial-of-service behaviour;
account takeover.
7.5 Payments and subscriptions
Payment or subscription providers may use technologies for:
checkout session;
card authentication;
fraud prevention;
risk scoring;
billing;
subscription management;
chargeback prevention;
regulatory compliance.
7.6 Embedded content
Video, map, social, portfolio or other embedded providers may use technologies when content is loaded or interacted with.
Potential providers may include, where activated:
YouTube;
Vimeo;
Google Maps;
Instagram;
Facebook;
LinkedIn;
X;
TikTok;
other media, map, review or portfolio platforms.
A provider is not necessarily active merely because it is mentioned here.
7.7 Advertising and marketing
Where introduced and consented to where required, technologies may support:
campaign measurement;
conversion tracking;
attribution;
audience creation;
frequency control;
retargeting;
personalised or non-personalised advertising;
referral analysis.
7.8 Personalisation and recommendations
May support:
relevant profiles;
recently viewed items;
saved searches;
recommended categories;
location-based results;
customised dashboard content.
8. Providers that may be involved
Depending on current configuration, the Platform may involve technologies supplied by categories such as:
WordPress and website-system components;
WooCommerce or subscription systems;
paid-membership systems;
hosting, caching, CDN and firewall services;
Stripe or another payment provider;
email-delivery and marketing providers;
consent-management providers;
security and anti-spam providers;
analytics providers;
map, video, social and embedded-content providers;
support, logging and error-monitoring providers.
The current Cookie Settings panel or cookie inventory should be used to identify technologies actually detected or configured at the latest audit.
9. Current cookie inventory
Because cookies can be added, renamed, removed or changed by software updates and third-party providers, the current technical inventory must be maintained through a cookie scanner, consent-management platform and periodic manual review.
The inventory should identify, where reasonably possible:
Field Information
Name or key Cookie, local-storage key, pixel or identifier
Provider PhotoCrew or third party
Purpose What it does
Category Necessary, preferences, analytics, marketing or other
Duration Session or stated period
Party First or third party
Legal treatment Consent, exception or other applicable basis
Operational requirement: the live Platform should display or link to the current inventory through its Cookie Settings or consent-management interface. This written Policy provides the legal framework but is not a substitute for maintaining the technical inventory.
A User may request information about the latest known inventory from hello@photocrew.co.uk.
10. Why the inventory changes
Technologies may change because of plugin updates, theme updates, WordPress updates, hosting changes, payment-provider changes, security changes, consent-tool changes, embedded content, new features, A/B tests, analytics changes, legal changes, provider renaming or browser changes.
We take reasonable steps to review material changes but cannot guarantee that a third party will notify us immediately or that every transient identifier will be detected instantly.
11. Future technologies and “may use” wording
PhotoCrew may introduce, replace or discontinue cookies, local storage, pixels, tags, SDKs and other technologies as the Platform develops.
Mention of a possible category or provider:
does not necessarily mean that it is currently active;
does not authorise use contrary to law;
does not replace any consent required at the time of activation;
does not prevent PhotoCrew from changing suppliers.
Where a newly introduced non-exempt technology requires consent, we will take reasonable steps to configure it so that it is not intentionally activated until the required consent is obtained.
12. Strictly necessary technologies
Necessary technologies may be used without optional consent where legally permitted.
Examples of functions include remembering that a User logged in, protecting a login session, maintaining a basket or checkout, preventing cross-site request forgery, securing payment, remembering a privacy choice, distributing network traffic, detecting abuse and enabling a form requested by the User.
If a browser blocks these technologies, the requested feature may fail.
13. Analytics
Analytics helps us understand and improve the Platform.
Analytics may be consent-based, configured under a statutory statistical exception where all conditions are satisfied, server-side, aggregated or provided by hosting or analytics suppliers.
Analytics may be incomplete because of rejection, opt-out, privacy tools, VPNs, ad blockers, bots, caching, technical errors or device restrictions.
PhotoCrew analytics does not guarantee exact unique-person counts, commercial exposure, enquiries, bookings, ranking, conversion or return on investment.
Paid Users must not treat analytics as audited business accounts or guaranteed performance data.
14. Advertising and attribution
Advertising technology may be introduced only where appropriate.
We do not guarantee ad delivery, targeting, attribution, conversion counts, audience quality, campaign performance or third-party availability.
Browser restrictions and consent choices may reduce measurement.
