Effective date: 25 March 2026 · Consent schema version: 1
This policy explains how SureStart ("we", "us") uses cookies and similar technologies on mysurestart.org. It covers cookies, localStorage, tracking pixels, and third-party embeds that may read or write identifiers on your device.
Cookies are small text files stored by your browser when you visit a website. "Similar technologies" includes browser localStorage, sessionStorage, pixels, beacons, and identifiers set by third-party content embedded on our pages (such as YouTube videos and Airtable forms). Throughout this policy, "cookies" refers to all of these technologies unless stated otherwise.
We group cookies and similar technologies into four categories. Only Strictly Necessary items run without your consent. All other categories are off by default and require your explicit opt-in before any data is collected or third-party content is loaded.
Required for the site to function and to remember your privacy choices. These cannot be disabled.
| Name | Provider | Purpose | Type | Lifetime |
|---|---|---|---|---|
ss_consent |
SureStart | Stores your cookie consent preferences so we do not ask again on every page. | localStorage | Persistent until cleared |
We also use Cloudflare R2 CDN (operated by Cloudflare, Inc.) to deliver images, videos, and other static assets. This is essential site infrastructure. Cloudflare may process minimal technical data (e.g., IP addresses for content delivery) but does not set tracking cookies on R2 public bucket requests under normal operation. Cloudflare Privacy Policy.
Fonts used on this site (Eastman Grotesque, DM Sans, Inter, Source Serif Pro) are self-hosted from our own domain. No font files are loaded from third-party servers such as Google Fonts.
Third-party forms used for contact and enrollment. Default: off.
| Name | Provider | Purpose | Type | Lifetime |
|---|---|---|---|---|
| Airtable session cookies | Formagrid Inc. (Airtable) | Embeds contact and enrollment forms. Airtable may set its own session cookies inside the form iframe. | iframe-opaque | Session |
vibeLabRegistration |
SureStart | Temporarily stores Vibe Lab registration data you submit so it can be sent to the server. | localStorage | Persistent until cleared |
Note: The Vibe Lab registration feature is not currently active on the site. This entry is listed for transparency and will apply if the feature is re-enabled.
Airtable forms appear on the Contact and Students pages. They are not loaded until you consent to the Preferences category. Because the forms run inside a cross-origin iframe, exact cookie names are controlled by Airtable. Airtable Privacy Policy.
Helps us understand how visitors use the site so we can improve it. Default: off.
| Name | Provider | Purpose | Type | Lifetime |
|---|---|---|---|---|
_ga |
Google LLC | Distinguishes unique users for Google Analytics 4. | Cookie | 2 years |
_ga_CM0T1ZNC15 |
Google LLC | Maintains session state for Google Analytics 4. | Cookie | 2 years |
_gid |
Google LLC | Distinguishes users within a 24-hour window. | Cookie | 24 hours |
We use Google Analytics 4 (measurement ID: G-CM0T1ZNC15) with
Google Consent Mode v2 in basic mode. No analytics data is collected
before you consent — the Google Analytics script is not loaded at all until you
opt in. Google does not receive cookieless pings from this site.
We do not enable Google Signals, User-ID, or advertising features.
Google Privacy Policy.
YouTube video embeds that may set third-party tracking cookies. Default: off.
| Name | Provider | Purpose | Type | Lifetime |
|---|---|---|---|---|
YSC |
Google LLC (YouTube) | Registers a unique ID to track which videos have been viewed. | Cookie | Session |
VISITOR_INFO1_LIVE |
Google LLC (YouTube) | Estimates bandwidth for video playback. | Cookie | 6 months |
GPS |
Google LLC (YouTube) | Registers a unique ID on mobile devices for tracking. | Cookie | 30 minutes |
IDE |
Google LLC (YouTube) | Used by Google DoubleClick for ad targeting. | Cookie | 1 year |
Until you consent, YouTube videos are replaced with a privacy-safe placeholder
and a "Load Video" button. No requests are made to YouTube's servers (including
thumbnail images) before you consent. When loaded, we use
youtube-nocookie.com where possible to reduce tracking.
Google Privacy Policy.
When you first visit the site, a consent banner appears with three equally prominent choices:
You can change your choices at any time by clicking "Cookie Settings" in the footer of every page. Changing or withdrawing consent is exactly as easy as granting it — the same panel opens with the same controls.
We honour the Global Privacy Control
signal. If your browser sends GPC (navigator.globalPrivacyControl = true),
we automatically default all non-essential categories to off and display a
"GPC honoured" badge on the consent banner. You can still choose to opt in
if you wish — your explicit choice takes precedence.
Limitation: This site is hosted on GitHub Pages (static hosting) and
cannot read the Sec-GPC HTTP request header server-side. We detect GPC
via the browser JavaScript API, which is supported by all major GPC-capable browsers
(Firefox, Brave, DuckDuckGo, Privacy Badger extensions).
Some pages embed content from third parties. These embeds may set their own cookies once loaded. We prevent them from loading until you consent to the relevant category. Each embed shows a placeholder explaining what will happen if you choose to load it.
| Provider | Purpose | Consent Category | Pages | Privacy Policy |
|---|---|---|---|---|
| Google LLC | Analytics (GA4) | Analytics | All pages | Link |
| Google LLC (YouTube) | Video embeds | Marketing | Home, K-12, Higher Ed, Impact Stories | Link |
| Formagrid Inc. (Airtable) | Contact & enrollment forms | Preferences | Contact, Students | Link |
| Cloudflare, Inc. | Image & asset delivery (CDN) | Strictly Necessary | All pages | Link |
You can also manage cookies through your browser settings. Most browsers let you block or delete cookies, and some offer built-in tracking protection. Here are links to cookie management instructions for common browsers:
Note that blocking all cookies may affect site functionality (for example, our consent preferences are stored in localStorage, which may also be restricted by aggressive browser privacy settings).
We apply EU/UK-style opt-in rules globally. All non-essential cookies are off by default and require your active consent before loading. This approach is consistent with the ePrivacy Directive (Art. 5(3)) and GDPR requirements for cookie consent. Our consent banner provides equally prominent options to accept, reject, or manage preferences.
We honour the Global Privacy Control (GPC) signal as described in Section 4. We do not sell or share personal information for cross-context behavioural advertising, and we do not use advertising pixels or retargeting. Because the same strict opt-in model applies to all visitors regardless of location, US visitors receive the same protections as EU/UK visitors.
We may update this policy when we add or remove vendors, or change how we use cookies. The consent schema version (currently v1) is stored in your consent record. If we make a material change that requires re-consent, the version will be incremented and the consent banner will re-appear automatically.
| Version | Date | Change |
|---|---|---|
| 1 | 2026-03-11 | Initial policy. Categories: necessary, preferences, analytics, marketing. Vendors: SureStart consent record, Google Analytics 4, YouTube embeds, Airtable forms, Vibe Lab localStorage. |
| 1 | 2026-03-25 | Added Cloudflare R2 CDN disclosure, self-hosted fonts note, regional notes, browser settings links, third-party summary table, and page navigation. No category or vendor changes. |