GEARHOLD®
Get a quote
Home/Legal/ Cookies & tracking

Cookies & tracking.

One consent record, one opt-in chatEffective 20 Aug 2026
Index
Honesty noteWorking documents drafted at the bench, not by a lawyer. They describe what we actually do and they are written to be read, but they are not legal advice — have your own counsel read them before you rely on them.
QUESTIONS?
hello@fixedgearstraps.com
+1 (762) 760-1179

Our own code still sets no cookies and runs no analytics, but two outside tools now appear in your browser: a consent manager that remembers the choice you make in its banner, and a live-chat widget that stays blocked until you opt in. This page is the full inventory, what each one stores, and how to change your mind.

1.0
The short version

Our own code sets no cookies and writes nothing to local storage, session storage or IndexedDB. No session cookie, no preference cookie of ours, no analytics cookie, no advertising cookie. That part of the old version of this page still stands.

Two outside tools do appear in your browser now, and they are the reason this page changed. The first is the consent manager, Termly, which runs the banner you saw on arrival. It stores your choice in your browser so the banner does not ask again on every page, and it keeps a record that a choice was made. The second is the live-chat widget, tawk.to, which the consent manager blocks until you opt in to its category. Say no and it never loads.

There are also the two standing exceptions from before, each with a section of its own below. The page fetches its typefaces from two outside providers across three hosts, and asking for a font tells them your IP address. And the pages themselves come from a web host, which sees your browser ask for a file: your IP address, what you asked for and when.

A page claiming that nothing at all is recorded about your visit would be claiming something no website can honestly claim, so all of it is written out below rather than left for you to find.

2.0
What a cookie is

A cookie is a small piece of text a website asks your browser to keep and hand back on the next page, so the site can recognize the same browser again. That is how a cart survives a page change, how a site remembers you chose dark mode, and how an ad network follows you from one site to the next.

Local storage and session storage do a similar job with more room and no automatic expiry. IndexedDB is a small database sitting in the same place. Our own code uses none of the three. The consent manager keeps your choice in this kind of storage — remembering your answer is the whole point of it — and the chat widget uses it too, once you have opted in. Nothing else of ours sits in your browser to clear when you leave.

3.0
Why there is a banner now

This page used to explain why there was no consent banner: there was nothing non-essential to consent to, and a banner would have been asking permission for something that was not happening.

That stopped being true when the site added a live-chat widget. The widget is genuinely useful and genuinely optional, and optional means your call. So the site now runs a consent manager, Termly, which asks before anything optional loads: a banner on your first visit with accept, decline and per-category choices, and a Cookie Settings button in the footer of every page that reopens the same controls.

The rule the old page set still holds: the banner arrived before the cookie did, not after. The chat widget is held by the consent manager until you opt in to its category, and declining leaves the site completely usable — the chat is a convenience, not a key to anything.

4.0
The full inventory

Here is the table a cookie policy is supposed to carry. Two rows now have something in the middle column, and both get a section of their own below. The last column says what each category would be for, so the empty rows mean something to you instead of asking to be taken on faith.

CategoryOn this siteWhat it is for
Strictly necessaryOne, from the consent managerTermly stores your consent choice in your browser — a cookie or local-storage entry under its own name — so the banner does not reappear on every page. A site cannot offer you a choice without remembering what you answered. Section 6.0.
PreferencesNone setRemembering a language, a currency or a theme. The site has no such switches.
AnalyticsNone setCounting visits and pages. We do not count them.
AdvertisingNone setRetargeting you elsewhere and measuring ad clicks. We run none.
SocialNone setFeeds, share buttons and social logins. There are no embeds and no login.
Live chat (optional)Only after you opt intawk.to, the chat widget. Once you allow its category it uses cookies and browser storage to hold the chat session open across pages. Held until then — section 7.0.

No tracking pixels, no fingerprinting, no tag manager, no A/B testing, no session recording, no heatmaps, no CRM, no captcha, no embedded map or video, no newsletter signup, no social login and no accounts. Those are not disabled or dormant. They were never added. The consent manager and the chat widget are the only two exceptions to the old “never added” list, and both are on this page.

5.0
Local storage and the quote form

The wholesale quote builder looks exactly like the kind of tool that saves your work somewhere. It doesn’t. It asks for your name, email, company or shop name, buyer type, the products you want, quantity in pairs, colorways, timeline and any notes, then runs the lot inside your own browser: it checks the fields, works out an estimate, prints a reference number shaped GH-Q-XXXX-### and shows you a summary panel.