PhotoCrew is not responsible for an advertising provider’s independent processing except where law makes us responsible.
Users may still see non-personalised advertising after rejecting personalised advertising.
15. Embedded content
Embedded content may transmit IP address, browser, device, page URL or interaction data to the provider.
Optional embeds may be blocked until consent or activation.
Clicking an external link takes the User to another service.
External providers control their own technologies.
PhotoCrew does not guarantee the privacy, accessibility, security or availability of external content.
Users should review the provider’s policies.
16. Payment technologies
Secure payment may require technologies controlled by payment providers.
Blocking them may prevent payment.
Providers may perform authentication, fraud prevention and risk analysis.
PhotoCrew does not control every payment-provider identifier, retention period or decision.
Full payment-card details are normally handled by the provider rather than PhotoCrew.
A declined payment, hold, challenge or outage may occur independently of PhotoCrew.
17. Security, bots, scraping and abuse prevention
Technologies may be used to detect or prevent bots, spam, fake Accounts, automated applications, credential stuffing, scraping, data harvesting, malicious links, fake reviews, payment fraud, denial-of-service attacks and repeated policy breaches.
Security technologies may be necessary or may rely on another lawful exception or basis.
Security controls can make mistakes. We may require additional verification, delay an action or restrict access where risk is detected.
18. Consent records
We may record:
consent or objection status;
categories selected;
date and time;
policy or consent version;
device or browser identifier;
IP address or truncated IP where appropriate;
region;
technical logs.
Consent records may be retained for a reasonable compliance period.
19. Managing preferences
A User may manage technologies through:
the PhotoCrew consent banner;
Cookie Settings;
browser settings;
device settings;
privacy extensions;
provider opt-out tools.
Browser controls may allow blocking, warning, deletion or restriction.
Clearing cookies may remove the stored choice and require a new selection.
20. Consequences of blocking or deleting technologies
Blocking, rejecting or deleting technologies may log the User out; prevent authentication; break forms; stop checkout; prevent payment verification; lose saved settings; reset filters; disable embedded videos or maps; cause repeated consent prompts; prevent security checks; reduce analytics; limit Paid Features; or cause unexpected interface behaviour.
To the fullest extent permitted by law, PhotoCrew is not responsible for loss or reduced functionality caused solely by the User’s browser, device, extension, network, privacy tool or voluntary cookie choice. This does not exclude responsibility for PhotoCrew’s own breach of mandatory law or failure to supply a paid service with legally required care and skill.
21. Shared, workplace and managed devices
Choices may apply to a browser or device rather than a specific person.
Another person may change the choice.
Employers, schools, libraries, network administrators and device owners may monitor or restrict activity.
PhotoCrew does not control third-party device or network policies.
Users should not assume privacy on a shared or managed device.
22. Do Not Track and preference signals
Browsers may send Do Not Track, Global Privacy Control or similar signals.
Standards and legal requirements differ.
Where legally required and technically supported, we may recognise an applicable signal.
Users should also use Cookie Settings because not every provider recognises every signal.
We do not guarantee that an independent third party will respond to a browser signal.
23. Children
The Platform is intended for persons aged 18 or over.
We do not knowingly use cookies to target children.
If an under-18 Account is identified, we may restrict or delete it subject to law.
Portfolio content may depict children, but that does not mean the child is a Platform User.
24. International processing
Cookie providers may process identifiers outside the UK. Transfers are handled as described in the Privacy Policy. Users should review third-party provider notices where relevant.
25. Liability and third-party changes
Third parties may change technology, names, domains, purposes or retention without immediate notice.
We take reasonable steps to keep information accurate.
We do not guarantee that every temporary, provider-generated or rapidly changing identifier is described instantly.
Nothing excludes liability or obligations that cannot lawfully be excluded.
PhotoCrew is not responsible for independent tracking by websites or services not controlled by PhotoCrew.
26. Audits and governance
PhotoCrew should:
run automated cookie scans periodically;
test public and logged-in pages;
test registration, dashboards and checkout;
test before consent, after rejection and after acceptance;
review network requests and browser storage;
review new plugins and integrations;
update classifications;
record consent-tool changes;
maintain a current inventory;
keep a permanent Cookie Settings link available.
These are operational controls supporting this Policy.
27. Changes to this Policy
We may update this Policy to reflect technologies, providers, laws, Platform changes or audit findings. The effective date and version will be updated. Material changes may be highlighted through the Platform or consent tool.
