Legal
Cookie notice
An inventory rather than a policy. Two entries exist, both set by the hosting provider, both strictly necessary, and one request leaves the page for a font host. Everything else on this page is a statement about what is absent, written so that it can be checked with the developer tools rather than believed.
In force 10 August 2026Revision 1.0Privacy Act 1988 (Cth)
01Position, as a field block
Scope: every storage and network fact about this site, compressed into one block. The sections after it are the working.
- Cookies from our code
- None
- Cookies from the host
- Two, strictly necessary, itemised at 02
- Analytics
- None installed, of any vendor
- Advertising and pixels
- None
- Local storage, session storage, IndexedDB
- Nothing written by anything we ship
- Fingerprinting
- Not attempted, and no returning-visitor recognition of any kind
- Consent banner
- None, for the reason at 04
- Outbound requests
- One, to a font host, disclosed at 06
- Forms
- None on any page, so nothing is posted anywhere
02Storage inventory
Scope: the complete list of what can end up on your device from a visit here.
| Name | Written by | Function | Lifetime | Consent |
|---|---|---|---|---|
| __cf_bm | Cloudflare, the host | Distinguishes a human request from an automated one, so abuse can be dropped. Strictly necessary | 30 minutes, extended while you keep clicking | Not required |
| cf_clearance | Cloudflare, the host | Written only after a challenge has been shown and passed, so one visitor is not put through two | 30 days at the outside | Not required |
The list ends there. Neither value reads back to us as an identifier for a person, neither feeds a measurement, and neither was asked for by us: they are part of how the host keeps automated abuse off an origin.
03What Australian law actually asks for
Scope: the legal basis for a page like this one, which is frequently assumed to be European and is not.
This country runs no separate cookie consent regime. No local instrument matches the ePrivacy Directive in Europe, and no statute here makes a banner the precondition of writing storage. On an Australian site the banner is a design decision, usually a copied one.
What does apply is the Privacy Act 1988 (Cth). Should a cookie or a comparable mechanism gather information about a reasonably identifiable person, that counts as personal information. The Australian Privacy Principles then attach: APP 3 for the collecting, APP 5 for the telling, APP 6 for whatever follows.
The two entries at 02 are assessed against that test each time this page is reviewed. Neither is used to build a record about a person, which is why neither is treated as requiring consent, and the assessment would change if their function did.
04Why nothing here asks permission
Scope: the absent banner, and the second reason for its absence.
Permission is the thing a banner collects, for storage reaching past strictly necessary. None of that runs here, so the dialog would be seeking approval of an empty list, and the click would move nothing.
The second reason happens to be this company's subject. A consent management platform is one of the most expensive things a marketing site loads: a blocking script, a reflow when it paints, and another round trip before the page can be read. On a slow connection and an old handset it is routinely the heaviest item on the page, and it would be there to ask about storage this site does not use. Shipping one would be hard to defend on a site that argues about frame time for a living.
Add analytics or advertising later and permission gets asked before a byte of it loads, refusing stays exactly as easy as accepting, and this page changes before the code ships rather than after.
05Deliberately absent, and checkable
Scope: the negative inventory. Each line is verifiable from your own browser in under a minute.
- No Google Analytics. No Plausible, Fathom or Matomo. No measurement product under any other name.
- No advertising of any kind, and no advertising cookie.
- No conversion tracking, and no pixel or insight tag from Meta, LinkedIn or TikTok.
- No session replay, heatmap or scroll depth instrumentation.
- No embedded video player, map, comment system or social widget.
- No tag manager, and no third party script at all, which is what makes the rest of this list easy to keep true.
- No A/B testing framework, and no personalisation of the page for anyone.
The check: developer tools open, Application panel for storage, Network panel for requests, then a reload. What is described above is what you will find, and a discrepancy is worth an email.
06The one outbound request
Scope: the single third party this page contacts.
