1. The short version
This site sets no analytics or advertising storage of any kind until you say yes. There is no cookie wall — refusing works exactly as well as accepting, and the site behaves identically either way. The only things we store without asking are the handful of items needed to actually take a booking, listed in full below.
We do not use Google Analytics, Meta Pixel, advertising cookies, or any cross-site tracking or profiling. We do not sell or share your browsing data.
2. Changing your mind
You can change or withdraw your choice at any time — it is as easy to take back as it was to give. Use the control here or in the footer of every page. Withdrawing analytics consent immediately stops any measurement and deletes the attribution record described in section 4 from your device.
Your choice is remembered for six months, after which we ask again. You can also clear it yourself by clearing this site’s data in your browser settings.
3. Strictly necessary — always on, no consent needed
These are exempt from the consent requirement under regulation 6(4) of the Privacy and Electronic Communications Regulations, because the booking you asked for cannot be delivered without them.
- bap_consent — browser local storage, set by us. Records your cookie choice, when you made it and which version of this policy you were shown. Without it we would have to ask you on every single page. Lifetime: 6 months, then we ask again.
- pba:checkout — browser session storage, set by us. Carries your dates, chosen service and price from the search results to the checkout page, so a refresh does not lose your booking. Lifetime: deleted when you close the tab.
- pba:confirmation — browser session storage, set by us. Holds your booking reference and summary so the confirmation page can show it. Lifetime: deleted when you close the tab.
- __stripe_mid — cookie, set by Stripe Payments Europe Ltd on the checkout page only. Fraud prevention: it lets Stripe recognise the device a payment came from and block card testing and fraudulent charges. Lifetime: 1 year.
- __stripe_sid — cookie, set by Stripe on the checkout page only. The session half of the same fraud check. Lifetime: 30 minutes, extended while you are active.
We are being straight with you about the Stripe ones: they are genuine tracking-capable cookies set by a third party, and we still class them as strictly necessary. That is because they exist to stop fraudulent card use on a payment you are choosing to make, and Stripe cannot process the payment safely without them. Stripe’s own current list is published at stripe.com/cookies-policy/legal. Stripe’s scripts are only loaded on the checkout page — no other page on this site contacts Stripe.
Nothing on this site loads fonts, scripts, maps or anything else from Google, on any page. Our typefaces are served from our own domain.
4. Analytics — only with your consent
If you accept analytics, two things happen. Neither is on by default and both stop the moment you withdraw consent.
- Page measurement — a privacy-first, cookieless analytics script that counts page views in aggregate. We use Umami, self-hosted on our own server in the EU — your data goes to us and nobody else. It sets no cookie and stores nothing on your device, and it does not build a profile or follow you to other websites.
- bap_attr — browser local storage, set by us. Records how you first arrived: the first page you landed on, the site or search engine that referred you, and any campaign tags on the link (utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid, msclkid), plus whether you are on a mobile, tablet or desktop, when you first arrived and how many times you have visited. If you go on to book, this is sent with the booking so we can see which advertising and which search results actually bring people in. Lifetime: at most 6 months, and deleted immediately if you withdraw consent.
This is not strictly necessary — it is marketing measurement — which is exactly why it is behind a consent switch and off until you flip it. If you refuse, your booking simply arrives with no idea where you came from, and nothing else changes.
What we cannot see, and want to be clear about: if you found us through an ordinary Google search, we can tell that you came from Google, but not what you typed. Search engines stop sending the search terms, so no one can tie a keyword to your booking. Aggregate, non-personal keyword data is available to us through Google Search Console, and never links to an individual.
5. What we never do
- No advertising or retargeting pixels.
- No social media tracking widgets.
- No selling, renting or sharing of your data with data brokers.
- No automated decision-making or profiling.
- No pre-ticked boxes, and no treating “keep browsing” as consent.
6. Related policies and contact
How we handle the personal data in your booking — name, email, vehicle registration and so on — is covered by our privacy policy. Our terms and conditions cover the booking itself.
Questions, or a request to see or delete what we hold: email bookings@parkingbristolairport.co.uk or call 07960 011047. If you are not satisfied with our response you can complain to the Information Commissioner’s Office at ico.org.uk.