Cookie Policy

Pixel Mill · Cookie Policy · v1.0 · Effective 21 July 2026

FieldValue
OperatorMANAGEMENT RESILIENCE LTD
Company number15587224
Registered office20 Wenlock Road, London, England, N1 7GU
Trading name / brandPixel Mill
Websitehttps://pixel-mill.com
Contact emailinfo@pixel-mill.com
Support / complaintsinfo@pixel-mill.com; written correspondence may also be sent to the registered office
Governing lawEngland and Wales
Document versionv1.0
Effective date21 July 2026
Important: Strictly necessary technologies support security and requested functions; analytics, preference and marketing technologies are controlled under the applicable consent rules.

1. Introduction and scope

1.1 This Cookie Policy explains how Pixel Mill uses cookies and similar storage or access technologies on the public website, Account, checkout integrations and generation interface.

1.2 It should be read with the Privacy Policy and applies when the relevant technology or embedded feature is enabled. In practice, introduction and scope is assessed through the technology, purpose, consent state, duration, provider and user preference, with the result reflected in the inventory entry, consent record and browser-facing outcome.

1.3 The governing framework includes the Privacy and Electronic Communications Regulations 2003, United Kingdom data protection law and applicable Data (Use and Access) Act 2025 amendments.

1.4 When applying introduction and scope, those indicators are considered together rather than relying on a single unverified assertion.

2. What cookies and similar technologies are

2.1 A cookie is a small browser file, and similar technologies include local storage, session storage, pixels, scripts, tags, link decoration and device identifiers. The operational checkpoint for what cookies and similar technologies are is technology purpose, storage duration, provider, consent state and browser signal; completion is shown by the consent record, preference state and deployment inventory.

2.2 Some technologies store information on a device and others read information already stored, with session and persistent durations. This treatment of what cookies and similar technologies are is traceable without expanding collection or restriction beyond what the situation requires. Where the identifier relates to a person, it is also processed as personal data under the Privacy Policy.

3. Why Pixel Mill uses them

3.1 Strictly necessary technologies support sessions, log-in, checkout security, consent memory, fraud prevention and requested downloads. For why pixel mill uses them, relevant indicators include the technology, purpose, consent state, duration, provider and user preference, and the resulting action is documented through the inventory entry, consent record and browser-facing outcome.

3.2 Functional technologies remember choices, analytics technologies measure aggregate performance, and marketing technologies support consented attribution or advertising.

3.3 Pixel Mill uses the minimum category reasonably needed for the documented purpose. The why pixel mill uses them approach is calibrated to the transaction, request or risk actually identified and preserves any mandatory remedy.

4. Cookie categories

4.1 The category table distinguishes purpose, consent requirement and the effect of disabling each category.

4.2 Strictly necessary status is limited to genuine delivery or security needs rather than general commercial convenience. Implementation of cookie categories links technology purpose, storage duration, provider, consent state and browser signal to the consent record, preference state and deployment inventory, so the practical consequence can be explained and reviewed.

4.3 Functional, analytics and marketing technologies are controlled through the preference interface where consent is required.

4.4 No cookie categories outcome is based solely on a technical label where reliable contrary evidence is available.

Cookie category table

CategoryPurposeConsent requiredEffect if disabled
Strictly necessarySession security, authentication, checkout integrity, consent memory and requested downloadsNo, where the legal exemption appliesAccount, payment, generation or security functions may fail
Functional / preferencesRemember interface and user choices beyond what is essentialYes, where requiredPreferences may reset and convenience features may be unavailable
Analytics / performanceMeasure aggregate usage, errors, speed and feature performanceYesPixel Mill receives less information for diagnostics and improvement
MarketingMeasure campaigns, attribution or advertising audiencesYesAdvertising may be less relevant and campaign measurement reduced

5. Lawful basis and consent

5.1 Strictly necessary technologies may be used without consent where the legal exemption applies, while clear information remains available. Pixel Mill verifies lawful basis and consent against the wording presented, affirmative user action, timestamp, channel and later preference and records the action in the consent or suppression record and the resulting communication setting.

