Privacy notice
Last updated 6 October 2026
Who we are
FortuneCookies (fortunecookies.cloud) is a service run by Webwax Ltd, a company registered in England and Wales (company number 08125321), 5–6 Grays Yard, Chelmsford, Essex CM2 6QR, UK. In this notice “we”, “us” and “our” mean Webwax Ltd.
We are the controller of the personal data described under “This website” and “Clients”. For the cookie banners we run on our clients’ websites we are a processor acting for those clients (see “Our banner on clients’ websites”).
Questions or requests about your data: privacy@fortunecookies.cloud. This notice applies under the UK General Data Protection Regulation and Data Protection Act 2018 (“UK GDPR”), the EU General Data Protection Regulation (“EU GDPR”) where it applies to you, and Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”) and Quebec’s Act respecting the protection of personal information in the private sector (“Law 25”) where they apply.
This website
Enquiries you send us
When you use the enquiry form we collect your name, email address, company (optional), your website addresses, the cookie tool you use today and anything you write in the message.
- Why: to reply to you and, if you want, to prepare a quote and set up the service.
- Lawful basis: taking steps at your request before entering into a contract (Article 6(1)(b)), and our legitimate interest in answering business enquiries (Article 6(1)(f)).
- You don’t have to give us this information, but we can’t reply without a name and an email address.
The beta
If you join the beta on our pricing page we collect your name, your email address and, if you add them, your website addresses and the plan you’re interested in.
- Why: to email you when there’s a place in the beta for your website, and to reply if you write back.
- Lawful basis: your consent (Article 6(1)(a)). You can withdraw it at any time by replying to any email from us or writing to privacy@fortunecookies.cloud, and we’ll take you off the list.
Apart from the beta list, if you join it, we don’t add you to a mailing list, and we don’t send marketing emails.
Spam protection
Our contact and beta forms use a hidden field and a limit on how many messages one connection can send per minute; that limit uses your IP address only at that moment. They may also use Cloudflare Turnstile, which checks that a person is sending the form using technical information from your browser and connection, such as your IP address and browser details. Our basis is our legitimate interest in keeping the form free of spam (Article 6(1)(f)).
Visiting the site
Like any website, our hosting provider receives technical information when your browser requests a page, such as your IP address, browser type and the page requested. We use this only to deliver the site, keep it secure and fix problems (legitimate interests, Article 6(1)(f)). We don’t use analytics, advertising or tracking tools on this site. See our cookie notice.
Clients
If your organisation becomes a client, we use the business contact details of the people we deal with to provide the service, record sign-offs of your cookie list and banner wording, send invoices and manage the account (contract and legitimate interests, Articles 6(1)(b) and (f)), and keep accounting records as the law requires (legal obligation, Article 6(1)(c)).
A sign-off record holds the name and email address of the person who approved a change, how and when they approved it, and any note we add.
Our banner on clients’ websites
When you visit a website that uses our banner, the owner of that website is the controller, and we process data only on its instructions, under our data processing agreement. Questions about that website should go to its owner first. We keep this to a minimum:
- One cookie. The banner sets a single cookie,
fc_consent, on that website to remember your choice. It holds a random ID, your choices and the date. It lasts six months unless the website owner sets a shorter time. - A consent record. When you make a choice, we store the random ID, the time, your choices, the version of the banner you saw, the page path and your country (worked out from your connection, not stored as an IP address). We keep it for two years so the website owner can show that consent was given, then delete it.
- No IP addresses stored, no profiles. Your IP address and browser details are used briefly to deliver the banner and to limit abuse. They are not stored with consent records, and we don’t track you across websites.
Your random ID is shown in the banner’s settings panel. If you contact the website owner about your choices, quoting it helps them find your record.
Who we share data with
We don’t sell personal data. We share it only with service providers who process it for us under contract:
- Cloudflare, Inc. hosts the website, the banner service and our database (consent records are stored in Cloudflare’s EU region), loads websites for our scans, sends our notification emails, and provides Turnstile spam protection.
- Our email provider, where enquiry notifications and our replies are stored.
- Our accountants and professional advisers, for clients, where needed.
We may also disclose data where the law requires it, or to protect our rights.
International transfers
Consent records are stored in the EU. Cloudflare runs a global network, so other data, and data in transit, may be processed outside the UK, the European Economic Area and Canada, including in the United States. Where that happens we rely on the safeguards the law allows: the EU–US Data Privacy Framework and its UK Extension where the recipient is certified, or the EU Standard Contractual Clauses and the UK International Data Transfer Addendum in Cloudflare’s data processing terms. You can ask us for more detail.
How long we keep it
- Enquiries and beta sign-ups that don’t lead to a contract: up to 2 years, then deleted automatically, or sooner if you ask.
- Client records and sign-offs: for the length of the contract, then 6 years for accounting and legal purposes.
- Consent records on clients’ websites: 2 years, then deleted automatically, or earlier if the client asks us to delete them.
- Technical logs held by our hosting provider: short periods, typically days, as set by the provider.
Your rights
You have the right to:
- ask for a copy of your personal data (access);
- have inaccurate data corrected;
- have your data deleted;
- restrict how we use it;
- object to processing based on our legitimate interests;
- receive data you gave us in a portable format, where the basis is contract;
- withdraw consent at any time, where we rely on it.
Email privacy@fortunecookies.cloud. We’ll reply within one month (30 days for requests under Canadian law). We may need to confirm your identity first. Using your rights is free unless a request is clearly unfounded or excessive. For consent records on a client’s website, we’ll pass your request to the website owner and help them answer it.
We don’t make decisions about you by automated means that have legal or similarly significant effects.
Complaints
Please tell us first at privacy@fortunecookies.cloud and we’ll try to put things right. You can also complain to a data protection authority: in the UK, the Information Commissioner’s Office (ico.org.uk); in the EU, the authority where you live or work; in Canada, the Office of the Privacy Commissioner of Canada, or in Quebec the Commission d’accès à l’information.
Changes to this notice
We may update this notice. The date at the top shows when it last changed. If a change affects clients significantly, we’ll tell them by email.