What ShipORB.com stores in a browser, what Google Analytics receives, and how to change or withdraw the choice.
This notice describes every piece of information ShipORB.com stores in a visitor’s browser and everything it sends to a third party. It covers the marketing site at shiporb.com and its subdomains. It is not a privacy policy and does not describe the ShipORB product, which stores Oil Record Book data on the vessel and on the operator’s own shore instance rather than in a browser.
The site loads one third-party service, Google Analytics 4, and only after a visitor accepts it. A visitor who has not accepted, or who has refused, causes no request to any Google host and receives no cookie from this site. The site carries no advertising, no advertising trackers, no social media pixels, and no cross-site identifiers.
One entry in browser local storage, under the key shiporb.consent.analytics. It holds the string granted or denied and nothing else: no identifier, no timestamp, no visitor record. It is written when one of the two buttons in the consent banner is pressed and read on each page load to decide whether the banner appears.
It is deliberately not a cookie. A cookie is transmitted to the server on every request, and a record of a refusal has no reason to travel anywhere. Local storage stays in the browser.
Storage whose only purpose is to carry out a choice the visitor has made is exempt from the consent requirement it serves, under the ePrivacy Directive Article 5(3) exemption for storage strictly necessary to provide a service the subscriber explicitly requested. Nothing else on the site relies on that exemption.
Google Analytics 4 sets two first-party cookies:
| Cookie | Purpose | Expiry |
|---|---|---|
_ga | Distinguishes one browser from another so repeat visits are not counted as new ones | 2 years |
_ga_G8ZGR0CJGE | Holds the session state for this site’s specific Analytics data stream | 2 years |
Both are set by script running on shiporb.com and are readable only by shiporb.com. Neither carries a name, an email address, or an account identifier, because the marketing site has no accounts to identify anyone by.
Google receives the page address, the referring address, the browser user agent string, approximate location derived from the IP address, and the sequence of pages visited. The purpose is to count visits and establish which pages are read. There is no other purpose, and the data is not used to build advertising audiences: the Consent Mode signals ad_storage, ad_user_data, and ad_personalization are set to denied for every visitor, including a visitor who accepts analytics, because the site runs no advertising and has no use for the permission.
gtag.js is never requested. No connection is made to googletagmanager.com or any other Google host, no cookie is written, and no data leaves the browser. The refusal is recorded in local storage so the banner does not reappear on every page.
This is stricter than the arrangement Google recommends, which loads the tag immediately with consent signals set to denied and continues to send cookieless measurement pings. Those pings still transmit an IP address to a third party. ShipORB.com does not send them.
Select Cookie settings in the footer of any page. The banner reopens and either button can be pressed.
Withdrawing consent sets the Analytics consent signal back to denied, which stops collection within the open page, and deletes the _ga and _ga_G8ZGR0CJGE cookies. Subsequent page loads do not request the tag at all. Withdrawal is available at any time and takes the same single action as giving consent, as required by GDPR Article 7(3).
Clearing site data through the browser has the same effect, with one difference: it also removes the stored decision, so the banner appears again on the next visit.
The consent decision is stored per host. A subdomain of shiporb.com that carries its own analytics asks for its own consent and records it separately.
The shore dashboard at app.shiporb.com runs no analytics. The measurement code exists in the application but is disabled at build time, and if it is ever enabled it reports route patterns rather than addresses, so a vessel identifier in a URL is replaced before anything is transmitted.
Questions about this notice go to hello@shiporb.com.