DRAFT FOR LEGAL AND GOVERNANCE REVIEW — NOT AN APPROVED OR FINAL COOKIE POLICY
About cookies and similar technologies
Cookies and similar technologies store or read information on a device. This draft records categories and services observed in the Foundation’s current local website snapshot. Browser behavior, provider settings, expiry periods and legal consent requirements require final technical and legal verification.
Observed categories
Strictly necessary and security
WordPress and installed website components may use cookies or local storage for administrative login, authenticated sessions, security, preferences and core site functions. These may be necessary for a requested service or secure administration.
Forms and donation functionality
WPForms and GiveWP may use session, anti-spam, form-state or donation-flow storage when their workflows operate. WPForms is inactive and GiveWP is in test/manual mode in the audited local snapshot. This draft does not enable either workflow or assert that a live payment service is available.
Analytics
Google Analytics 4 is loaded through Google tag `G-FH4L7Q25H7`. It may use cookies or similar identifiers to measure visits, page use, referral information, device/browser characteristics and interaction events. The exact event configuration, retention period, advertising settings, IP handling and Google processing locations have not been approved or fully verified.
Live chat
Tawk.to chat code is loaded. Tawk.to may use cookies or similar technologies to provide chat, maintain a conversation, measure use and support service security. Messages entered into chat may be handled by Tawk.to and Foundation personnel. Do not send sensitive child, health, identity or financial documents through chat.
Embedded and third-party content
If pages include third-party media, maps, social links or embedded content, those services may set their own cookies when loaded or used. The final site must inventory each active embed before approval.
Consent status
No cookie-consent plugin or proven category-blocking mechanism was found in the audited local snapshot. Google Analytics and Tawk.to code loaded on the tested page without a verified consent gate. This draft does not change that behavior and must not be read as evidence of compliance. The Foundation must obtain legal advice on which technologies require consent and implement and test an approved consent mechanism before final publication.
Managing cookies
Visitors can usually delete or block cookies through browser settings, but doing so may affect requested site functions. A final policy should provide an approved preference-control method if required; no working preference centre was proven in this audit.
Retention and provider details
Cookie names, purposes, providers, domains and expiry periods require a live browser/storage inventory after the final integrations and consent design are set. Google and Tawk.to provider terms and international processing details also require legal review. No retention promise is made in this draft.
Questions
General contact details are available on the Contact page. The approved privacy contact and complaints process remain pending. See the draft Privacy Policy for the broader data-flow summary.
Approval
A final effective date, approval authority, cookie table and preference instructions must be added only after technical verification and legal/governance review.