It transmits nothing and it stores nothing. None of what you type goes into a cookie, into local storage or into session storage, because it only ever exists in the page in front of you. Close the tab and the entry is gone — there is no draft waiting when you come back, and there is no copy on our side. To actually send a quote request, email quotes@fixedgearstraps.com or call +1 (762) 760-1179, Tue–Sat 10–18 ET.

The rest of the site behaves the same way. The arrowed quote links on the products take you to the quote form and do nothing else. There is no cart, no checkout and no card entry on fixedgearstraps.com, so there is nothing for a cookie to hold on to.

6.0
The consent manager

In plain EnglishTermly runs the banner and remembers your answer. It is the one strictly necessary storage write on the site, because a choice that is forgotten every page is not a choice.

The banner on your first visit, and the Cookie Settings button in the footer of every page, are run by Termly, a third-party consent manager. Its job is narrow: ask before anything optional loads, remember what you said, and let you change your mind.

Remembering what you said takes storage. Termly writes your choice to your browser as a first-party cookie or a local-storage entry under its own name, per its current documentation, and your browser reports the choice to Termly’s consent service — the consent.api.termly.io connections in your network tab — so there is a record that consent was given or refused. The record carries the choice, a timestamp and the page you were on.

The stored choice has an expiry set by the consent manager rather than by us, and when it lapses the banner asks again. You never have to wait for that: Cookie Settings in the footer reopens the controls at any time, and switching a category off stops it loading from the next page on. Withdrawing does not reach back and delete what was logged while the category was on — for that, write to us and we will take it up with the provider. 14.0 has the addresses.

7.0
The chat widget, held until you say yes

In plain Englishtawk.to runs the chat bubble. It is blocked until you opt in to its category in the banner, and this section is what opting in turns on.

The chat bubble is tawk.to, a third-party live-chat service. The consent manager holds it: the widget’s code does not load, and it makes no connections and writes no storage, until you opt in to its category in the banner or in Cookie Settings. Decline and it never appears.

Once you switch it on, the widget can begin a visitor session even before you type anything. What it processes while it is active, per the provider’s current documentation: your chat messages and any name, email or other details you submit; your IP address and browser or device data; the pages you view and your session activity; your approximate location; and timestamps. It keeps the session alive across pages with cookies and local or session storage under its own name, and the messages go to tawk.to and its subprocessors, which process them internationally.

The purposes are what a chat is for: delivering the live chat, monitoring and troubleshooting chat sessions, security, support and follow-up. What the provider keeps and for how long sits in our settings with them, and a deletion request to us is actioned through their dashboard or passed on.

One warning, because the chat window feels like the bench: do not put card numbers, account credentials or anything highly sensitive into it. Card payment never happens through this website at all — /legal/trust-security covers why — and nothing legitimate will ever ask you for one in a chat.

8.0
Asterisk one: webfonts

In plain EnglishYour browser fetches the typefaces from Google and Fontshare, which shows them your IP address. Section 11.0 is how to stop it.

This page is set in Archivo, Space Mono and Clash Display. Those files come from two providers across three hosts we do not run, and your browser has to ask them directly. Two of the three are preconnected, which means your browser opens the connection a moment before it needs the file — the same hosts, one less wait.

HostWhat it servesWhat the request sends
fonts.googleapis.comThe stylesheet for Archivo and Space Mono (Google Fonts, United States)IP address, user-agent, referring page
fonts.gstatic.comThe Archivo and Space Mono font files (Google Fonts, United States)IP address, user-agent, referring page
api.fontshare.comClash Display (Fontshare, operated by Indian Type Foundry, India)IP address, user-agent, referring page

That is a real transfer, not a formality. An IP address is roughly a location. Two of those hosts are operated from the United States and one from India, so unless you are reading this from one of those two countries, that information leaves your country. What each provider does with the request is governed by its own policy rather than ours, and a request about that data has to go to the provider holding it.

They set no cookies on fixedgearstraps.com, and nothing comes back to us. No report, no log, no visitor count. We do not know that you were here.

Those three, the consent manager and — only after you allow it — the chat widget are the only outside servers this page asks for anything. The 3D cog on the home page runs on three.js, and that code is bundled into the site rather than pulled from a content delivery network, so it calls nowhere. The host that serves the pages themselves is the next section.

9.0
Asterisk two: the web host

In plain EnglishEvery website you open tells the computer serving it your IP address. Ours is no different, and we add nothing to what a host records by default.

A page has to come from somewhere. The files that make up this site sit with a hosting provider, and asking for a page means your browser connects to them. That connection carries your IP address, your user-agent string, which file you asked for and the time you asked — the four things every web server on the internet sees.

