PRIVACY

What this site does, and what it doesn't.

This site sets no cookies, runs no analytics of any kind, and makes no requests to anybody else. There is no consent banner because there is nothing to consent to.

Last updated 13 August 2026

No cookies, and no analytics

This site sets no cookies. It runs no analytics — no page-view counter, no session recorder, no tag manager, no tracking pixel, no heatmap. Nothing on any page is measuring you, and there is nothing to turn off.

That is a standing constraint on this site rather than a description of how it happens to be configured today. Adding analytics here would not be a settings change; it would be a decision, and it is one nobody has taken.

No requests to anybody else

Every font, stylesheet, script and image on this site is served from this domain. There is no content delivery network, no embedded video, no map, no social widget and no hosted script. Loading a page here contacts one server, and it is ours.

This one is not a promise we are asking you to take on trust. It is one of the product's eleven invariants, and it is asserted in our continuous integration across the whole codebase with no exclusions: a build that referenced a font network would fail before it could be deployed.

The only outbound links, and following one is your decision

Articles in the Learn library cite their sources, and those citations are links to standards bodies and regulators. They are the only addresses on this site that are not ours, and nothing is fetched from them while you read — the link sits there until you choose to follow it.

When you do follow one, you are on somebody else's site under somebody else's policy, which is the ordinary situation and worth naming rather than implying.

What the server writes down

Our web server keeps an access log, which is how any server records that it answered a request. Its filter deletes the client IP address from every entry before the line is written, along with any cookie or authorisation header that arrived with the request.

That is a filter in the server's own configuration rather than a policy somebody has to remember, and it is checked automatically: a server block whose log does not delete both address fields fails our build.

If you write to us

The addresses on the contact page reach a mailbox we operate. If you email us, we keep the message so that we can answer it and find the thread again later, which is what an inbox is.

You are not added to anything by writing. There is no sequence, no newsletter and nothing to unsubscribe from — the only thing we send unprompted is the GS1 changelog, and only to people who have asked for it.

The dashboard and product pages are separate surfaces

This notice is about this marketing site. The dashboard is a signed-in application and it does set a session cookie, because that is what signing in is. The consumer product pages a scan lands on are a third surface with rails of their own.

Neither is covered by what is written here, and each will carry its own notice.

If this changes

The date at the top of this page changes with it. We will not quietly add a tracker and leave the date where it is; the whole point of a page this specific is that it can be checked against what the site actually does.

Asking about any of this

Write to hello@packagepage.com. It reaches a person, and the reply comes from one.