1. What is a cookie
A cookie is a small text file that a website asks your browser to store. The browser sends the file back on every subsequent request to the same site, so the server knows it is talking to the same visitor. Cookies have legitimate uses - keeping you logged in, remembering items in a shopping cart, preserving language preferences - and illegitimate ones, such as following you across the web to build an advertising profile. We use cookies only for the former.
2. The cookies we set
The donation flow uses a functional session cookie named blp_session, with no value other than a randomly-generated identifier. It is set only when you reach the donation page and is required for the donation form to function - it ties the browser session to the in-progress transaction so that, if the page is refreshed mid-checkout, your selections are preserved. The cookie expires when you close the browser tab. It is marked Secure and HttpOnly. It contains no personal data and is never read by any third party.
This first-party session cookie is separate from the payment and anti-fraud services described below. Optional campaign tags may also use cookies according to your consent choices.
3. Plausible Analytics - cookieless by design
We use Plausible Analytics to count how many people visit which pages on the site. Plausible was built specifically to avoid the privacy harms of conventional analytics: it does not set cookies, does not collect personal data, and does not fingerprint visitors. Page-view counts are aggregated server-side without ever creating a per-visitor identifier. Plausible's data-collection script is hosted on plausible.io and weighs less than one kilobyte. You can review Plausible's open-source code on GitHub and its data-handling practices at plausible.io/data-policy.
Because Plausible does not use cookies and does not collect personal data, it does not require consent under the GDPR ePrivacy Directive in any EU member state.
3a. Analytics and advertising tags - with your consent
To understand which outreach campaigns bring new supporters, and to reach people who have already shown interest in our work, we additionally use a configurable set of measurement and advertising tags. Depending on current campaigns these may include: Google Tag Manager, Google Analytics 4 and Google Ads (Google LLC), the Meta Pixel (Meta Platforms), Microsoft Clarity (Microsoft), Outbrain, Taboola, and the TikTok Pixel. These services may set cookies or use similar technologies to measure visits, attribute donations to campaigns, and build remarketing audiences.
Where consent is required (the EEA, the United Kingdom and Switzerland), these tags default to a non-consented state using Google Consent Mode v2 and equivalent mechanisms, and are activated only according to the choice you make in the cookie banner. Choosing "essential only" keeps advertising and analytics storage off. You can change your choice at any time by clearing this site's data in your browser, which will re-display the banner.
Each provider processes data under its own privacy policy: policies.google.com/privacy, facebook.com/privacy/policy, privacy.microsoft.com, outbrain.com/privacy, taboola.com/policies/privacy-policy, tiktok.com/legal/privacy-policy.
4. Stripe - payment processing on the donation page
On the donation page, we embed Stripe's hosted payment form. Stripe sets a small number of its own cookies on the donation page itself for fraud-detection purposes (notably the cookie named __stripe_mid, which assigns a long-lived merchant identifier to the browser). These cookies are set by Stripe, not by us, and are governed by Stripe's privacy notice at stripe.com/privacy. They are necessary for the secure operation of the payment flow under the strong customer authentication requirements of PSD2 and equivalent regimes; we would not be able to process card payments without them.
Stripe's cookies appear only on the donation page and are not set on any other page of the site. They are explicitly excluded from the prior-consent requirement of the ePrivacy Directive because they are strictly necessary to provide the service you have explicitly requested - namely, making a donation.
4a. Google reCAPTCHA - necessary payment security
Google reCAPTCHA Enterprise protects our donation and payment flows against automated card testing, fraud and abuse. Its script loads on payment pages and the risk assessment runs when you submit. Our server sends the generated security token, requested action, browser user agent and IP address from a trusted platform header to Google. It does not send card numbers, CVV or iFields payment tokens in that assessment request.
When executed, reCAPTCHA sets the security cookie _GRECAPTCHA and may use similar browser storage for risk analysis. Our integration loads from www.google.com and www.gstatic.com, so existing Google cookies may accompany requests. We classify this limited anti-fraud service as strictly necessary to protect a payment you request; it is separate from optional analytics and advertising tags and remains active when you choose essential cookies only. More detail is available at docs.cloud.google.com/recaptcha/docs/faq.
Blocking reCAPTCHA's script or security storage can prevent a card donation from completing. If you cannot pass the security check, contact donations@blphome.org for assistance or an alternative way to give; do not send card details by email.
5. What we do not do
We do not sell or rent personal data to anyone, ever. We do not participate in cookie-based affiliate networks. We do not load fonts from third-party CDNs that fingerprint visitors (all our fonts are either system fonts or self-hosted). We do not use chat widgets that set cookies. We do not embed YouTube videos in their default tracking mode; the few videos we do embed use the nocookie variant. The advertising tags listed above are used solely to measure and improve our own fundraising outreach - never to track you for any third party's benefit.
6. Managing cookies
You can block or delete cookies in your browser's privacy settings. Blocking functional session storage, payment-processing cookies or reCAPTCHA security may prevent the donation form from working correctly or a card payment from completing. The rest of the site remains available. For another way to give, contact donations@blphome.org; do not send card details by email.
7. Questions
Cookie questions are addressed to privacy@blphome.org. We will answer within five business days.