28. Scope, interpretation and relationship with other documents
This Policy applies to the Platform whether accessed through a desktop browser, mobile browser, tablet, webview, embedded interface, account dashboard, checkout flow, authentication flow, email link, social preview, application link or another supported access method.
It applies whether a person is logged in or logged out and whether the person holds a Visitor, Creator, Studio, administrator, support, test or other Account.
It covers storage or access on terminal equipment and related processing of identifiers or personal data.
The Privacy Policy explains how personal data associated with these technologies may be processed.
The Terms and Conditions allocate contractual risk and responsibility for use of the Platform.
If a specific point-of-collection notice, consent panel or provider notice gives more specific information about a particular technology, that more specific information applies to that technology together with this Policy.
This Policy does not govern independent websites merely because PhotoCrew links to them.
Headings, examples and summaries assist navigation but do not narrow the broader wording of a section.
References to a technology being “necessary”, “optional”, “exempt”, “consent-based” or “first-party” describe its intended classification. The legal classification depends on actual purpose and implementation.
Nothing in this Policy authorises any technology to be used in a way prohibited by law.
29. Detailed definitions
For this Policy:
Consent Tool means any banner, preference centre, plugin, interface or system used to present information, collect choices, store choices or block technologies.
Cookie Settings means the control made available by PhotoCrew to review or change optional choices where technically supported.
Device means a computer, phone, tablet, smart device or other terminal equipment.
Identifier means a cookie value, local-storage value, token, device value, account value, pixel value, URL parameter, session value or comparable reference.
Provider means PhotoCrew or a third party supplying technology or functionality.
Storage and Access Technology means any technology that stores information on or accesses information from a Device.
Strictly Necessary means essential from the User’s perspective to transmit a communication, provide a requested online service, protect that service where no reasonable proportionate alternative exists or otherwise satisfy a narrow legal exception.
User Choice means an acceptance, rejection, category selection, objection or withdrawal made through a Consent Tool or another recognised method.
30. The difference between PECR consent and UK GDPR lawful basis
PECR rules about storing or accessing information on a Device are separate from the UK GDPR rules governing later processing of personal data.
A technology may require consent under PECR even where PhotoCrew believes it has a legitimate interest in the broader processing purpose.
PhotoCrew will not intentionally use legitimate interests as a substitute for PECR consent where PECR requires consent.
If information is obtained using consent-required technology, later processing must remain fair, transparent and consistent with the basis on which the information was obtained.
A consent choice does not create consent to unrelated processing.
Rejecting optional technologies does not prevent processing that is independently necessary for a contract, security, legal obligations or another valid basis, provided that the Device storage or access itself is also lawful.
The same Identifier may support more than one purpose. Each purpose must be assessed separately.
Where one purpose requires consent, PhotoCrew may need to block the technology entirely unless purposes can be technically separated.
31. Communication exception
PhotoCrew may use technology without consent where its sole purpose is transmission of a communication over an electronic communications network and the transmission cannot reasonably occur without it.
Examples may include load-balancing identifiers, routing information, sequence information and transmission-error detection.
The exception does not cover analytics, advertising, convenience or commercial optimisation merely because those activities happen during transmission.
If a technology has an additional non-exempt purpose, the communication exception may not cover that additional purpose.
32. Strictly necessary exception
PhotoCrew may use technology without optional consent where it is technically essential to supply a service expressly requested by the User.
This may include authentication, session continuity, checkout, payment security, form security, fraud prevention, consent storage and access-control enforcement.
Necessity is assessed from the User’s perspective, not solely from PhotoCrew’s preference or commercial benefit.
A tool is not strictly necessary merely because it improves conversion, advertising, analytics, convenience or revenue.
Security technology may be treated as necessary where it is a reasonable and proportionate way to protect Accounts, personal data, transactions or the Platform and there is no reasonable less-intrusive alternative.
PhotoCrew may restrict or refuse a requested service if essential security or authentication technology is blocked.
33. Statistical purposes exception
Current UK law may permit certain storage or access without consent where the sole purpose is collecting statistical information about use of the service with a view to improving it.
PhotoCrew will rely on this exception only where the specific legal conditions are reasonably considered satisfied.
Information must be clear and comprehensive.
A simple, free means of objecting must be made available.