5.2 Non-essential technologies require freely given, specific, informed and affirmative consent, with rejection as accessible as acceptance. The lawful basis and consent record supports user communication, internal control and any provider, authority or court process that lawfully follows. Consent is separate from the Terms and purchase and may be withdrawn for future use.

6. Inventory and authorised technology

6.1 The inventory lists technologies authorised for common Pixel Mill functions when the relevant feature is deployed. The practical standard for inventory and authorised technology is tested using technology purpose, storage duration, provider, consent state and browser signal; the consent record, preference state and deployment inventory then evidences the action taken.

6.2 A payment or authentication technology may operate on the payment provider’s domain and be governed partly by that provider’s notice.

6.3 Pixel Mill reconciles the production implementation against the inventory and removes technologies without a documented purpose. Timing, scope and any exception under inventory and authorised technology are determined from the actual Service stage rather than a generic classification.

Cookie and technology inventory

Cookie / technologyTypePurposeDurationProvider
pixelmill_sessionStrictly necessaryMaintains authenticated session and Account securitySession or 24 hoursPixel Mill / hosting provider
pixelmill_csrfStrictly necessaryProtects forms and checkout actions against request forgerySessionPixel Mill
pixelmill_consentStrictly necessaryStores category choices and policy version12 monthsPixel Mill / consent provider
pixelmill_preferencesFunctional / preferencesRemembers interface and generation settings6 monthsPixel Mill
payment_sessionStrictly necessaryLinks the browser to secure payment and authenticationSession or 24 hoursPayment service provider
fraud_deviceStrictly necessaryDetects abuse, Account takeover and fraudulent checkoutUp to 13 monthsPayment or fraud provider
analytics_idAnalytics / performanceDistinguishes visits and measures aggregate performanceUp to 13 monthsAnalytics provider
campaign_idMarketingAttributes consented visits or conversions to a campaignUp to 90 daysMarketing provider

7. Third-party and embedded services

7.1 Payment, fraud, support, analytics, video or social services may set their own technologies when a user activates the feature and the consent position permits it.

7.2 An external service can receive an IP address, browser details, referring page, event data and identifiers. Operational review of third-party and embedded services focuses on provider role, contractual instruction, returned status, security control and independent legal duty, after which the supplier record, user-facing status and any necessary escalation confirms the result.

7.3 Pixel Mill configures integrations to minimise data and prevent non-essential loading before consent where required.

7.4 The third-party and embedded services distinction prevents an Account, payment, content or rights issue from being treated as if every consequence were identical.

8. Managing preferences

8.1 Users can accept, reject or select non-essential categories through the banner or preference centre. For managing preferences, Pixel Mill considers technology purpose, storage duration, provider, consent state and browser signal and uses the consent record, preference state and deployment inventory to close or escalate the matter.

8.2 Strictly necessary technologies cannot be disabled through that interface where they are needed for Account, checkout, generation or security functions. The managing preferences outcome remains proportionate to severity, recurrence, user impact and the legal or contractual duty involved. Browser deletion may sign the user out, reset consent, remove preferences or interrupt payment and download functionality.

9. Retention and review

9.1 Each technology has a session or fixed duration stated in the inventory and may be refreshed only while purpose and consent remain valid. In practice, retention and review is assessed through data category, purpose, lawful basis, recipient, location and retention criterion, with the result reflected in the processing record, rights response and deletion or retention action.

9.2 Pixel Mill reviews the implementation after material releases, new integrations and provider changes and at least every six months.

9.3 Consent records are retained long enough to demonstrate the choice and refreshed when purpose or applicable validity materially changes. When applying retention and review, those indicators are considered together rather than relying on a single unverified assertion.

10. Do-Not-Track and browser signals

10.1 General Do-Not-Track signals are not implemented consistently and Pixel Mill therefore relies primarily on the preference centre.

