Browser storage and device identifiers
Cookies and local storage
What thegarma.com writes to the device you are reading this on, what our mobile titles use in place of cookies, and where the controls for both actually sit.
Effective 15 August 2026. Version in force since that date.
1. Why this page exists
Nearly every question a reader has about a website reduces to one thing: what is on my device now that was not on it before I loaded the page. This document answers that for thegarma.com, and for the mobile titles GARMA TECHNOLOGY LIMITED publishes on the Apple App Store and Google Play.
It sits alongside the Privacy Policy Statement rather than replacing it. Where the two describe the same processing, the privacy statement carries the fuller account and this page carries the mechanics. Publishing both is part of what DPP5 asks of a data user: the way personal data is handled should be discoverable without anyone having to ask us.
2. Where the rules come from
Hong Kong governs this subject through the Personal Data (Privacy) Ordinance, Cap. 486, and nothing else. There is no separate cookie statute here, no rule attaching to the act of writing to terminal equipment as such, and no statutory requirement to obtain permission before a file is stored in a browser. A site in Hong Kong is therefore not obliged to interrupt you with a consent interface, and we would rather explain the position than assert a legal duty that the statute book does not contain.
The Ordinance asks a different question, and it is the one that matters: is the thing being stored, or the record built from it, personal data? A cookie value, an advertising identifier, a software development kit identifier or a device fingerprint becomes personal data at the point where it is practicable to work out which living individual it belongs to, whether from the identifier alone or from it together with anything else held. Past that point the six Data Protection Principles bind it exactly as they bind a name.
- DPP1 requires that you be told, on or before collection, what the purpose is and which classes of persons the data may reach, and that the collection be necessary rather than merely convenient.
- DPP2 and DPP4 govern how long an identifier may be kept and how it must be protected while it is held.
- DPP3 stops an identifier gathered for one purpose being turned to a genuinely different one without prescribed consent.
- DPP6 gives you the right to ask what is held against an identifier tied to you, and to have it corrected.
- Part VIA takes over entirely if such data is ever used to aim marketing at you as an identified person, and it is enforced by prosecution rather than by an enforcement notice.
So the obligation on this domain is not to stage a permission ritual. It is to describe the storage accurately and to keep that description true as the site changes. That is what the rest of this page does.
3. What this site writes to your device
thegarma.com is a static corporate site. It has no accounts, no sign-in, no forms, no comment system, no advertising slots and no analytics product. The table below is the complete inventory of client-side storage on this domain, checked against the files that are actually deployed rather than against an intention.
| Mechanism | Used on this site | Detail |
|---|---|---|
| First party cookies | None | No response from this domain carries a Set-Cookie header. |
| Third party cookies | None | Nothing on the page is capable of setting one. There is no embedded player, social widget, chat box, map or advertising tag. |
| localStorage and sessionStorage | Not used | The single script on the site writes no key to either store. |
| IndexedDB, Cache Storage, service worker | Not used | No service worker is registered, so nothing on this domain runs after you close the tab. |
| Ordinary browser cache | Yes | Images are served with a one year cache lifetime, the stylesheet and script with one hour. This is the browser storing a copy of a file it already fetched. |
| In-memory page state | Yes, per page view | A class on the root element that selects the section reveal method, and a custom property on a button that sets which edge its fill runs from. Both are discarded when the tab closes. |
The only durable trace, then, is the browser's own cache, which is browser behaviour rather than a tracking mechanism. It is keyed to a file address rather than to a person, it holds no identifier, it is readable only by your browser, and clearing your browsing data removes it. It exists so the second page you open loads from the disk in front of you instead of from a server in another region.
One structural point is worth stating because it is externally checkable. The responses from this domain carry a Content Security Policy that permits scripts only from this origin, styles and fonts only from this origin and the two Google Fonts hosts named below, and no outbound connections beyond this origin at all. A tracker cannot be quietly introduced into a page here by dropping in a tag: the policy would block it, and the policy would have to be rewritten in public first.
4. The external request this site makes
Two typeface families are loaded from Google Fonts, so your browser requests files from fonts.googleapis.com and fonts.gstatic.com. In the ordinary course of serving a font those hosts see your IP address, your user agent string and the address of the page that asked for the file. Google decides for itself what to do with that request, which makes it a separate data user in respect of it rather than a processor acting on our instruction, and its own privacy documentation governs the outcome.
The font request sets no cookie. Because the Content Security Policy admits exactly those two hosts and nothing else, this is not an example of third-party traffic on the site; it is the entirety of it.
5. What the server records instead
A site that stores nothing on your device still leaves a record at the other end, and being straight about cookies is worth little without saying so. Serving a page writes an entry in our hosting provider's request log: the originating IP address, the timestamp, the path requested, the HTTP status returned, the user agent string, and the referring page where your browser sent one. Country-level location is derived from the IP address by the provider for routing and abuse prevention, and nothing more precise is derived on this site.