Statistical information obtained under this exception must not be used for unrelated advertising, cross-site tracking or individual targeting.
Where a provider combines statistical information with other information for independent purposes, consent may still be required.
PhotoCrew may choose to obtain consent even where an exception might be available.
An analytics provider or plugin describing itself as “privacy-friendly” does not automatically satisfy the exception.
34. Appearance and functionality preference exception
Current UK law may permit certain technology without consent where its sole purpose is adapting appearance or functionality in accordance with the User’s preference.
Examples may include remembering an interface setting, language, accessibility preference, display density, layout or other expressly selected preference.
PhotoCrew will provide clear information and a simple means of objecting where required.
This exception does not automatically cover profiling, advertising, cross-service personalisation or behavioural recommendations.
A preference technology may become necessary where a User expressly requests that the setting be remembered as part of the service.
35. Emergency assistance exception
Current UK law contains a narrow exception for identifying the geographical position of a Device where the sole purpose is to provide emergency assistance requested by the subscriber or User.
PhotoCrew does not ordinarily provide emergency-location services.
Mention of this exception does not mean PhotoCrew currently accesses precise Device location for emergency assistance.
Users should contact emergency services directly in an emergency and must not rely on PhotoCrew as an emergency service.
36. Simple means of objecting
Where PhotoCrew relies on a statistical-purpose or appearance exception requiring an objection mechanism:
the objection method should be free;
it should not require unnecessary Account creation;
it should be reasonably easy to locate and use;
the objection should take effect as soon as reasonably practicable;
PhotoCrew may store a necessary Identifier to remember the objection;
the objection may need to be repeated on another browser, Device or profile;
clearing browser storage may remove the objection record;
the objection does not prevent unrelated necessary technologies.
37. Default state and pre-enablement
Non-exempt optional technologies should not be intentionally pre-enabled before the required consent.
Optional category toggles should default to off where consent is required.
Strictly necessary technologies may remain active.
A third-party script loaded before consent may itself access Device information even if a later event is disabled. PhotoCrew therefore aims to block the script, not merely suppress a later event, where consent is required.
Cached pages, delayed scripts, plugin conflicts or provider changes can create unexpected behaviour. Such issues should be investigated when identified.
No statement in this Policy guarantees that a technical defect can never occur.
38. Consent-banner design
The Consent Tool may display Accept, Reject and Manage options.
Rejecting non-essential technologies should not be intentionally made materially harder than accepting them.
Wording should be understandable and should avoid falsely implying that optional consent is mandatory.
The banner may use layered information so that essential information is displayed first and detailed information is available in the preference centre.
The banner may vary according to region, Device, browser or applicable law.
A banner cannot itself guarantee legal compliance if scripts are technically misclassified or loaded incorrectly.
PhotoCrew may change banner design to reflect law, ICO guidance, usability, accessibility, technology or testing.
39. Consent evidence and audit trail
PhotoCrew may retain evidence including:
consent or objection status;
category choices;
date and time;
policy and banner version;
browser or Device Identifier;
approximate region;
technical delivery records;
script-blocking status;
proof of withdrawal;
records of banner configuration.
The evidence is intended to demonstrate and manage choices. It does not prove that every external provider behaved exactly as configured.
40. Withdrawal, alteration and expiry of choices
Consent may be withdrawn as easily as reasonably possible through Cookie Settings.
Withdrawal applies prospectively and does not make earlier lawful processing unlawful.
A provider may receive information before withdrawal takes effect.
Existing third-party profiles or data already created may be retained by the provider under its own lawful basis and retention rules.
PhotoCrew cannot directly erase information held by an independent controller merely by changing a local cookie setting.
Users may need to contact the relevant provider.
PhotoCrew may ask for consent again after a material purpose, provider, retention or technology change.
Consent may also be refreshed after a reasonable period or where required by guidance.
41. Multiple purposes and linked technologies
A single technology may support authentication, analytics, security, personalisation and advertising.
Each purpose must be considered separately.
PhotoCrew may disable all functions of a mixed-purpose technology unless purposes can be separated lawfully.
A Provider’s own documentation may be incomplete, outdated or subject to change.
PhotoCrew may classify conservatively where the purpose is uncertain.
Classification may change following an audit, provider clarification or legal guidance.
42. Server-side logs and technologies outside the browser
Web servers, hosting providers, firewalls, CDNs, payment providers and security systems may generate logs independently of browser cookies.