10.2 A legally recognised browser signal will be honoured where applicable, including an advertising-related opt-out signal required by relevant law. The operational checkpoint for do-not-track and browser signals is technology purpose, storage duration, provider, consent state and browser signal; completion is shown by the consent record, preference state and deployment inventory.

10.3 Such a signal does not disable strictly necessary technology used for a requested service.

10.4 This treatment of do-not-track and browser signals is traceable without expanding collection or restriction beyond what the situation requires.

11. Children and age

11.1 The Service is for adults aged 18 or over and Pixel Mill does not intentionally profile children or target advertising to them. For children and age, relevant indicators include age requirement, Account control, payment authority and any credible safeguarding information, and the resulting action is documented through the eligibility decision, protective restriction and limited disclosure record.

11.2 A parent or guardian may contact Pixel Mill where a child’s device or Account appears to have interacted with the Service. The children and age approach is calibrated to the transaction, request or risk actually identified and preserves any mandatory remedy. Users must not create Accounts or submit payments on behalf of children to circumvent the age requirement.

12. International data flows

12.1 Technology providers may process identifiers outside the United Kingdom through global networks. Implementation of international data flows links data category, purpose, lawful basis, recipient, location and retention criterion to the processing record, rights response and deletion or retention action, so the practical consequence can be explained and reviewed.

12.2 Where the information is personal data, Pixel Mill applies the transfer safeguards stated in the Privacy Policy.

12.3 Rejecting a non-essential category prevents the associated transfer where that transfer depends on the technology. No international data flows outcome is based solely on a technical label where reliable contrary evidence is available.

13. Governing standards and user rights

13.1 This Policy is interpreted under the laws of England and Wales and applicable United Kingdom privacy and electronic communications law.

13.2 Mandatory rights in a user’s place of residence remain unaffected, including privacy rights concerning access, objection, erasure and consent withdrawal. Pixel Mill verifies governing standards and user rights against applicable status, user location, request details, correspondence and mandatory legal conditions and records the action in the reasoned response, escalation route and preserved statutory option.

13.3 Users may complain to the Information Commissioner’s Office or another competent authority.

13.4 The governing standards and user rights record supports user communication, internal control and any provider, authority or court process that lawfully follows.

14. Changes

14.1 Pixel Mill may update this Policy when technology, purpose, provider or law changes. The practical standard for changes is tested using the previous version, reason for change, affected feature, notice route and transaction date; the effective version, preserved accrued right and future-use rule then evidences the action taken.

14.2 A new non-essential purpose will not be activated before the required consent is obtained. Timing, scope and any exception under changes are determined from the actual Service stage rather than a generic classification. The version, effective date and production preference centre identify the current implementation and choices.

15. Contact

15.1 Cookie and consent questions should be sent to info@pixel-mill.com with the browser, device, approximate date and relevant technology or preference where known. Operational review of contact focuses on applicable status, user location, request details, correspondence and mandatory legal conditions, after which the reasoned response, escalation route and preserved statutory option confirms the result.

15.2 Postal correspondence may be sent to MANAGEMENT RESILIENCE LTD at 20 Wenlock Road, London, England, N1 7GU.

15.3 Users must not send passwords or full card details. The contact distinction prevents an Account, payment, content or rights issue from being treated as if every consequence were identical.

16. Operational Maintenance Checklist

16.1 Before a material release, Pixel Mill scans the public site, Account and checkout for cookies, storage, pixels, tags and embedded requests and maps each to an owner, purpose, category and duration.

16.2 The consent flow is tested to ensure non-essential technology does not fire before consent and reject and withdraw controls remain functional and balanced. For operational maintenance checklist, Pixel Mill considers payment status, entitlement creation, file or output availability, email events and user troubleshooting and uses the release, redelivery, restoration, service notice or refund outcome to close or escalate the matter.

16.3 At least every six months, obsolete tags are removed, provider and transfer details are verified and the inventory and Privacy Policy are updated where flows change.

16.4 The operational maintenance checklist outcome remains proportionate to severity, recurrence, user impact and the legal or contractual duty involved.

Cart (0 items)

Create your account