Legal
Cookies and storage
Written the way we write a restore drill. Each numbered clause states the precondition it assumes, the procedure that follows, the outcome you should observe, and the record left behind. Read it, then run drill 08 and check the answers against your own browser.
Effective 14 August 2026Version 2.0Privacy Act 1988 (Cth)
01What this page proves
Take the short version first. Loading a page here writes nothing to your device on our behalf. Nobody counts you, nobody profiles you, nobody plants a marker to recognise you next week, and no product on this site exists to work out who you are.
Two things nonetheless cross the boundary of the page, and both get a clause of their own. A security cookie may arrive from the company that serves the files. Two font files are fetched from Google. Neither is a tracker, both are describable in full, and describing them is cheaper than asking you to trust a summary.
Precondition
A browser requests a page on shielddata.link.
Procedure
HTML, one stylesheet, one script and two images are returned. The script came from this domain and drives the small-screen menu.
Outcome
Nothing that identifies you is written by us, so no permission is sought and no banner obstructs the page.
Record kept
A line in the server's request log, held by the provider. Drill 07 sets out what that line contains.
02The footing under browser storage
No statute in this country makes you click a button before a cookie may be written. Nothing here mirrors the European ePrivacy Directive, so a banner on a site governed from New South Wales reflects the taste of whoever built it rather than an obligation placed on them.
The Privacy Act 1988 (Cth) is what actually bites. Where storage on a device gathers information about somebody reasonably identifiable, that information is personal information and the Australian Privacy Principles govern it like any other: APP 3 on whether it may be gathered at all, APP 5 on saying so, APP 6 on the uses that follow, APP 11 on protecting it and getting rid of it.
So the useful questions are whether a thing was needed, whether it was disclosed, and whether it stays inside the purpose given for it. Work through the clauses below and you have our answer to each.
Precondition
You are reading from anywhere. The company is governed by Australian law wherever you sit.
Procedure
Test every stored item against necessity, disclosure and purpose before it ships, rather than against whether consent could be harvested for it.
Outcome
Readers in the European Economic Area and the United Kingdom, where consent would be owed for anything past strictly necessary storage, get the same result: there is nothing past it.
Record kept
This page, dated and versioned at the top.
03The missing banner
A consent dialogue has one job: to gather permission for storage nobody needs in order to serve the page. Since no such storage exists here, a dialogue would be collecting agreement to an empty set.
Putting one up anyway would do damage in two directions. It teaches readers to swat away a control that carries real weight elsewhere. And it hints that something is being gathered, which would make our own notice misleading in the direction nobody bothers to complain about.
Precondition
Someone proposes analytics, advertising, or any other non-essential storage for this site.
Procedure
Update this page first. Ask before the thing loads. Make declining exactly as quick as agreeing, with nothing pre-ticked and neither button whispering.
Outcome
A dialogue appears here only when there is genuinely something to decide.
Record kept
A new effective date on this page, carrying the change that prompted it.
04The storage inventory
Everything capable of landing on your device is listed here. There is no second table.
| Name | Written by | Job | Lifetime | Consent owed |
|---|---|---|---|---|
| __cf_bm | Cloudflare, which serves these files | Separates automated traffic from people so abusive traffic can be turned away. Required to deliver the site at all | 30 minutes, refreshed while you keep reading | No |
| cf_clearance | Cloudflare | Written only where a challenge was shown and passed, so the same challenge does not reappear on the next page | Up to 30 days | No |
Both belong to the edge that serves the files. We write nothing, and neither entry gives us a handle by which to recognise you. They exist because anything reachable from the open internet needs some way to distinguish a reader from a script.
No local storage. No session storage. No IndexedDB. No cache entry pressed into service as an identifier. No service worker.
Precondition
Traffic arrives at the edge, some of it automated.
Procedure
The edge classifies the request and, where a challenge is warranted, records the result of it in one of the two entries above.
Outcome
Pages are delivered without being buried under scripted traffic, and the entries expire on the clock stated.
Record kept
Nothing on our side. Neither value is copied off your device or joined to anything we hold.
05Instruments this site refuses to carry
An absence is easier to verify than an assurance, so here is the list to verify.
- No Google Analytics, and equally no Plausible, Fathom, Matomo, Umami or anything else that counts readers.
- No advertising, no advertising cookie, no remarketing tag.
- No Meta pixel, no LinkedIn Insight tag, no TikTok pixel, no conversion measurement of any description.
- No session replay, no heatmap, no scroll-depth capture, no rage-click detector.
- No experimentation or split-testing tool.
- No embedded video, map, social widget, chat bubble or comment thread, each of which usually arrives towing storage of its own.
- No form anywhere, so no form analytics either. Reaching us means typing an address into your own mail client.
- No visitor-identification or company-lookup product, the sort that converts an IP address into a sales lead.
- No fingerprinting, by canvas or by any other route.
- No third-party JavaScript whatsoever. One script runs, it is ours, it comes from this domain, and it opens and closes the menu on a narrow screen.
Precondition
You would rather check than believe.
Procedure
Open the Network and Application panels in your browser's developer tools, then reload.
Outcome
What those panels show is authoritative, and it should agree with the list above item for item.