Logs may record IP address, timestamp, request path, response code, user agent, security event and network information.
PECR storage-and-access rules may apply differently depending on whether information is stored on or accessed from the User’s Device.
UK GDPR may still apply to personal data in logs.
Logs may be necessary for security, troubleshooting, legal compliance and fraud prevention.
The Cookie Settings tool may not control every server-side log.
The Privacy Policy explains broader processing and retention.
43. WordPress, themes, plugins and core functionality
PhotoCrew is built using WordPress and related components.
WordPress, the active theme and plugins may create session, authentication, preference, security, form, commerce, media or technical Identifiers.
A plugin may introduce a new technology after installation or update.
A dormant or disabled feature may still load code if incorrectly configured.
PhotoCrew may not receive advance notice of every provider change.
PhotoCrew will take reasonable steps to review material additions when they become known.
Users acknowledge that an online platform involving accounts, dashboards, messaging and checkout cannot generally operate without some necessary storage or access.
44. Accounts, authentication and sessions
Technologies may support:
login and logout;
password reset;
session continuity;
Account-role recognition;
plan eligibility;
dashboard access;
CSRF protection;
suspicious-login detection;
repeated failed-login limits;
impersonation protection;
remember-me functionality where selected;
administrative security.
Blocking such technologies may prevent Account use. PhotoCrew is not required to provide an insecure alternative.
45. Forms, CAPTCHA, anti-spam and abuse prevention
Forms may use tokens, nonces, hidden fields, rate limits, CAPTCHA, behavioural signals or third-party anti-spam systems.
These systems may inspect Device, browser, network and interaction information.
They may incorrectly classify a genuine User as suspicious.
PhotoCrew may require a retry, alternative verification or manual support.
PhotoCrew does not guarantee that every spam message, bot or malicious submission will be blocked.
Disabling required form-security technology may prevent submission.
Third-party anti-spam providers may act as independent controllers for some processing.
46. Memberships, commerce, subscriptions and entitlements
Technologies used by commerce or membership systems may support:
cart or checkout state;
product selection;
subscription status;
plan renewal;
access to Paid Features;
order tracking;
tax or currency presentation;
discount or promotion eligibility;
fraud and duplicate-purchase prevention;
cancellation and refund workflows.
A rejected or deleted necessary Identifier may cause an incomplete purchase, duplicate step, lost selection, failed access or inaccurate display. Mandatory consumer rights remain unaffected.
47. Stripe and payment-provider technologies
Stripe or another payment provider may set or access technology for secure payment, authentication, fraud prevention, regulatory checks and payment-session continuity.
Some technology may be loaded directly from the provider’s domain.
PhotoCrew does not control every provider Identifier, duration, risk model or decision.
Payment providers may process data as independent controllers.
Blocking payment technology may make checkout impossible.
PhotoCrew is not responsible for a provider’s independent refusal, authentication challenge, risk assessment, outage or retention policy except to the extent PhotoCrew is legally responsible.
Users should consult the provider’s own privacy and cookie information displayed during checkout.
48. Email, newsletter and communication technologies
Email providers may use tracking pixels or link decoration to measure delivery, opens, clicks, device or campaign interaction where legally permitted.
Service emails may contain security or delivery identifiers necessary to provide the requested communication.
Marketing measurement may require consent or another lawful basis depending on the technology and circumstances.
Blocking images can prevent an open pixel from loading.
Link redirection may still occur where required for security or unsubscribe management.
Email clients and network providers may independently process communication metadata.
PhotoCrew does not guarantee the accuracy of open or click metrics.
49. Hosting, CDN, caching and security providers
Hosting and delivery providers may use network, session, firewall, bot-management, load-balancing, cache or security technologies.
Some may be necessary for availability and protection.
CDN location and routing can result in processing in multiple territories.
A cache may temporarily serve an older banner or policy version.
PhotoCrew may purge caches but cannot guarantee immediate propagation to every network node.
Security providers may block access, challenge a browser or request verification.
50. Video, maps, social media and other embedded content
An embed may transmit technical information before the User actively plays or interacts with it unless it is blocked behind consent.
PhotoCrew may use a placeholder requiring activation.
Activating content may constitute a request to load the provider’s service.
Providers may set their own cookies, create profiles, measure interactions or combine information with an existing Account.
PhotoCrew cannot control an independent provider after content is loaded.
