Cookie policy
Last reviewed: 2026-04-20
Spitfire Association Website
Cookie Policy
This page explains the small number of cookies the Spitfire Association website uses, why we use them, and the choices you have.
What is a cookie?
A cookie is a small text file stored by your web browser. It lets a website recognise that a later request came from the same browser — for example, to keep you logged in as you move between pages, or to remember a choice you’ve made.
What this site uses
We use only a small set of first-party cookies — cookies set on our own domain, not shared with any third party.
Strictly necessary
- Session cookie (PHPSESSID). Identifies your visit so the site can keep you signed in as a member, hold items in a cart, and validate form submissions against cross-site request forgery. It expires when you close your browser (or after a period of inactivity). Marked HttpOnly, Secure, and SameSite=Lax.
- Consent cookie (
spitfire_consent). Records the choice you make on our cookie banner, so we don’t ask again on every page. Stored for up to 180 days, after which we ask again.
Strictly necessary cookies are set even if you reject non-essential cookies, because the site cannot safely function without them.
Payment processing (Stripe)
On pages where a payment can occur — the shop, membership signup and renewal pages — we load Stripe.js so card details go directly from your browser to Stripe and never touch our servers. Stripe is classed as a strictly necessary service on those specific pages. We do not load Stripe.js on biographical, news, or informational pages.
Spam protection (hCaptcha)
Our contact and registration forms are protected by hCaptcha. hCaptcha is loaded only if you choose Accept all on our cookie banner. If you choose Reject non-essential, we use simpler spam checks that don’t require a third party, at the cost of slightly less effective protection against bots.
What this site does NOT use
To keep our visitors’ privacy simple and strong, this site does not use any of the following:
- Google Analytics, or any other behavioural-analytics platform
- Facebook Pixel, Facebook SDK, or any social-media tracking
- LinkedIn, Twitter/X, TikTok, or other platform trackers
- Third-party advertising networks or remarketing cookies
- Third-party live-chat widgets
- CDN-hosted fonts (our typefaces are self-hosted)
- Persistent “remember me” cookies storing your identity beyond the session
Your choices
When you first visit, you’ll see a short banner with two equally prominent options:
- Accept all — enables hCaptcha on forms, in addition to the strictly necessary cookies.
- Reject non-essential — only the strictly necessary cookies are set. hCaptcha is not loaded; form-spam checks fall back to simpler methods.
You can change your decision at any time by clearing the
spitfire_consent cookie in your browser’s privacy
settings and revisiting any page; the banner will re-appear.
Your browser also provides built-in controls to accept or refuse cookies (including the strictly necessary ones). Refusing strictly necessary cookies will prevent features that rely on a session — such as member login and checkout — from working.
Updates to this policy
We may update this Cookie Policy from time to time. Changes take effect immediately on posting. See the Last reviewed date at the top of this page for when it was last checked.
Related documents
- Privacy policy — how we handle your personal information more broadly.
- Terms and conditions — the rules for using this website.
Contact
Questions about our use of cookies can be sent to privacy@spitfireassociation.com .