- Hosts contacted
- fonts.googleapis.com for the stylesheet, then fonts.gstatic.com for the files themselves
- What they receive
- An IP address, a user agent string, and the referring page
- Cookies set
- None. Google states the Fonts service sets no cookie and does not use these requests for advertising or profiling
- Blockable
- Yes. Block both hosts and the site renders in a system font with nothing else lost
- On the removal list
- Self hosting the two files, which removes the request entirely
Two typefaces are fetched that way, and it is the only network cost on this site that goes anywhere other than our own origin. Describing it plainly is better than leaving it for somebody to find in a waterfall, and it stays on the removal list until it is gone.
07What a page here costs to load
Scope: page weight. Not a cookie question, but the same argument, so it belongs somewhere public.
- Markup
- Static HTML, written by hand, served as a file
- Stylesheet
- One, shared across every page
- Script
- One, small, deferred, and it fails open
- What the script does
- Opens the navigation on a narrow screen, and reveals sections as they scroll into view
- Framework, bundle, hydration
- None of the three
- Images
- WebP, sized in the markup so nothing shifts as they arrive
Nothing on the page depends on the script running. Turn scripting off and the content is all still there, which is the property most sites lose first when the tag list grows.
08Server logs are not device storage
Scope: the record a request leaves behind at the other end of the connection.
Every web server keeps a record of what it was asked for. Ours holds an IP address, a path, a response status, a user agent and a timestamp. Nothing of that reaches your device, which keeps it outside the definition of a cookie. It remains personal information, and an inventory omitting it would be dishonest.
Those entries stay with the host, ageing out on its own rotation, currently under 30 days. They serve two purposes: delivering the file, and defending the origin against abuse. The same record appears in the privacy policy at 06, with its retention clock.
09Clearing storage from your side
Scope: doing this yourself, without asking us for anything.
Storage can be blocked, cleared and inspected from any current browser. Block the two entries at 02 and the host may put a challenge in front of you more often; the pages carry on working.
- Chrome: open Settings, go to Privacy and security, then the controls covering site data and third-party cookies.
- Safari, under Settings, in Privacy, at Manage Website Data.
- Firefox, under Settings, in Privacy and Security, at Cookies and Site Data.
- Edge, under Settings, at Cookies and site permissions.
Private browsing discards both entries when the window closes, which is a simpler route to the same result.
10Opt-out signals
Scope: the browser signals that tell a site to stop, and what they change here.
Global Privacy Control and Do Not Track are both honoured, an easy promise when nothing here is waiting to be switched off. With either header present, no further storage is written and no further processing runs, which is equally true with neither.
A Global Privacy Control signal is also treated as a valid opt out of any sale or sharing of personal information, as the privacy policy records at 31, in case a reader is somewhere that gives that signal legal weight.
11Telemetry in a title is a separate mechanism
Scope: keeping two different things apart, since they are often confused.
Cookies are a browser mechanism and stop at the edge of this website. A mobile title does not use them; what it writes is performance telemetry, with its own field list, its own retention clocks and its own switch inside the title's settings.
The short version: frame timing, thermal and power telemetry can be turned off in a title's settings and play is unaffected. The long version, field by field, is at 05 of the privacy policy.
12Questions, corrections, complaints
Scope: what to do with a question about this page, or with evidence that it is wrong.
- Address
- engineering@iopex.co.im
- Question about this page
- 5 business days
- Privacy request
- 30 days, per the privacy policy
- Evidence this page is inaccurate
- Treated as a defect report, and the page is corrected rather than argued about
Where our answer settles nothing, the Office of the Australian Information Commissioner takes it next: GPO Box 5218, Sydney NSW 2001, on 1300 363 992, or at oaic.gov.au. Nothing is charged for that, and our agreement forms no part of it.
- Entity
- IOPEX TECHNOLOGIES PTY LTD, ACN 696 561 609, ABN 54 696 561 609
- Related documents
- Privacy policy and terms of use