Rejecting embed-related technology may leave a placeholder or external link instead of the embedded content.
User-supplied external links are controlled by the linked provider, not PhotoCrew.
51. Analytics configurations
Analytics may be configured using one or more of the following:
consent-based browser analytics;
exempt statistical analytics where all legal conditions are met;
server-side aggregate analytics;
hosting analytics;
security or operational logs;
conversion events;
consent-mode signals;
anonymisation or truncation controls;
retention limits;
internal platform analytics.
Different methods have different accuracy and privacy characteristics. PhotoCrew does not warrant that a provider’s “anonymised”, “cookieless” or “privacy mode” label guarantees that no personal data is processed.
52. Advertising, retargeting and audience technology
PhotoCrew may introduce advertising, conversion or audience tools in the future.
Such introduction is not authorised merely because this Policy mentions it.
Consent will be obtained where required.
Users may see non-personalised advertising after rejecting personalised advertising.
An advertising provider may maintain data already collected before withdrawal under its own lawful rules.
PhotoCrew does not guarantee targeting, attribution, audience size, conversion, revenue or compliance by an independent provider beyond PhotoCrew’s legal responsibility.
PhotoCrew may discontinue advertising technology without notice.
53. A/B testing, experiments and feature rollouts
PhotoCrew may test layouts, functionality, wording, search presentation or onboarding flows.
A test may require an Identifier to keep a User in a consistent variation.
The legal classification depends on whether the test is necessary, statistical, preference-based or optional.
Optional testing technology will be consented to where required.
Tests may produce different experiences for different Users.
PhotoCrew does not guarantee permanent access to a test variation.
54. Referral, affiliate and campaign parameters
Links may contain referral, campaign, source or attribution parameters.
Parameters may be stored temporarily to associate a visit or purchase with a campaign.
Some attribution is optional and may require consent.
Fraud-prevention records may be retained where necessary.
PhotoCrew does not guarantee that attribution is accurate or that a referral payment is due unless expressly agreed in writing.
55. AI, automated systems and model providers
Storage and access technology may support bot detection, content classification, support tools, moderation, recommendations or AI-assisted functions.
Mention of AI does not mean all Platform data is used to train a model.
PhotoCrew prohibits unauthorised third-party AI training on Platform content.
Public content may nevertheless be unlawfully collected by others.
An external AI provider may process technical or submitted information under separate terms.
Optional AI functionality may require a separate notice or consent depending on implementation.
56. Browser fingerprinting
Fingerprinting may infer a Device or browser from multiple technical characteristics.
It can be privacy-intrusive and may require consent unless a narrow exception applies.
PhotoCrew does not claim that fingerprinting is currently used merely because it is described in this Policy.
Security providers may use device or browser characteristics for risk detection.
PhotoCrew will assess actual purpose, proportionality and legal requirements when such technology is identified.
57. Link decoration and navigational tracking
Providers may add Identifiers to URLs to measure campaigns, maintain state, authenticate a flow or connect activity across domains.
URL Identifiers may be copied, shared, logged or exposed in referrer information.
Users should avoid publishing private or security-sensitive links.
PhotoCrew may remove or shorten certain parameters but cannot guarantee that all external providers do so.
A link Identifier may be necessary for password reset, email verification or payment return flows.
58. Mobile browsers, webviews and future applications
Mobile browsers and in-app webviews may handle cookies differently from desktop browsers.
Operating systems may reset, restrict or partition storage.
A future PhotoCrew application may use SDKs, app storage, push tokens or device permissions.
Additional notices and controls may be supplied if such an application is introduced.
This Policy applies to comparable technologies to the extent appropriate.
59. Browser privacy controls and blocking tools
Browsers, extensions, DNS filters, VPNs, firewalls, antivirus products and network administrators may alter requests.
They may block necessary and optional technology without distinction.
They may inject their own code or headers.
They may report misleading results to testing tools.
PhotoCrew cannot guarantee compatibility with every privacy tool.
A User who chooses aggressive blocking accepts the foreseeable risk of reduced functionality, subject to mandatory rights.
60. Shared, public, workplace and family Devices
A stored choice may apply to every person using the same browser profile.
PhotoCrew cannot determine who made a device-level choice.
Employers, schools, libraries, internet providers or household administrators may impose controls.
Users must not assume that a shared Device is private.
Account Users should log out and avoid saving credentials on shared Devices.
