Your choice
On your first visit, XP247 offers separate options to accept analytics, reject non-essential tracking or manage your choice. Rejecting analytics does not prevent account creation, checkout, payment, delivery, Rewards, referrals or customer support.
You can reopen the consent panel at any time using Cookie settings in the footer and change your analytics choice.
Analytics is off until you allow it. XP247 does not load Microsoft Clarity or create its own analytics-attribution identifier unless the analytics preference stored by XP247 says analytics is allowed.
What counts as a cookie or similar technology
Cookies are small pieces of information stored on your browser or device. Similar technologies can also store or read identifiers and preferences. Some are needed for a service you request; others, such as analytics technologies, generally require a separate choice.
Essential storage
These technologies support functions that XP247 needs in order to provide requested account, checkout, security, referral or privacy-preference features. They are not switched off through the analytics toggle.
- Supabase authentication/session storage: maintains secure sign-in and authenticated sessions.
- pl_consent: stores your current analytics preference and Cookie Policy version for up to 180 days.
- pl_consent_id: an HTTP-only identifier that links the browser preference to a server-side consent record for up to 180 days.
- pl_ref: where you deliberately arrive through a referral link, remembers the referral code for the referral programme's stated attribution window so the requested referral benefit can be applied. It is not used for cross-site advertising.
- Checkout, payment and security state: short-lived technical storage that may be needed to complete, verify or protect a transaction.
- Storefront preferences: where used, technical preference storage may remember choices such as locale or currency so the site can provide the version of the storefront you requested.
XP247 first-party source attribution
Consent required. This attribution process only runs after you allow analytics.
When analytics is allowed, XP247 records the landing path, the referring website host and recognised UTM source, medium, campaign, term and content fields where present.
A pseudonymous pl_visitor_id cookie is then set as an HTTP-only first-party cookie for up to 90 days. It allows a later signup or order to be associated with the original acquisition source so XP247 can measure the consented visit → signup → order → paid → completed funnel.
XP247 stores the referring website's host rather than the full referrer URL to reduce unnecessary collection.
If you later reject analytics, XP247 removes the pl_visitor_id cookie so it is not used for new attribution activity.
Microsoft Clarity
XP247 uses Microsoft Clarity for consent-based website analytics such as heatmaps, interaction analysis and session recordings.
The Clarity script is not loaded by XP247 unless analytics has been allowed. When analytics is allowed, XP247 sends Clarity a consent signal with analytics storage granted and advertising storage denied.
Clarity can use first-party cookies such as _clck and _clsk to recognise a browser and connect page views into a session. Microsoft also documents third-party cookies that may be involved in Clarity's normal operation. Those technologies are controlled by Microsoft once Clarity has been loaded.
Microsoft's current consent mode for UK/EEA/Swiss traffic supports operation without Clarity cookies when consent has not been granted. XP247 goes further in its current implementation by not loading the Clarity script at all until analytics is allowed.
Session-recording protections
Microsoft states that Clarity masks input fields by default before the information reaches Clarity's servers. XP247 also marks sensitive areas for additional masking, including account, admin, authentication, checkout, delivery, password-reset and order-tracking routes.
This masking is intended to stop sensitive page content from appearing in readable form in Clarity recordings. Analytics should never be used as a substitute for appropriate security controls on customer credentials or payment information.
Changing or withdrawing analytics consent
Open Cookie settings in the footer at any time and switch analytics off.
When you withdraw analytics consent, XP247:
- updates the stored XP247 consent preference;
- stops new first-party attribution collection;
- removes the XP247 pl_visitor_id attribution cookie; and
- sends a denied analytics-storage signal to Clarity if Clarity has already loaded on that page.
On later page loads, the current XP247 implementation will not load Clarity unless analytics is allowed again.
Advertising tools
XP247 does not currently grant Microsoft Clarity advertising storage through this implementation and does not currently enable advertising or remarketing tags such as Meta Pixel or TikTok Pixel.
If advertising or remarketing technologies are introduced later, XP247 must review this policy and the consent mechanism and obtain any additional consent required before those tools are enabled.
Browser controls
You can also delete or block cookies through your browser. Blocking authentication, checkout or other essential storage may prevent requested site functions from working properly.
Browser controls are separate from XP247's own Cookie settings. Where possible, use Cookie settings as well so XP247 can record and apply your choice to its consent-based analytics systems.
Changes to this policy
If XP247 changes the purposes of non-essential tracking, introduces new analytics or advertising technologies, or materially changes how consent-based storage is used, this policy and the consent version will be reviewed. Fresh consent will be requested where required.
Last updated: 19 September 2026. Policy versions are recorded at checkout where applicable.