Last updated: 1 September 2026
This policy explains what coworkings.uk puts on your device when you browse the catalogue, and what it does not. The short answer is that we set no cookies of our own at all — but that is not the whole story, so the rest of this page sets out exactly what is stored, by whom, for how long, and how you can clear it.
It sits alongside our Privacy Policy, which covers the details you send us through an enquiry form, and our Terms and Conditions.
The short version
- We set no cookies of our own — no analytics cookies, no advertising cookies, no session cookies.
- There is no account, no login and no server session on this site, so there is nothing for a session cookie to hold.
- There are currently no analytics counters on the site at all. Nothing measures your visit.
- Cloudflare, which hosts and protects the site, sets its own technical cookies for security. These are strictly necessary and outside our control.
- We do use your browser's own storage to remember three small things that last — your shortlist of buildings, your cookie choice and a dismissed language hint. Everything else we write, including every pop-up record, lives only in the current tab and is gone when you close it. None of it is ever sent to us.
- Some page elements are loaded from other companies, which means those companies can see your IP address, and the map can store data of its own once it loads. They are listed below.
- Sending an enquiry keeps you on this domain: the form posts to coworkings.uk itself, and no third-party forwarding service is involved in delivering it.
Who this policy is from
coworkings.uk is a catalogue of flexible offices in the United Kingdom, operated by Rent office today Ltd.
For anything in this policy, write to info@coworkings.uk.
Cookies and browser storage: what is the difference
A cookie is a small file that a website asks your browser to keep and then sends back to a server with every later request to that site. Because it travels with each request, a cookie can be used to recognise a returning browser — which is why cookies are the usual tool for logins, analytics and advertising.
localStorage and sessionStorage are different. They are key-and-value stores that live inside your browser. Nothing in them is attached to network requests automatically. A value only leaves your device if the page's own code deliberately sends it — and on this site, none of it is sent anywhere. localStorage stays until you clear it. sessionStorage is wiped as soon as you close the tab.
The UK rules — the Privacy and Electronic Communications Regulations 2003 (PECR), read together with the UK GDPR — apply to storing or reading information on your device whatever the technology is called. So we describe our browser storage here on the same footing as cookies, rather than leaving it out because it is technically not a cookie.
We set no cookies of our own
This site is built in advance as a set of static pages and served from Cloudflare Workers. There is no application server of ours behind it, no user account, no shopping basket and no server-side session. As a result there is no first-party cookie to describe — no table of them exists because none of them exist.
We also run no advertising tags, no social media pixels, no heat-mapping or session-replay tools, and no cross-site tracking of any kind.
Cookies set by Cloudflare
The site is hosted and protected by Cloudflare, Inc. Cloudflare's network sits in front of every page and may set its own technical cookies to keep the site available and to tell real visitors from automated traffic. These are set by the infrastructure, not by us, and we cannot read them or switch them off for you.
| Cookie | Set by | Purpose | Category |
|---|---|---|---|
| __cf_bm | Cloudflare | Distinguishes human visitors from bots so that abusive automated traffic can be filtered out. | Strictly necessary |
| cf_clearance | Cloudflare | Records that a browser has passed a security check, so the check is not repeated on every page. | Strictly necessary |
Both are security and delivery cookies rather than analytics or marketing cookies, and under PECR strictly necessary cookies do not require consent. Their exact lifetimes are set by Cloudflare and are described in Cloudflare's own documentation. Depending on how you reach the site and how our security settings respond to your traffic, you may see one, both or neither.
What we keep in your browser storage
This is the complete list of what coworkings.uk itself stores. Every entry below is written and read only by the page you are looking at. None of it is transmitted to us, to our hosting, or to anyone else. Clearing your browser's site data for coworkings.uk removes all of it, and the site keeps working normally afterwards.
Third-party components can store data of their own on your device, which is not covered by the list below: the Mapbox map does so once it loads, and it loads only after you interact with a page that has a map — a scroll, a click or a movement of the mouse. If you would rather that did not happen, block third-party storage for this site in your browser, or browse privately.
localStorage — stays until you clear it
| Key | What it holds |
|---|---|
| rot_favs | Your shortlist of saved buildings, so the ones you marked as favourites are still there when you come back. It is a list of building references, nothing more. |
| rot_cookie_analytics | The choice you made in the Cookie Settings panel about analytics. This is what allows us to honour a refusal rather than ask you again. |
| rot_bridge_off | Remembers that you dismissed the language hint, so it is not shown to you again. It is written only when you dismiss it. |
sessionStorage — wiped when you close the tab
| Key | What it holds |
|---|---|
| rot_geo_cc | A two-letter country code for your location, obtained from Cloudflare's own trace endpoint. It is used for one thing: pre-filling the correct international dialling code in the phone field of an enquiry form, so you do not have to find it yourself. |
| promoShownAt, bdPromoShownAt, cwPromoShownAt, mcPromoShownAt, brandPromoShownAt, rotAnyPopupAt | Timestamps recording when each type of enquiry pop-up was last displayed, so the same window is not thrown at you repeatedly during your visit. |
| rotPromoClosed, rotBdClosed, rotCwClosed, rotMcClosed | Flags recording that you closed a particular pop-up, so it stays closed for the rest of the visit. |
None of these entries identify you by name, build a profile, follow you to other websites, or feed any advertising system. Apart from your shortlist, your analytics choice and the dismissed language hint, everything above disappears together with the tab.