PhotoCrew is not responsible for another authorised or unauthorised Device user changing or viewing local settings except to the extent caused by PhotoCrew’s unlawful conduct.
61. Users outside the United Kingdom
PhotoCrew is primarily directed to the United Kingdom.
A visitor from another country may be subject to local laws.
The Consent Tool may display a regional configuration.
PhotoCrew does not warrant that one configuration satisfies every law worldwide.
Users outside the UK are responsible for deciding whether they may lawfully use the Platform.
PhotoCrew may restrict access by region.
62. Responsibility for third-party technologies
PhotoCrew remains responsible for selecting and configuring third-party technology to the extent required by law.
This does not make PhotoCrew responsible for every independent act of a provider beyond PhotoCrew’s control.
Providers may act as processors, joint controllers or independent controllers depending on the activity.
PhotoCrew may rely on provider documentation, contracts and settings, but cannot guarantee that every representation remains accurate.
PhotoCrew may replace a provider where appropriate but does not guarantee uninterrupted replacement.
63. Accuracy, completeness and rapid technical change
Cookie names, durations and purposes can change without visible Platform changes.
Some Identifiers are generated dynamically.
Some exist only for seconds, during an error or for selected Users.
Automated scanners can miss authenticated, geographic, conditional, payment or interaction-triggered technology.
Manual testing can also miss intermittent behaviour.
The inventory is therefore maintained on a reasonable-efforts basis and should not be read as a warranty that no transient technology exists.
This limitation does not remove PhotoCrew’s legal obligation to provide clear information and maintain appropriate governance.
64. User responsibility and risk allocation
Users are responsible for:
reviewing this Policy and available settings;
making choices appropriate to their circumstances;
maintaining browser and Device security;
clearing storage on shared Devices;
understanding that blocking may prevent requested functions;
reviewing third-party notices before activating external content;
not relying on analytics as guaranteed commercial evidence;
reporting suspected unexpected tracking with sufficient technical detail.
Public content, search-engine indexing and external copies are not controlled solely by cookie choices.
65. No guarantee of absolute tracking prevention or anonymity
PhotoCrew does not represent or warrant that:
rejection makes a User anonymous;
every network request is invisible to hosting or internet providers;
a browser will honour every setting correctly;
third parties will comply with their obligations;
no external copy, cache or log will exist;
private browsing prevents all tracking;
a VPN prevents identification;
deleting cookies deletes provider-held data;
consent tools can control technology on websites not operated by PhotoCrew;
no technical defect will ever occur.
66. Liability and mandatory legal protections
To the fullest extent permitted by law, PhotoCrew is not liable for loss caused solely by a User’s voluntary blocking, deletion or rejection of technology necessary to provide a requested service.
PhotoCrew is not liable for independent third-party tracking, browser behaviour, external websites, network-provider activity or provider changes outside PhotoCrew’s reasonable control, except to the extent law makes PhotoCrew responsible.
PhotoCrew does not exclude responsibility for its own failure to comply with mandatory PECR, UK GDPR, consumer or other legal duties.
Nothing in this Policy limits a right or remedy that cannot lawfully be excluded.
The limitation provisions in the Terms and Conditions also apply where relevant.
This Policy is an information document and does not require a User to waive statutory privacy rights.
67. Operator and address for service
PhotoCrew.co.uk is operated by Mr. Martin J., a sole trader trading as PhotoCrew.co.uk.
Address for business correspondence and service of legal documents: 44 Chesterton House, Ingrave Street, London, SW11 2UD, United Kingdom.
Email: hello@photocrew.co.uk
The address above is provided for business correspondence and service of legal documents only. It is not a public office, retail premises, meeting location, collection point, delivery point or location at which in-person customer support is offered. No User or other person is authorised to attend without a prior written appointment expressly confirmed by PhotoCrew. Unsolicited visits, personal approaches, harassment, intimidation, surveillance, photography, filming, publication of unrelated personal information, doxxing, unwanted deliveries and use of the address for unrelated marketing are prohibited to the fullest extent permitted by law.
68. Changes to technologies and this Policy
PhotoCrew may add, remove, replace or reconfigure technologies.
We may update this Policy, Cookie Settings, inventory, categories and banner wording.
A material new consent-required purpose will not be intentionally activated merely by updating this Policy; the required choice will be presented.
Minor technical changes may be reflected in the inventory without a prominent notice.