Our hosting provider keeps whatever request logs a web host keeps by default. We add no logging of our own on top of it, we do not analyse it, and we do not use it to count visitors or to work out who has been reading what. It is not a cookie, nothing is written to your browser, and it cannot follow you to another site.

This one is not something we can switch off. A server cannot send you a page without being told where to send it. We would rather write it down than let the rest of this page imply that nobody sees you arrive.

The full list of outside companies involved in this site and in the business, and what each one gets, is at /legal/trust-security.

10.0
Caching is not tracking

Your browser will normally keep a downloaded font file for a while so the next page does not have to fetch it again. That is ordinary caching, and it is worth being clear about what it is: a copy of a typeface sitting on your machine. It is not an identifier and it holds nothing about you. Nothing on this site reads it, and we cannot see it.

Clearing your browser cache clears it. There is nothing else of ours in there to clear.

11.0
How to block it anyway

If you would rather your browser never asked those three font hosts for anything, you can stop it. Any of these will do.

  • Browser settings. Most browsers can block third-party requests, or remote fonts specifically, somewhere under privacy or content settings.
  • A content blocker extension. Most of them include a switch for remote fonts. Turning it on stops all three requests.
  • Reader mode. It strips the page down to text in a typeface already installed on your machine, usually before the fonts load.
  • A blocker at network level, on your router or in your DNS, if you already run one.

The site is built to survive that. Blocked fonts fall back to what is already on your machine. The type looks plainer and a little less like us, but every word, link, table and button still works, and the layout does not break.

We would rather you read the site in system fonts than not trust it.

What none of that blocks is the request for the page itself, covered at 9.0. Nothing can, short of a VPN or Tor, and those change which IP address arrives at the host rather than whether one does.

12.0
Do Not Track and Global Privacy Control

In plain EnglishBoth signals tell a site to stop tracking you. Everything they could stop here is already off until you switch it on yourself.

Do Not Track is a header your browser can send with every request. Global Privacy Control is a newer signal that, in some US states, counts as a legal request not to sell or share your personal information. Most sites receive both and ignore both.

We honor them in the only way that matters. There is no tracking to switch off, no profile being built, and nothing gathered on this site that gets sold or shared. The one optional extra, the chat widget, is off by default for every visitor — which is the thing Global Privacy Control exists to ask for.

We do not read the headers, and the consent manager is not set to read them either. Reading them would change nothing, because the default state of this site is already what the signals ask for. If that ever stops being true — an advertising pixel, a sale of data — the signal gets honored and this page says so first.

If you would rather have the opt-out recorded in writing than sent as a signal, /legal/your-data is where that request goes and you will get a written answer.

13.0
If we ever add analytics

Two tools have arrived since this page was first written — the consent manager and the chat widget, both described above — and both arrived the way this section promised: this page changed in the same release, before either one ran. There is still no analytics. If that day comes, this is the order it happens in.

  • This page changes first, before anything is switched on, with a new effective date at the top.
  • We name the tool. Not “an analytics provider” — the actual product, and where it keeps what it collects.
  • We say what it records, what it does not, and how long it holds it.
  • If it needs a cookie or any form of consent, you get a real choice before it is set, and declining leaves the site completely usable.
  • Anything we add is measurement for the workshop, not advertising. We aren’t going to start retargeting you.

Until then this page is accurate as written, and you don’t have to take our word for it. Open your browser developer tools, look at the cookies and storage panel, and reload the page. The only entries you will ever find there are the consent manager’s record of your own choice and, if you opted in to it, the chat widget’s session storage.

14.0
Questions

If anything here does not match what you see in your own browser, tell us. That is either a bug in the site or a mistake on this page, and both are worth fixing.

This page covers the website only. What the business holds once you email, call or order is at /legal/privacy, how to ask for a copy or a deletion of it is at /legal/your-data, and how the whole place is run is at /legal/trust-security.

When this page changes, the effective date at the top changes with it. Anything material — a new third-party request, a new tool, a cookie of any kind — is written here before it goes live, not after.

Gearhold LLC, 104 S Cherry St, Tunnel Hill, GA 30755, USA · hello@fixedgearstraps.com · +1 (762) 760-1179 · Tue–Sat 10–18 ET. Wholesale quote requests go to quotes@fixedgearstraps.com.

Those are the only two addresses we have. There is no privacy inbox, no data protection officer, no EU or UK representative and no outside privacy vendor standing between you and an answer. You get the bench.