This is an earlier version. The current version took effect September 24, 2026. Read the current Cookie Statement.
Cookie Statement
fondfully.com sets no cookies of its own and uses no analytics; this statement explains the few strictly necessary security checks our providers run.
The short version
- fondfully.com sets no cookies of its own, and has no analytics, no ads and no tracking.
- The claim form on gift brief pages uses Cloudflare Turnstile to keep bots out.
- Cloudflare, which protects our site, may set a strictly necessary security cookie when it needs to check for automated traffic.
- Our admin console, which isn't public, uses Cloudflare Access session cookies for our team.
1. Our website
Our website, fondfully.com, includes our home page, this manual, our legal pages, the account deletion page and gift brief pages. It:
- sets no cookies of its own;
- doesn't use analytics, advertising, social media or other third-party tracking scripts; and
- serves its fonts, images and scripts itself, so opening our pages doesn't contact other companies' servers, except for the Turnstile check described below.
Gift brief pages work without cookies. A brief is decrypted in your browser with the key in the link, and the key is never sent to us.
2. Cloudflare Turnstile on gift brief pages
When someone claims an idea on a gift brief page, the claim form uses Cloudflare Turnstile to check that a person, not a bot, is making the claim. Most of the time this happens in the background without a puzzle.
To make the check, Turnstile loads from Cloudflare's servers and processes technical information about your browser and connection, such as your IP address, browser characteristics and signals about how the page is being used. Cloudflare uses this information to provide and improve its bot-detection service, not for advertising. We receive only whether the check passed. Cloudflare's Turnstile privacy addendum explains more.
We use Turnstile because it's strictly necessary to protect gift briefs and the people who share them from abuse.
3. Security cookies set by Cloudflare
Our site is delivered and protected by Cloudflare. When traffic looks automated, or during an attack, Cloudflare may set strictly necessary security cookies, such as:
- __cf_bm, which helps tell people from bots, and expires after 30 minutes; and
- cf_clearance, which remembers that your browser passed a security check, so you aren't asked again straight away.
These cookies are used only for security. They aren't used to track you across websites or for advertising. See Cloudflare's cookie policy for details.
4. The admin console
Our admin console, at admin.fondfully.com, is used only by the Fondfully team. It's protected by Cloudflare Access, which sets session cookies (such as CF_Authorization) after an authorized team member signs in. It isn't open to the public, and these cookies are never set when you visit fondfully.com.
5. The apps
The Fondfully apps don't use cookies to track you, and contain no third-party analytics, advertising or tracking software. When you open a product link from the app, it opens in your browser, where the store's website may set its own cookies under its own policy. If you've turned on "Support Fondfully when you shop", the store may use cookies to credit your purchase to our affiliate tag; see our Affiliate Disclosure.
6. Your choices
Because the only cookies on fondfully.com are strictly necessary for security, we don't show a cookie banner. You can block or delete cookies in your browser's settings at any time. If you block Cloudflare's security cookies, you may see extra security checks.
7. Changes and contact
If we ever change how cookies are used on fondfully.com, we'll update this statement first, and ask for your consent where the law requires it. Questions: privacy@fondfully.com. Our Privacy Policy has more about how we handle personal information.
Other versions
- Version 2026-09-24 · effective September 24, 2026 (current)