The effective date and version may be updated.
Users should revisit Cookie Settings periodically.
69. Contact
Cookie, consent, technology and privacy enquiries may be sent to:
hello@photocrew.co.uk
Schedule 1 — Cookie and technology inventory framework
The live Cookie Settings interface should identify known active technologies. The following table describes the fields that should be maintained:
Field Required information
Name/key Exact cookie, local-storage, session-storage, pixel, script or Identifier name
Provider PhotoCrew or named third party
Domain Domain or service that sets or reads it
Purpose Clear explanation of what it does
Category Necessary, preference, analytics, advertising, embedded content or other
Duration Session, event-based or stated maximum period
Party First-party or third-party
Trigger Page load, login, checkout, consent, video play or other event
Legal treatment Consent or identified exception
Objection/control Cookie Settings, provider setting, browser setting or other method
The actual live inventory cannot be safely determined from legal wording alone. It must be produced from technical scanning and manual testing.
Schedule 2 — Illustrative technologies that may be detected
The following are examples only and must not be treated as confirmation that each is active:
WordPress login and test cookies;
security nonces and anti-CSRF tokens;
WooCommerce or membership-session values;
consent preference values;
Stripe security and fraud-prevention values;
CDN and firewall identifiers;
anti-spam and CAPTCHA values;
embedded-video provider values;
map-provider values;
analytics identifiers;
email campaign link identifiers;
saved-search or interface preference values.
Only the live technical audit determines the current inventory.
Schedule 3 — Minimum cookie-audit procedure
A meaningful audit should test at least:
a clean browser before any choice;
Reject non-essential;
Accept all;
each optional category independently;
logged-out homepage and search;
registration and email verification;
login and password reset;
Creator dashboard;
Studio dashboard;
profile editing;
public profile pages;
messages and contact forms;
review submission;
gig and job forms;
application flows;
videos, maps and social embeds;
Pricing and checkout;
subscription management;
cancellation and refund pages;
mobile and desktop browsers;
private browsing;
different User roles;
Network requests, Cookies, Local Storage and Session Storage;
retesting after major plugin, theme, hosting or payment changes.
Schedule 4 — Recommended banner wording
Primary text
PhotoCrew uses cookies and similar technologies to operate and secure the Platform, remember requested settings, process login and payments and, with your permission or where a legal exception applies, measure and improve the service. You can accept optional technologies, reject them or manage your choices. Rejecting optional technologies will not block strictly necessary technology, but blocking necessary technology in your browser may prevent requested functions.
Buttons
Accept optional technologies
Reject optional technologies
Manage choices
Permanent control
A Cookie Settings link should remain available in the footer or equivalent persistent location.
Schedule 5 — Suggested preference categories
Strictly necessary — always active where required
Supports network delivery, login, security, forms, consent records, checkout, payment protection, subscriptions, fraud prevention and requested Account functionality.
Preferences and appearance
Remembers choices such as language, display, layout, saved filters or accessibility preferences. Some may be exempt; others may be optional.
Analytics and performance
Measures use and technical performance. It may be consent-based or use a narrow statistical exception where all conditions are met and an objection method is available.
Embedded content and social media
Loads video, maps, portfolio or social services that may receive technical and interaction information.
Advertising and marketing
Supports campaign measurement, attribution, audiences, retargeting or personalised advertising. It is optional where consent is required.
Schedule 6 — Technical incident reporting template
A report of unexpected technology should include:
exact URL;
date and time;
whether the User was logged in;
consent choice selected;
browser and version;
Device and operating system;
cookie or storage name;
provider domain;
screenshot;
relevant Network request;
steps to reproduce;
whether extensions, VPN, proxy or privacy tools were active.
Incomplete reports may be difficult to reproduce, but PhotoCrew may still investigate proportionately.
Schedule 7 — Maximum protection statement
To the fullest extent permitted by law, Users acknowledge that modern online services depend on multiple technical layers; that not every technology is controlled directly by PhotoCrew; that blocking technology may prevent requested functionality; that optional choices do not control public indexing or third-party copies; that analytics and attribution are estimates; that technology changes rapidly; and that no banner, scanner, browser, extension, policy or privacy tool can guarantee absolute anonymity, complete technical detection or elimination of every external record.
This acknowledgement does not waive statutory rights or excuse PhotoCrew from duties that cannot lawfully be excluded.