Record kept
Should the panels disagree with the list, that is a defect. Send it to [email protected] and it gets treated as one.
06The single outbound request
Lora and Roboto Mono are fetched from fonts.googleapis.com and fonts.gstatic.com. Making that fetch hands Google's servers your IP address, your user agent and the address of the page that sent you. Google's own position is that the Fonts service writes no cookie and that these requests feed neither advertising nor profiling.
It remains a call to a party you never chose. Saying so plainly beats leaving it out on the grounds that everybody does it. Serving both faces from this domain would end the request altogether, and on the day that change ships this clause changes with it.
Block the two hosts, at your network or with an extension, and nothing here breaks. The page falls back to a serif and a monospace face already installed on your machine. No behaviour depends on the download.
Precondition
A page loads and the two faces are not yet cached.
Procedure
The browser fetches a stylesheet and the font files from the two Google hosts named above.
Outcome
Text renders in the intended faces, or in your system defaults where the fetch is blocked or fails.
Record kept
Whatever Google keeps at its end, on its own terms. Nothing about the fetch is recorded here. No other host is contacted: no script CDN, no icon service, no image host, no error-reporting endpoint.
07Request logs, which sit elsewhere
Servers write down the requests they answer, and this one is no exception. The provider logs an IP address, a timestamp, the path asked for, the user agent string and the status code sent back.
None of that lands on your device, so it is not storage and consent has nothing to do with it. It is still personal information under the Act, and a page that inventoried device storage while stepping around the logs would be telling a half-truth.
Precondition
Any request reaches the provider's edge.
Procedure
The five fields above are written to the provider's log and rotate on the provider's cycle, currently shorter than 30 days.
Outcome
Pages get served and abusive traffic gets blocked. There is no other use.
Record kept
The provider's log and nothing further. We copy none of it into a database of ours, join it to nothing, and run no traffic reporting over it.
08Run the check yourself
Every serious browser will block storage, delete what has already been written, and show you the current contents. Block the two edge entries from drill 04 and you may meet a challenge more often; the site still works.
- Chrome: Settings, then Privacy and security, then Third-party cookies. Site data shows what is already written.
- Safari: open Settings, choose Privacy, and use Manage Website Data.
- Firefox: open Settings, choose Privacy and Security, and look under Cookies and Site Data.
- Edge: Settings, then Cookies and site permissions.
Precondition
A browser you control, and five spare minutes.
Procedure
Clear site data, reload a page here, then reopen the panel and read what came back.
Outcome
At most the two entries in drill 04, and often neither. A private window throws away the lot at the end of the session, which changes almost nothing here.
Record kept
Yours, in your own browser, checkable again whenever you like.
09Do Not Track and Global Privacy Control
Send either header and it is honoured. That is a cheap promise here, because there is nothing waiting to be switched off: the behaviour with the header is the behaviour without it.
State the position anyway. A site that quietly disregards these headers has made a choice it would prefer nobody examined, and writing the choice down costs one sentence.
Precondition
Your browser or extension attaches a DNT or GPC header to the request.
Procedure
The header is accepted. No branch of any code path here consults it in order to do something extra.
Outcome
No additional storage, no additional processing, identical to the case where no header arrives.
Record kept
Only the ordinary request log from drill 07.
10The rehearsal service and browsers
Cookies live in browsers, and the verification service is not something you point a browser at. A rehearsal fires on a schedule against a customer's backup: no operator, no browser, no session, nothing to keep signed in.
Build a customer dashboard one day and it needs at least a session cookie to hold somebody's login, which every classification in the world calls strictly necessary. On the day that exists it joins the table in drill 04, with its name, its lifetime and its job written out, before it ships and not afterwards.
Precondition
A rehearsal is due under an engagement.
Procedure
The run happens machine to machine, against a backup store, inside an isolated environment.
Outcome
Nothing in the service reaches a browser, so nothing in the service can write to one.
Record kept
The evidence file for that rehearsal, described in the terms of use.
11Amending the inventory
Anything that would write to your device beyond the two entries listed goes into the table before it goes live, under a fresh effective date. Where the law reaching you demands consent, you are asked while the thing is still off rather than once it is running.
Precondition
A change is proposed to what this site stores or which hosts it contacts.
Procedure
Amend drill 04 or drill 06, stamp a new effective date, publish, then deploy the change.
Outcome
This page is never behind the site it describes.
Record kept
Superseded versions are retained but not published as separate pages. Ask for the wording as it stood on a given date and you will be sent it.
12Questions, requests, complaints
Write to [email protected]. Questions about this page come back inside 5 business days. A request under the Privacy Act comes back inside 30 days.
Where our answer leaves you unsatisfied, take it to the Office of the Australian Information Commissioner: GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au. Lodging costs nothing, needs no solicitor, and needs no agreement from us.
Precondition
Something on this page is wrong, unclear, or contradicted by what your browser shows.
Procedure
Email the address above. Put the page and the browser in the message, and paste what you observed.
Outcome
Either the page is corrected or the site is, and you are told which.
Record kept
SHIELD DATA SYSTEMS PTY LTD, ACN 696 553 036, ABN 46 696 553 036, New South Wales, Australia. The wider account of what is held and why sits in the privacy policy.