Most entries are written only after you do something — save a building, close a window, make a choice. The pop-up records are the exception: a timestamp is written when a window is first displayed, precisely so that it is shown less often. Those records are deliberately kept in tab-only storage, so nothing about which pop-ups you have seen is carried into a later visit. If you would rather nothing at all was written, use a private window, or block storage for this site in your browser.
Analytics: none at the moment
At the date at the top of this page the site carries no analytics counter whatsoever. The measurement tools used elsewhere in our network were deliberately left off this domain, and the published pages contain no third-party tracking scripts.
That may change: a website without any measurement is hard to improve. If we do add an analytics tool, it will be described in an updated version of this page, and it will load only after you have agreed to it in the Cookie Settings panel in the footer. Nothing will be switched on retrospectively on the strength of a choice you never made.
The analytics toggle in Cookie Settings already works today and your choice is stored — it simply has nothing to enable yet. If you turn it off now, that refusal is what any future counter will read before deciding whether to load.
Third-party services that can see your IP address
Whenever a browser fetches a file from another company's servers, that company necessarily receives your IP address, your browser's user-agent string and the address of the page requesting the file. That happens on almost every website; here is who it involves on ours.
- Cloudflare, Inc. — hosting, content delivery and protection against attacks. Every request passes through it, and it sets the technical cookies described above. Cloudflare is also more than our host: the code that receives an enquiry runs on its network, and the e-mail copy of an enquiry is sent by Cloudflare's own Email Service, as described below.
- Amazon Web Services (S3) — building photographs are served directly from storage, so image requests reach AWS.
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — the typefaces used across the site.
- Mapbox — the interactive map. It is deliberately not loaded when the page opens: the map code is only requested after you do something on the page, such as scrolling, clicking or moving the mouse. If you open a page and leave it alone, no request reaches Mapbox. Once it has loaded, Mapbox can store data of its own on your device, which we neither control nor read.
Sending an enquiry does not hand your browser over to anybody else. The form posts to an address on coworkings.uk itself, and our own code, running on Cloudflare's network, deals with it there. From there the message goes to two places: to Telegram (Telegram Messenger Inc.), which is outside the United Kingdom, and to an e-mail sent by Cloudflare's own Email Service from an address on this domain to the owner's mailbox. There is no third-party forwarding or mailing service anywhere in that chain. Because those messages are sent by our code and not by your browser, neither Telegram nor the mail path receives a request from you, and your IP address is not passed to them as part of it. What happens to the details you type is set out in the Privacy Policy.
Your IP address is, however, used at that endpoint for one narrow purpose, and no cookie or stored value is involved in it: the code counts recent submissions from the same address and, above six in a minute, declines and asks you to try again shortly rather than pretending your message was sent. The form is protected in the same cookie-free way against automated abuse — by a hidden field that only automated software fills in, by a check that the request comes from a page on this site, by a ceiling on the size of what may be submitted, and by discarding administrative fields such as those that would try to redirect a copy of your message to another address.
These companies act under their own privacy terms for the technical data they receive. We do not send them any of the details you type into a form as part of loading a page.
How to control what is stored
Cookie Settings
Every page has a Cookie Settings link in the footer. It opens a panel where you can set your position on analytics. Your answer is recorded in your browser (the rot_cookie_analytics entry above) and will govern any measurement tool we introduce later. The panel has no separate control for the pop-up records, because none of them outlive the tab you are using.
Your browser
Browser settings give you the real control, and they cover things we cannot switch off for you — including Cloudflare's security cookies and anything the map stores. In Chrome, Edge, Firefox and Safari you can, for this site specifically:
- view and delete cookies and site data;
- block cookies and storage from third parties, or from all sites;
- clear everything a site has stored, including localStorage and sessionStorage.
Clearing site data for coworkings.uk resets everything listed on this page. The practical effect is small: your saved shortlist disappears and pop-ups you had dismissed may appear again. Nothing else breaks. There is no sign-in to lose, and no form on the site depends on a cookie in order to submit: the enquiry endpoint checks that the request comes from a page on this site, which needs nothing stored on your device.
Blocking Cloudflare's cookies is your right, but be aware that the security layer may then ask you to pass a check more often.
Private browsing
Opening the site in a private or incognito window is the simplest option if you want nothing to persist. Everything described above is discarded when you close that window.
How to withdraw your consent
You can withdraw your analytics choice at any time in the Cookie Settings panel in the footer, and clear the stored record of it in your browser. Withdrawal is as easy as giving consent in the first place:
- open Cookie Settings in the footer and turn analytics off — any counter we add later then stops loading on your next page view;
- clear the site's data in your browser if you want the record of the choice itself gone;
- close the tab, and every pop-up record described above goes with it — there is nothing left to withdraw.
Withdrawing consent does not affect anything that was lawfully collected before you withdrew it.
Your rights and how to complain
This policy is written to meet PECR 2003 and the UK GDPR. Where information stored on your device counts as personal data, the rights set out in our Privacy Policy apply to it — including the right to ask what is held and to ask for it to be deleted.
If you think we have handled any of this badly, tell us at info@coworkings.uk. Your right to complain to the Information Commissioner's Office, and how to use it, is set out in our Privacy Policy.
Changes to this policy
We will update this page if what we store changes — in particular if we add an analytics tool, a new third-party service, or any cookie of our own. The date at the top always shows the current version. There is no mailing list here, so the page itself is the notice; it is worth a glance if this matters to you.
Contact us
Questions about cookies, browser storage or anything else on this page: info@coworkings.uk. Related documents: Privacy Policy, Terms and Conditions, Usage Policy.