Cookies
Effective date: 18 September 2026
Contact: productions@lowlightking.com
1) What this site sets of its own
One thing, and it is running. This site uses PostHog product analytics, and it writes an identifier to your browser so that a second page you read is known to be the same visit as the first. That identifier is first-party: it is set by this site, on this domain, and no other website can read it. Section 2 says what is recorded against it, and Section 4 says how to stop it.
Apart from that, nothing. No advertising, no cross-site tracking, and no third-party request for fonts or stylesheets — the three typefaces are served from this domain.
That is a statement about our code. Third parties embedded on these pages also write to your browser, and Section 3 says which and what.
2) How we count visits
Two things, which answer different questions.
Cloudflare Web Analytics is cookieless: it stores nothing in your browser, sets no identifier, and cannot follow you to another site. It records the page, the referrer, and coarse details such as country, browser and whether the page loaded quickly. It counts how many times a page was served.
PostHog is not cookieless, and we are not going to describe it as though it were. It sets an identifier of its own so it can tell that the four pages read in a row were one person reading four pages. It records which pages were read, in what order, what was clicked on them, your device and browser, and your IP address. It is how we find out which pages are doing their job and which are being skipped. We do not ask it who you are: it is not given your name or your email, and no account or form submission is joined to it.
Session recording is on. PostHog records what happens on screen during your visit — the pages, where you move and click, how far you scroll — and replays it back to us as video. It is a recording of this website as you used it, not of you: there is no camera, no microphone and no access to anything outside this browser tab.
Two limits on it are built into the site rather than promised. Everything you type into a form field is masked before it is recorded, so the recording shows that a field was filled, never what was put in it. And the audit-request form is a HubSpot frame, which sits in its own separate window inside the page — the recorder cannot see inside it at all, so nothing entered there reaches a recording by any route. If we ever bring that form into the page itself, this paragraph is rewritten before that ships.
If you would rather not be recorded, the Do Not Track paragraph in Section 4 stops it, along with everything else on this page.
PostHog may also show you things. Three features are enabled that can put something on screen: a chat window for talking to us, a short survey, and a guided tooltip pointing at part of a page. Anything you type into the chat or a survey is sent to PostHog and read by us — that is the point of it — so treat it as a message to us rather than as a form with a privacy notice of its own. None of the three is configured to appear today, and none of them will ever sit between you and something you came to read.
Errors are collected too. When a script on this site fails in your browser, the error, the line it came from and the page you were on are sent to PostHog so that we find out the site is broken from the site rather than from you. It carries no more about you than a page view does.
The two are not both running. PostHog is: a project key is configured, and the site loads it unless your browser sends Do Not Track. Cloudflare is not yet — its beacon renders only where a site token is configured, and none is, so it makes no request from these pages today. If that changes, it changes here first.
An earlier version of this page said we had chosen the analytics product that needed no consent banner. That was true when Cloudflare was the only one. It is not the whole truth now, and Section 4 states the position rather than repeating the old sentence.
3) The third parties on this site
HubSpot — on every page, loading with the page. Every page that ends on the
Video Strategy Audit carries a HubSpot form for requesting it, which is every
page. HubSpot publishes a list of the cookies its software sets. It names
hubspotutk, which identifies a browser and is passed to HubSpot when a form is
submitted so that repeat submissions resolve to one person, and __hstc,
__hssc and __hssrc, which count visits and sessions. HubSpot classes the
last three as non-essential analytics cookies. Which of them this particular
form embed sets, as against HubSpot's full tracking code, is not something its
documentation separates out and not something we are going to assert on its
behalf. See HubSpot's cookie list and
its privacy policy.
PostHog — Section 2, and named here so this list is complete. PostHog is a third-party company and its storage is described in Section 2 rather than here, because unlike the others it is something this site places on purpose rather than something an embed brings with it. See its privacy policy.
Vimeo — nothing loads until you press play, and nothing has yet. The video player on this site is Vimeo, and it is built only when you click it: until then the page holds a still image and a button, and no request reaches Vimeo. When it is built it is asked not to track. No video identifier is configured on this site today, so no player can be constructed and nothing has ever loaded. This paragraph is here before that changes rather than after.
Vidyard is not embedded here. We use Vidyard to host the audit video we make for a prospect and to show the view data back to them on the call. It is named as a processor in the privacy notice for that reason. It sets nothing in your browser from this website, and an earlier version of this page said otherwise.
What an embedded third party does with what it stores is that vendor's decision and is governed by that vendor's policy, not by this one.
4) The position under Indian, EU and UK rules
India. There is no equivalent of the EU ePrivacy rules, and the Digital Personal Data Protection Act 2023 contains no cookie provision. No banner is required of a site serving visitors in India.
The European Union. Article 5(3) of the ePrivacy Directive ordinarily requires consent before anything is written to a browser that is not strictly necessary. Neither the HubSpot cookies in Section 3 nor the PostHog identifier in Section 2 is strictly necessary in that sense, and we have not put a consent gate in front of either. That is a decision, not an oversight: the founder took it on 12 September 2026, confirmed it on 18 September, and extended it to PostHog on the same date and the same basis — that this company is established in India, does not target the EU market, and does not offer the audit to buyers established there. The exposure that remains is stated here rather than argued away, and the paragraph below says what you can do about it.
The United Kingdom. The Data (Use and Access) Act 2025 amended the Privacy and Electronic Communications Regulations with effect from 5 February 2026, so that certain low-risk categories — including analytics used solely by the site operator — no longer require consent, provided visitors are told and given a way to object. The two cases on this site fall on opposite sides of that line. PostHog is analytics used solely by us: telling you is what Section 2 does, and objecting is the paragraph below. The HubSpot cookies are set by a third party for its own purposes and do not fall inside the exemption, so on those the UK position is the same as the EU one.
What you can do.
If your browser sends a Do Not Track signal, PostHog is not loaded for you at all: nothing is written and no event is sent. The site checks for it before it does anything. Firefox and Brave still offer that setting; Chrome removed it, and we would rather say so than let you assume a switch is being honoured that your browser is no longer sending.
Blocking third-party storage in your browser stops the HubSpot cookies, and the site works without them — the form is the only thing that needs them, and you can request the audit by writing to us or telephoning instead, which reaches the same place. Blocking third-party storage does not stop PostHog, because the identifier it sets is first-party; Do Not Track, or blocking this site's storage specifically, is what stops that one.
Nothing else on this site depends on anything being stored.
If you are in the EU or the UK and this is not good enough, say so and we will book the audit with you by email or telephone, and your browser will be asked for nothing. That is not a workaround offered grudgingly; it is how most of these are booked anyway.
5) Changes
If this site ever sets a cookie of its own, adds an analytics product that needs one, embeds a third party not named above, or a video identifier lands and the Vimeo player becomes constructible, this page changes before that ships, and the effective date at the top changes with it.
The other documents
This is one of nine. The index lists them all and says what each one decides.