An IP address is treated here as personal data wherever it is practicable to connect it to an identifiable person, rather than waved through as technical exhaust. Those log entries are held for up to 30 days and used for fault diagnosis and abuse prevention. The rest of the retention schedule, covering the apps as well as the site, is set out in section 10 of the privacy statement.
6. Identifiers inside the apps
A mobile application does not use cookies for the work a browser uses them for. It uses operating system identifiers, and the controls belong to the platform rather than to us. These are the kinds a GARMA title may use, and a given title uses a subset that its store listing declares.
- An installation identifier, generated by the title, so that a crash report or a support ticket can be matched to an install rather than to a named person. It is resettable by reinstalling.
- An account or guest identifier, which is what makes your progress yours and lets a lost progress ticket be answered.
- The Identifier for Advertisers on iOS, read only where a title carries advertising or install attribution, and only where you allowed it at the App Tracking Transparency prompt. Decline and advertising still appears in a title that carries it, but it is not personalised across apps and the identifier is not read. We do not attempt to rebuild a declined identifier through fingerprinting or any equivalent technique.
- The Advertising ID on Android, where a title uses it, declared in the Play Console as policy requires, and resettable or deletable by you at any time.
What each title actually ships is declared twice over, in the App Privacy label on its App Store product page and in the Data safety section of its Google Play listing, including identifiers that arrive inside a third-party software development kit rather than in our own code. Those declarations are maintained against the build. The fuller account is in section 18 and section 19 of the privacy statement, and the device permissions a title may request are tabulated in section 6.
7. Turning things off
On the website there is nothing to switch off, because nothing beyond the cache survives your visit. In the apps the controls are real and they belong to your operating system, which means they work whatever we do.
| What you want to do | Where it is |
|---|---|
| Clear cached files from this site | Your browser's privacy or history settings, usually worded as clearing browsing data or managing website data. Wording differs by browser; the setting is present in all of them. |
| Block cookies as a general rule | Your browser's cookie or site data settings. Blocking changes nothing about how this site behaves, since none are set here. |
| Withdraw app tracking permission on iOS | Settings, Privacy and Security, Tracking, then turn the title off. |
| Stop tracking requests reaching you at all | Settings, Privacy and Security, Tracking, then turn off Allow Apps to Request to Track. |
| Reset or delete the advertising ID on Android | Settings, Google, Ads. |
| Change a device permission for a title | Settings, then the title on iOS. Settings, Apps, the title, Permissions on Android. |
Resetting a platform advertising identifier severs the link between what was recorded before the reset and what is recorded after it. It does not reach back and erase what was already collected. For that, the routes are a data access or correction request under section 12 and account deletion under section 20 of the privacy statement, both of which are answered on the statutory clock rather than at our convenience.
8. Browser signals
Some browsers attach a Do Not Track header or a Global Privacy Control signal to every request they send. Hong Kong law gives neither signal any legal effect, and we are not going to claim we honour a preference in order to take credit for a state the site is already in. A signal asking a site to stop profiling its reader has nothing to act against on a domain that runs no analytics, sets no cookies and loads no advertising code, so on thegarma.com the request and the reality already agree.
The apps are where a preference has something to bite on, and there the mechanism is not a header but the platform prompt: App Tracking Transparency on iOS, the advertising identifier settings on Android. Both are honoured as described in section 6, and a decline is treated as final rather than as an invitation to find another route to the same data.
9. Before this site sets a cookie
This page describes the site as deployed today. A document like it is worth nothing if it is written once and then left to drift away from the code, so here is what happens before that description changes.
- This page is updated first. Any cookie or storage key would be named here, with what it holds, how long it lasts, and whether anyone other than us can read it, before the release that introduces it reaches you.
- The purpose is tested against DPP1. Collection has to be necessary and not excessive for a stated purpose. A preference that can be carried in a request or inferred from it does not justify a stored identifier, and that test is applied before the convenience of having one is weighed.
- Consent is obtained where the Ordinance requires it. If storage were ever put to a purpose DPP3 treats as new, or used for direct marketing under Part VIA, prescribed consent comes first: a separate, unticked step, logged with the wording you were shown, never folded into acceptance of the Terms of Service.
Until one of those things is true, there is no consent interface on this site, for the plain reason that there is no storage decision to put to you.
10. Questions and complaints
Write to the Privacy Compliance Officer, GARMA TECHNOLOGY LIMITED, at contact@thegarma.com. That address takes questions about this page, data access requests under section 18 of the Ordinance, correction requests under section 22, and deletion requests for an account in one of our titles. The 40 day period in section 19 runs from the day a request arrives there.
Office of the Privacy Commissioner for Personal Data, Hong Kong. You may complain to the regulator whenever you wish, and you are not required to raise the matter with us first. The online complaint form is at pcpd.org.hk, complaints by email go to complaints@pcpd.org.hk, and the office is at Unit 1303, 13/F, Dah Sing Financial Centre, 248 Queen's Road East, Wanchai, Hong Kong. The enquiry hotline is 2827 2827.
What the Commissioner may do about a complaint, and the one thing the office cannot do, is set out in section 23 of the privacy statement.